From unknown Sat Jun 14 18:05:41 2025 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Mailer: MIME-tools 5.509 (Entity 5.509) Content-Type: text/plain; charset=utf-8 From: bug#22408 <22408@debbugs.gnu.org> To: bug#22408 <22408@debbugs.gnu.org> Subject: Status: wget rejects Let's Encrypt certs, although Icecat accepts them Reply-To: bug#22408 <22408@debbugs.gnu.org> Date: Sun, 15 Jun 2025 01:05:41 +0000 retitle 22408 wget rejects Let's Encrypt certs, although Icecat accepts them reassign 22408 guix submitter 22408 Mark H Weaver severity 22408 normal thanks From debbugs-submit-bounces@debbugs.gnu.org Tue Jan 19 09:27:46 2016 Received: (at submit) by debbugs.gnu.org; 19 Jan 2016 14:27:46 +0000 Received: from localhost ([127.0.0.1]:53545 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84) (envelope-from ) id 1aLXG6-0000py-BU for submit@debbugs.gnu.org; Tue, 19 Jan 2016 09:27:46 -0500 Received: from eggs.gnu.org ([208.118.235.92]:42789) by debbugs.gnu.org with esmtp (Exim 4.84) (envelope-from ) id 1aLXG4-0000pi-Ry for submit@debbugs.gnu.org; Tue, 19 Jan 2016 09:27:45 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1aLXFy-0001Af-Oz for submit@debbugs.gnu.org; Tue, 19 Jan 2016 09:27:39 -0500 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on eggs.gnu.org X-Spam-Level: X-Spam-Status: No, score=-0.0 required=5.0 tests=BAYES_20 autolearn=disabled version=3.3.2 Received: from lists.gnu.org ([2001:4830:134:3::11]:56824) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1aLXFy-0001Ab-L6 for submit@debbugs.gnu.org; Tue, 19 Jan 2016 09:27:38 -0500 Received: from eggs.gnu.org ([2001:4830:134:3::10]:33727) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1aLXFu-0003Xr-2U for bug-guix@gnu.org; Tue, 19 Jan 2016 09:27:37 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1aLXFq-000187-P3 for bug-guix@gnu.org; Tue, 19 Jan 2016 09:27:34 -0500 Received: from world.peace.net ([50.252.239.5]:36512) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1aLXFq-00013U-Kp for bug-guix@gnu.org; Tue, 19 Jan 2016 09:27:30 -0500 Received: from [10.1.10.78] (helo=jojen) by world.peace.net with esmtpsa (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.72) (envelope-from ) id 1aLXFX-0007NU-0c; Tue, 19 Jan 2016 09:27:11 -0500 From: Mark H Weaver To: bug-guix@gnu.org Subject: wget rejects Let's Encrypt certs, although Icecat accepts them Date: Tue, 19 Jan 2016 09:27:09 -0500 Message-ID: <87twm9tzk2.fsf@netris.org> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.6.x X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.6.x X-Received-From: 2001:4830:134:3::11 X-Spam-Score: -5.0 (-----) X-Debbugs-Envelope-To: submit X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -5.0 (-----) On recent GuixSD, IceCat accepts the Let's Encrypt certificate from https://git.dthompson.us/, but 'wget' rejects it: mhw@jojen:~$ wget https://git.dthompson.us/presentations.git/blob/HEAD:/g= uix-blu-2016-01-20.pdf --2016-01-19 09:23:23-- https://git.dthompson.us/presentations.git/blob/= HEAD:/guix-blu-2016-01-20.pdf Resolving git.dthompson.us (git.dthompson.us)... 23.92.20.238 Connecting to git.dthompson.us (git.dthompson.us)|23.92.20.238|:443... co= nnected. ERROR: The certificate of =E2=80=98git.dthompson.us=E2=80=99 is not trust= ed. ERROR: The certificate of =E2=80=98git.dthompson.us=E2=80=99 hasn't got a= known issuer. Mark From debbugs-submit-bounces@debbugs.gnu.org Wed Jan 20 00:03:52 2016 Received: (at 22408) by debbugs.gnu.org; 20 Jan 2016 05:03:52 +0000 Received: from localhost ([127.0.0.1]:54274 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84) (envelope-from ) id 1aLkvv-0006pb-FS for submit@debbugs.gnu.org; Wed, 20 Jan 2016 00:03:52 -0500 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:47238) by debbugs.gnu.org with esmtp (Exim 4.84) (envelope-from ) id 1aLkvu-0006pU-P6 for 22408@debbugs.gnu.org; Wed, 20 Jan 2016 00:03:51 -0500 Received: from compute1.internal (compute1.nyi.internal [10.202.2.41]) by mailout.nyi.internal (Postfix) with ESMTP id 99C3720750; Wed, 20 Jan 2016 00:03:50 -0500 (EST) Received: from frontend1 ([10.202.2.160]) by compute1.internal (MEProxy); Wed, 20 Jan 2016 00:03:50 -0500 DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=famulari.name; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-sasl-enc :x-sasl-enc; s=mesmtp; bh=fe0Zi5t5r4Ar9IQcT1bA+SEeXJ8=; b=RCk+pI ye+C+UgjZqukrIGDwJp5iHxNvpO44fcE+Kc/ZveMz/jUU1HG0OHtba6Zt4g97lgf dZRm9xtnFvgmrdS4BqzBdabG0RXZsYlufyetYWVqDUXo2i42a3go11j08mSh/Jku BBPtfmtfqQyAYto4iG7LfFVQ+BkpcINuPxoUY= DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-sasl-enc:x-sasl-enc; s=smtpout; bh=fe0Zi5t5r4Ar9IQ cT1bA+SEeXJ8=; b=N/1YLSE6noPnv1gk4Vba/6uTAxbsCtqTNr8csJrJBF7IYsy BO8xV0OgaeQMHGVUGXNfas3R22fT8r9SvPTtOWWtKbmxy8cwcNwNy4dsKKl2c4zS peaZIB9Zb3CaQGl5DwSXKG83FHPRrXg769YgURYIe7qNAyvQRhuVvbwu3ICU= X-Sasl-enc: uMs+m0ztWXmPoWB49ZsJzt4r6XitUbfQJWntlYj8RRr+ 1453266230 Received: from localhost (c-69-249-5-231.hsd1.pa.comcast.net [69.249.5.231]) by mail.messagingengine.com (Postfix) with ESMTPA id 4AEA2C01714; Wed, 20 Jan 2016 00:03:50 -0500 (EST) Date: Wed, 20 Jan 2016 00:03:49 -0500 From: Leo Famulari To: Mark H Weaver Subject: Re: bug#22408: wget rejects Let's Encrypt certs, although Icecat accepts them Message-ID: <20160120050349.GA5962@jasmine> References: <87twm9tzk2.fsf@netris.org> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <87twm9tzk2.fsf@netris.org> User-Agent: Mutt/1.5.24 (2015-08-30) X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: 22408 Cc: 22408@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -0.7 (/) On Tue, Jan 19, 2016 at 09:27:09AM -0500, Mark H Weaver wrote: > On recent GuixSD, IceCat accepts the Let's Encrypt certificate from > https://git.dthompson.us/, but 'wget' rejects it: > > mhw@jojen:~$ wget https://git.dthompson.us/presentations.git/blob/HEAD:/guix-blu-2016-01-20.pdf > --2016-01-19 09:23:23-- https://git.dthompson.us/presentations.git/blob/HEAD:/guix-blu-2016-01-20.pdf > Resolving git.dthompson.us (git.dthompson.us)... 23.92.20.238 > Connecting to git.dthompson.us (git.dthompson.us)|23.92.20.238|:443... connected. > ERROR: The certificate of ‘git.dthompson.us’ is not trusted. > ERROR: The certificate of ‘git.dthompson.us’ hasn't got a known issuer. I don't think this issue is specific to our packaging. On up-to-date Debian testing, I have the same result from Debian's wget. I don't know how good the ssllabs.com test is, but it did report some errors while testing the domain. Let's Encrypt certs can work in Debian's and Guix's wget. I could `wget --https-only` from my domain with a Let's Encrypt cert with HTTP Strict Transport Security enabled. > > Mark > > > From debbugs-submit-bounces@debbugs.gnu.org Sun Jan 24 08:27:36 2016 Received: (at 22408) by debbugs.gnu.org; 24 Jan 2016 13:27:36 +0000 Received: from localhost ([127.0.0.1]:32828 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84) (envelope-from ) id 1aNKha-0003k8-UH for submit@debbugs.gnu.org; Sun, 24 Jan 2016 08:27:36 -0500 Received: from perdizione.investici.org ([94.23.50.208]:47563) by debbugs.gnu.org with esmtp (Exim 4.84) (envelope-from ) id 1aNJnP-0000ne-NI for 22408@debbugs.gnu.org; Sun, 24 Jan 2016 07:29:33 -0500 Received: from [94.23.50.208] (perdizione [94.23.50.208]) (Authenticated sender: niasterisk@grrlz.net) by localhost (Postfix) with ESMTPSA id 6D9921205D1; Sun, 24 Jan 2016 12:29:27 +0000 (UTC) From: Ni* Gillmann To: Leo Famulari Subject: Re: bug#22408: wget rejects Let's Encrypt certs, although Icecat accepts them References: <87twm9tzk2.fsf@netris.org> <20160120050349.GA5962@jasmine> Date: Sun, 24 Jan 2016 13:29:24 +0100 In-Reply-To: <20160120050349.GA5962@jasmine> (Leo Famulari's message of "Wed, 20 Jan 2016 00:03:49 -0500") Message-ID: <87h9i3b1p7.fsf@grrlz.net> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.5 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Spam-Score: -0.0 (/) X-Debbugs-Envelope-To: 22408 X-Mailman-Approved-At: Sun, 24 Jan 2016 08:27:34 -0500 Cc: Mark H Weaver , 22408@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -0.0 (/) Leo Famulari writes: > On Tue, Jan 19, 2016 at 09:27:09AM -0500, Mark H Weaver wrote: >> On recent GuixSD, IceCat accepts the Let's Encrypt certificate from >> https://git.dthompson.us/, but 'wget' rejects it: >>=20 >> mhw@jojen:~$ wget https://git.dthompson.us/presentations.git/blob/HEAD= :/guix-blu-2016-01-20.pdf >> --2016-01-19 09:23:23-- https://git.dthompson.us/presentations.git/bl= ob/HEAD:/guix-blu-2016-01-20.pdf >> Resolving git.dthompson.us (git.dthompson.us)... 23.92.20.238 >> Connecting to git.dthompson.us (git.dthompson.us)|23.92.20.238|:443...= connected. >> ERROR: The certificate of =E2=80=98git.dthompson.us=E2=80=99 is not tr= usted. >> ERROR: The certificate of =E2=80=98git.dthompson.us=E2=80=99 hasn't go= t a known issuer. > > I don't think this issue is specific to our packaging. On up-to-date > Debian testing, I have the same result from Debian's wget. > > I don't know how good the ssllabs.com test is, but it did report some > errors while testing the domain. > > Let's Encrypt certs can work in Debian's and Guix's wget. I could `wget > --https-only` from my domain with a Let's Encrypt cert with HTTP Strict > Transport Security enabled. > > I could run on debian testing, last updated 16 hours ago, the following without issues: wget https://gedankenausbruch.com/downloadbereich/Hinweis%20beim%20Download= .txt running gnurl -O https://gedankenausbruch.com/downloadbereich/Hinweis%20beim%20Down= load.txt on up-to-date guixsd did work too. gedankenausbruch.com is signed by let's encrypt too: https://www.ssllabs.com/ssltest/analyze.html?d=3Dgedankenausbruch.com This doesn't prove anything, but I guess it's no bug but misconfiguration at dthompson.us ? >>=20 >> Mark >>=20 >>=20 >>=20 > > > --=20 ng/ni* vcard: http://krosos.sdf.org From debbugs-submit-bounces@debbugs.gnu.org Sun Mar 05 16:05:36 2017 Received: (at 22408-done) by debbugs.gnu.org; 5 Mar 2017 21:05:37 +0000 Received: from localhost ([127.0.0.1]:41402 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1ckdLU-0007dm-Om for submit@debbugs.gnu.org; Sun, 05 Mar 2017 16:05:36 -0500 Received: from out4-smtp.messagingengine.com ([66.111.4.28]:53520) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1ckdLS-0007de-Nm for 22408-done@debbugs.gnu.org; Sun, 05 Mar 2017 16:05:35 -0500 Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.nyi.internal (Postfix) with ESMTP id 9A89E20775; Sun, 5 Mar 2017 16:05:34 -0500 (EST) Received: from frontend1 ([10.202.2.160]) by compute4.internal (MEProxy); Sun, 05 Mar 2017 16:05:34 -0500 DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=famulari.name; h= content-type:date:from:in-reply-to:message-id:mime-version :references:subject:to:x-me-sender:x-me-sender:x-sasl-enc :x-sasl-enc; s=mesmtp; bh=6qFK2eQYu+GB9iHXquQQLr5caoo=; b=UBO2gq TES8k73CIJy8OSB9Ajobj+CAznzKd+L7++crvkj3Dpx7S6jGg3v7FkLq332Zzo6/ ebo21Gg3oSFu+jS5sLuQPSo2mT3q6PfKT957N1v8yKXIqZlLMX9ZDHtBR9oDqUcQ lfT40wniD/PI82v1i8ye2LLzXm7osfe28feeI= DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d= messagingengine.com; h=content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-sender :x-me-sender:x-sasl-enc:x-sasl-enc; s=smtpout; bh=6qFK2eQYu+GB9i HXquQQLr5caoo=; b=pxaH6U17UQMOrHRR7BUCXI1kryJUwZP+/DwwUO+Hw3M2mm ceyFcmOpYwYQhkT8TiYOsGeN0F6OxK8kLmJ68ia0kNcl4NkMhzBI4nd2ycda/zw+ F9RRdvLTzWpInp5xzyFRg5DR+TDaMmclGFJ+4Ny1Y1BPQfBeBi3t1czMy+U/o= X-ME-Sender: X-Sasl-enc: DzKVBgBmawymrT5LOXcu9iHiaVptOWVC9IyHh4yWQOrm 1488747934 Received: from localhost (c-73-188-17-148.hsd1.pa.comcast.net [73.188.17.148]) by mail.messagingengine.com (Postfix) with ESMTPA id 5B0507E1FF for <22408-done@debbugs.gnu.org>; Sun, 5 Mar 2017 16:05:34 -0500 (EST) Date: Sun, 5 Mar 2017 16:05:33 -0500 From: Leo Famulari To: 22408-done@debbugs.gnu.org Subject: Re: bug#22408: wget rejects Let's Encrypt certs, although Icecat accepts them Message-ID: <20170305210533.GA3145@jasmine> References: <87twm9tzk2.fsf@netris.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="2oS5YaxWCcQjTEyO" Content-Disposition: inline In-Reply-To: <87twm9tzk2.fsf@netris.org> User-Agent: Mutt/1.8.0 (2017-02-23) X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: 22408-done X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -0.7 (/) --2oS5YaxWCcQjTEyO Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Jan 19, 2016 at 09:27:09AM -0500, Mark H Weaver wrote: > On recent GuixSD, IceCat accepts the Let's Encrypt certificate from > https://git.dthompson.us/, but 'wget' rejects it: >=20 > mhw@jojen:~$ wget https://git.dthompson.us/presentations.git/blob/HEAD:= /guix-blu-2016-01-20.pdf This works for me on GuixSD, so I'm closing the bug. --2oS5YaxWCcQjTEyO Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAli8fZ0ACgkQJkb6MLrK fwhQnA/9FJHQflaOW+eXBGTE9WK3BHb493erNRX8zWec79MeZp33DzZ3mWUZLpbB AfoVyn+KgQmrAJYj14Ku+1y6TaBTjUb6AjXgYuMXIKh1OkguV1iQzrf256C3Livf mCJ0QrlThB+e5v+tHwWLsn+WhgxWFGVuoHHh9MhHbS+Cnl0PVuhkLooXJGVKuxnG btr/GdK1Yr+V8weKQPZVixyLFTdXetGCMS8AvC0Whr/d2abXQtb+YVH4WTnUxImj 64g22EjD10ScxzNEnfmzeuYmMZGewbFveuhckop9Jq9v2OJSmO4idyN0aAnoOe5O vI3Tvhvc+JeJxOSIK7ORUUMg1ezIsoih4BMApaEypNHPBGk9xClrXWWVSk5BJ/JD aoVhUJQoJRkTFPzbhAYga307it9Us3mfbPR/KXan+H12/4zw+5vV70MR1tdFsMea FD8FmQpi/touj5Z29EN6Eox/cqGZUTUBJ5VmGg4l40QsRl3tnsrd3Dh0kCQrsC0p UbYFyxjLtqAE6RgCPWaIAbfMK52bbJbFs+DY9HsIHgPIxv7AP6/aSkzPEqhjde3d L7pK/8B+/X/Ge2CCSTVoYqlCDKh7XYDh5Y85n9nkdmwGGtSc8B0rE6ntf6zf6v8T mEEqUDZ/KvWNL5GeMGxesMxQArl7KysOq/JsN1KLPJg6p92s6sc= =HTmg -----END PGP SIGNATURE----- --2oS5YaxWCcQjTEyO-- From unknown Sat Jun 14 18:05:41 2025 Received: (at fakecontrol) by fakecontrolmessage; To: internal_control@debbugs.gnu.org From: Debbugs Internal Request Subject: Internal Control Message-Id: bug archived. Date: Mon, 03 Apr 2017 11:24:03 +0000 User-Agent: Fakemail v42.6.9 # This is a fake control message. # # The action: # bug archived. thanks # This fakemail brought to you by your local debbugs # administrator