Bug#912522: [OpenSSL 1.1.1] error:1417C086:SSL routines:tls_process_client_certificate:certificate verify failed

2018-10-31 Thread Christian Schrötter
Hi Lars, sadly I've missed a small detail before submitting the bug report... Quote from Debian wiki [1]: > SHA-1 is no longer supported for signatures > in certificates and you need at least SHA-256. Node certificate: > Signature Algorithm: sha256WithRSAEncryption Master certificate: > Sign

Bug#912522: [OpenSSL 1.1.1] error:1417C086:SSL routines:tls_process_client_certificate:certificate verify failed

2018-10-31 Thread Lars Kruse
Hello Christian, thank you for reporting this issue! Am Thu, 1 Nov 2018 00:18:26 +0100 schrieb Christian Schrötter : > I've upgraded my Debian Buster system to OpenSSL 1.1.1-1 (and > libnet-ssleay-perl 1.85-2). Just in case it is easy for you to test: does the paranoid mode still works, if you

Bug#912522: [OpenSSL 1.1.1] error:1417C086:SSL routines:tls_process_client_certificate:certificate verify failed

2018-10-31 Thread Christian Schrötter
Severity: important Package: munin-node Version: 2.0.37-2 Dear maintainer, I've upgraded my Debian Buster system to OpenSSL 1.1.1-1 (and libnet-ssleay-perl 1.85-2). Now it's impossible to use paranoid TLS setup at Munin-Node: > tls paranoid > tls_verify_certificate yes > tls_private_key /etc/ssl