Bug#795958: lynx-cur: certificate revocation checking is buggy

2015-08-18 Thread Vincent Lefevre
On 2015-08-18 13:48:33 +0200, Alessandro Ghedini wrote: > On Tue, Aug 18, 2015 at 01:32:19pm +0200, Vincent Lefevre wrote: > > openssl s_server -CAfile old.crt -key old.key -cert old.crt -www > > Try adding the "-status" option here. This doesn't change anything. > I think the problem is that

Bug#795958: lynx-cur: certificate revocation checking is buggy

2015-08-18 Thread Alessandro Ghedini
On Tue, Aug 18, 2015 at 01:32:19pm +0200, Vincent Lefevre wrote: > Package: lynx-cur > Version: 2.8.9dev6-3 > Severity: serious > Tags: security > > If I run > > lynx https://www.vinc17.net:4434/ > > I get > > SSL error:The certificate is NOT trusted. The certificate chain is revoked. > -

Bug#795958: lynx-cur: certificate revocation checking is buggy

2015-08-18 Thread Vincent Lefevre
Package: lynx-cur Version: 2.8.9dev6-3 Severity: serious Tags: security If I run lynx https://www.vinc17.net:4434/ I get SSL error:The certificate is NOT trusted. The certificate chain is revoked. -Continue? (n) as expected. But If I set up a test server with the same certificate with: