mrw wrote:
> Well, yes, somewhat disgraceful behaviour. And it seems that you are
> being punished for it.
>
> I've never attempted to build or install OpenSSL, and have no idea how
> one configures it. So not much help available from these parts.
>
> I see that "/usr/bin/openssl version -a"
Ron F. wrote:
> I have been very bad.
Well, yes, somewhat disgraceful behaviour. And it seems that you are
being punished for it.
I've never attempted to build or install OpenSSL, and have no idea how
one configures it. So not much help available from these parts.
I see that
mrw wrote:
> Well that's one hypothesis blown away !
As I have been suspecting, I have messed up my install of openssl.
Setting SSL_CERT_DIR is a workaround that solves my problem with running
LMS, but the issue is that I had downloaded a new version of openssl
from Github in the recent past,
mrw wrote:
> I wonder what your OpenSSL system directory has inside it. Mine contains
> a -/usr/lib/ssl/certs- directory that is a symbolic link to
> -/etc/ssl/certs-, which contains the certificates. If yours doesn't do
> that, then maybe that is the source of the problem.
>
> FWIW (not much,
Ron F. wrote:
> PERL modules could now find where the certificates are kept on Ubuntu:
> /etc/ssl/certs.
>
> Why this became necessary I still do not understand and I don't know
> what the normal mechanism is that PERL uses to find ca-certificates, but
> this stopgap measure has taken care of
Good to have an answer.
As it was I found some more perl ssl tools which were going to be next
step. So for the record in case osmebody hasl similar issues.
https://github.com/noxxi/p5-ssl-tools
The analyze-ssl.pl - create a lot more tracing which might have helped
in this case.
bpa wrote:
> I always feel it is better to try to find root cause as often the
> problem can recur.
>
> When you used SSL_VERIFY_MODE you used a number value and not a string.
> Strings were used in older versions of the module.
>
> ...
>
Thanks bpa, for convincing me to stick with this
Have you tried analyze-ssl.pl from here
https://github.com/noxxi/p5-ssl-tools/blob/master/analyze-ssl.pl
bpa's Profile: http://forums.slimdevices.com/member.php?userid=1806
View this thread:
Ron F. wrote:
> Yes, I tried both of those things: refresh of ca-certificates, and a
> flush of DNS cache. No change. Before wiping this system and starting
> over with a fresh install of Ubuntu, I might try to see if I can see
> anything using Wireshark. I wonder if anything is going out when
bpa wrote:
> Unlikely to help.
>
> Have you tried refresh your certificates
> >
Code:
> >
> sudo update-ca-certificates --fresh
>
> >
>
> Did you see that Learnincurve solved their SSL problem (the reasonfor
> this thread) by clearing DNS
Ron F. wrote:
> Thank you for your help. I have tried lots of things, such as
> reinstalling openssl, making sure the correct versions of openssl and
> c_rehash are being called, reinstalled ca-certificates, etc., nothing
> has changed.
> .
> .
> I don't understand how this happened to begin
bpa wrote:
> I don't know SSL details - at a guess there is something wrong with your
> certificates.
>
> Not sure what to so but perhaps I'll read the following it may offer
> some pointers.
>
> https://maulwuff.de/research/ssl-debugging.html
Thank you for your help. I have tried lots of
Learnincurve wrote:
> My personal issue is RESOLVED and was DNS related. After flushing DNS
> caches and forcing a standard NS lookup on the firewall, everything is
> behaving normally, including mysqueezebox.com and apps listings. I am
> sorry to have generated so much noise on this list for
Learnincurve wrote:
> My personal issue is RESOLVED and was DNS related. After flushing DNS
> caches and forcing a standard NS lookup on the firewall, everything is
> behaving normally, including mysqueezebox.com and apps listings. I am
> sorry to have generated so much noise on this list for
My personal issue is RESOLVED and was DNS related. After flushing DNS
caches and forcing a standard NS lookup on the firewall, everything is
behaving normally, including mysqueezebox.com and apps listings. I am
sorry to have generated so much noise on this list for something that
was not LMS
Ron F. wrote:
> OK, I did that, here is what was returned:
Is the package -ca-certificates- installed ? Absence, or breakage, would
cause that error. Or -ca-certificates- just needs updating ?
Edit: crossed with @bpa.
Ron F. wrote:
> OK, I did that, here is what was returned:
I don't know SSL details - at a guess there is something wrong with your
certificates.
Not sure what to so but perhaps I'll read the following it may offer
some pointers.
https://maulwuff.de/research/ssl-debugging.html
bpa wrote:
> Yes an error. Enable module debugging with the following change
>
> >
Code:
> >
> use strict;
> use IO::Socket::SSL qw(debug3);
>
> # simple client
> my $cl = IO::Socket::SSL->new('www.google.com:443');
> print $cl "GET / HTTP/1.0\r\n\r\n";
Ron F. wrote:
> Sorry - I should have explained, what I see is:
> "Can't use an undefined value as a symbol reference at testSSL.pm line
> 6.!"
>
> I assume this means that $cl remains undefined because IO::Socket:SSL
> failed.
Yes an error. Enable module debugging with the following change
bpa wrote:
> Not very helpful in describing how it failed. What do you see ?
>
> I get the following which I think is a success even though it looks
> like a failure.
> >
Code:
> >
> HTTP/1.1 302 Found
> Server: nginx/1.16.1
> Date: Thu, 14 Nov 2019 22:54:53
Ron F. wrote:
> But this, a short PERL script, does not work:
Not very helpful in describing how it failed. What do you see ?
I get the following which I think is a success even though it looks
like a failure.
Code:
HTTP/1.1 302 Found
Server: nginx/1.16.1
bpa wrote:
> Different approach - similar to the "telnet 443" but more complete.
>
> Perl uses OpenSSL package to make a connection. The following command
> will make a secure connection using OpenSSL libraries, certs etc . to
> www.mysqueezebox.com
> >
Code:
> >
Different approach - similar to the "telnet 443" but more complete.
Perl uses OpenSSL package to make a connection. The following command
will make a secure connection using OpenSSL libraries, certs etc . to
www.mysqueezebox.com
Code:
openssl s_client -connect
Depending on how desperate you are to confirm/refute a https problem.
I just checked how to enable some Perl module IO::Socket::SSL logging
when LMS accesses a https URL. It generates lots of messages to console
(i.e. LMs must be run form a commandline) - most of which are "normal".
The LMS
Learnincurve wrote:
> but this looks like a wider problem than just mysqueezebox.com . LMS
> updates are not being retrieved from repos.squeezecommunity.org and I'm
> having trouble with sourceforge.
mysqueezebox stuff looks to be HHTTPS related.
Ignore any sourceforge errors - that site
d6jg wrote:
> mysqueezebox.com has the following DNS servers - for testing you could
> point your affected host at one of them but it will only resolve
> mysqueezebox.com addresses
>
> dns.usw.mysqueezebox.com
> dns.use.mysqueezebox.com
> dns.euw.mysqueezebox.com
>
> If you point at that and
d6jg wrote:
> I'm not saying the DNS lookup is wrong - I don't think it is - I think
> mySB.com operates on Amazon cloud on a number of different servers which
> are probably load balanced.
> What I'm saying is that the affected host is getting a correct DNS
> address but that either the route
Learnincurve wrote:
> Thanks for all the good suggestions and well spotted d6jg regarding the
> IP address. I'll start with a more thorough investigation of DNS on the
> affected host, compared with the working one and take it from there.
I'm not saying the DNS lookup is wrong - I don't think
Thanks for all the good suggestions and well spotted d6jg regarding the
IP address. I'll start with a more thorough investigation of DNS on the
affected host, compared with the working one and take it from there.
Learnincurve wrote:
>
>
> telnet bpa-code.github.io 443
> Trying 185.199.109.153...
> Connected to bpa-code.github.io.
> Escape character is '^]'.
>
> Could this point to a perl ssl issue? How do I check my perl modules?
Testing 443 connectivity is not enough. I don;t know details but have
Could there be an IPv6 issue here - I had to turn off IPv6 DNS lookup
because I kept getting timeout from my ISP. It meant every lookup was
slow.
bpa's Profile: http://forums.slimdevices.com/member.php?userid=1806
View
d6jg wrote:
> i think the traceroutes are indicating a routing failure. Id suggest
> running some further longer term jobs and then referring the results to
> your ISP.
Note also that the DNS resolves a different address for mySb.com on the
final traceroute and the only one that works.
i think the traceroutes are indicating a routing failure. Id suggest
running some further longer term jobs and then referring the results to
your ISP.
VB2.4[/B] STORAGE *QNAP TS419P (NFS)
[B]Living Room* - Joggler & SB3 -> Onkyo TS606 -> Celestion F20s
*Office* - Pi3+Sreen -> Sony TAFE320 ->
Learnincurve wrote:
> Thanks.
>
> Trying that:
> [19-11-13 20:02:06.2725] Slim::Networking::Repositories::__ANON__ (146)
> Failed to fetch
> https://bpa-code.github.io/bpaplugins/files/betarelease-repo.xml: 404
> Not Found
>
Try *https://bpa-code.github.io/bpaplugins/betarelease-repo.xml*
bpa wrote:
> Can't play mp3 files over https as such - I was looking for a radio
> station (ideally MP3) which uses https.
>
> All your problems seems to be https related. Possibly just
> mysqueeze.com. Sourceforge is unreliable (I get sourceforge timeout all
> the time) so these errors
Continuation...
regarding SSL:
telnet sourceforge.net 443
Trying 216.105.38.13...
Connected to sourceforge.net.
Escape character is '^]'.
Connection closed by foreign host.
telnet www.mysqueezebox.com 443
Trying 34.229.43.96...
^C
telnet www.mysqueezebox.com 80
Trying 34.229.43.96...
^C
Learnincurve wrote:
> "openssl is already the newest version (1.1.1-1ubuntu2.2)"
Tried deleting cache with no improvement:
2019-11-13 17:14:45 squeezeboxserver_safe started.
[19-11-13 17:14:46.4650] main::init (387) Starting Logitech Media Server
(v7.9.2, 1572699180, Sat Nov 2 14:13:52 CET
Learnincurve wrote:
> Can you give advice on how to play .mp3 files directly over https?
Can't play mp3 files over https as such - I was looking for a radio
station (ideally MP3) which uses https.
All your problems seems to be https related. Possibly just
mysqueeze.com. Sourceforge is
bpa wrote:
> When LMS is stopped there should only be cache.db -IIRC wal is for
> process locking and shm is shared memory maybe for performance. I'd
> delete all three. I delete cache.db everytime I start LMS as I do
> testing with internet streams and caching plays havok with trying to get
bpa wrote:
> When LMS is stopped there should only be cache.db -IIRC wal is for
> process locking and shm is shared memory maybe for performance. I'd
> delete all three. I delete cache.db everytime I start LMS as I do
> testing with internet streams and caching plays havok with trying to get
When LMS is stopped there should only be cache.db -IIRC wal is for
process locking and shm is shared memory maybe for performance. I'd
delete all three. I delete cache.db everytime I start LMS as I do
testing with internet streams and caching plays havok with trying to get
reproducible
Learnincurve wrote:
> Thanks for the advice, I see three cache.db files (when the server is
> running:
>
> locate cache.db
> /var/lib/squeezeboxserver/cache/cache.db
> /var/lib/squeezeboxserver/cache/cache.db-shm
> /var/lib/squeezeboxserver/cache/cache.db-wal
>
> Should I delete all three?
>
bpa wrote:
> Forgot to suggest one of the basics. Clear the caches when LMS is
> stopped. Clear the Browser cache and delete LMS cache.db
Thanks for the advice, I see three cache.db files (when the server is
running:
locate cache.db
/var/lib/squeezeboxserver/cache/cache.db
bpa wrote:
> IT could be a DNS issue. Can you enable logging for network.asyncdns
> to DEBUG and see what is logged when you try to play a plain internet
> stream e.g. something via Tune-in.
Here is some network info:
# systemd-resolve --status enp2s0
Link 2 (enp2s0)
Current Scopes: DNS
Forgot to suggest one of the basics. Clear the caches when LMS is
stopped. Clear the Browser cache and delete LMS cache.db
bpa's Profile: http://forums.slimdevices.com/member.php?userid=1806
View this thread:
IT could be a DNS issue. Can you enable logging for network.asyncdns
to DEBUG and see what is logged when you try to play a plain internet
stream e.g. something via Tune-in.
bpa's Profile:
bpa wrote:
> Do you have multiple network interfaces ?
>
> Is all internet LMS functionality broken but local network is OK (i.e
> can play files to local network connected player) ? or just some
> internet functionality is broken/erratic ?
>
> edit:
>
> What is the system
> DNS address ?
Learnincurve wrote:
> Thanks but unfortunately already tried that. :(
Do you have multiple network interfaces ?
Is all internet LMS functionality broken but local network is OK (i.e
can play files to local network connected player) ? or just some
internet functionality is broken/erratic ?
bpa wrote:
> Looks like network issue.
> A common problem is where LMS is started before the network connection
> is up & running. Then LMS will report no network yet network will be OK
> for all other application.
>
> To check this theory. Just stop & restart LMS - not Ubuntu and not the
>
Looks like network issue.
A common problem is where LMS is started before the network connection
is up & running. Then LMS will report no network yet network will be OK
for all other application.
To check this theory. Just stop & restart LMS - not Ubuntu and not the
network.
Learnincurve wrote:
> Hi,
>
> I've been running LMS for a few years, with Spotify - Spotty amd
> youtube apps. Both have shown up in LMS and on my player (squeezelite),
> but were suddenly gone from the LMS web interface (although still
> installed.
>
> The log is listing loads of
Hi,
I've been running LMS for a few years, with Spotify - Spotty amd
youtube apps. Both have shown up in LMS and on my player (squeezelite),
but were suddenly gone from the LMS web interface (although still
installed.
The log is listing loads of network-related errors, but network is fine
from
52 matches
Mail list logo