Marcin, thanks for the report, and thanks for LANG=C, that's a serious help :)
Note that openssl s_client requires also giving a path to the CA root store to use, e.g.: openssl s_client -connect ebank.db-pbc.pl:443 -CApath /etc/ssl/certs/ It doesn't change this issue but may be useful for the future. Another URL for your bank's support staff: https://www.ssllabs.com/ssltest/analyze.html?d=ebank.db-pbc.pl Thanks -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1551615 Title: Alternative chain verification failure after 1024b root CAs removal To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/1551615/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
