[pca] Problem https with wget

BABAULT.Daniel daniel.babault at mbda-systems.com
Fri Aug 14 13:47:12 CEST 2009


Thanks,

With last wget version (1.11.4)  I saw the reason in clear, for some unknown (for me) reason our proxy replace all certificates by a local certificate.

 

So I do cat our_certificate >> /patches/pca/pca  and It works

 

As there is no option to use external certificate file in pca.conf , I will have to do this each time I upgrade it

 

D at niel

 

 

________________________________

De : pca-bounces at lists.univie.ac.at [mailto:pca-bounces at lists.univie.ac.at] De la part de gavin.reid at itc.alstom.com
Envoyé : vendredi 14 août 2009 12:33
À : PCA (Patch Check Advanced) Discussion
Cc : PCA (Patch Check Advanced) Discussion; pca-bounces at lists.univie.ac.at
Objet : Re: [pca] Problem https with wget

 


Try and replace wget with a newer version .. it solved this problem for me 





"BABAULT.Daniel" <daniel.babault at mbda-systems.com>   
Sent by: pca-bounces at lists.univie.ac.at   

14.08.2009 11:35 

Please respond to:
"PCA \(Patch Check Advanced\) Discussion" <pca at lists.univie.ac.at>  

To

"PCA (Patch Check Advanced) Discussion" <pca at lists.univie.ac.at> 

cc

 

Subject

[pca] Problem https with wget

 

 

 




I have a  problem since some time : 
  
=================== 
root at aneto #  ./pca --debug --download 126538 
Option download: 1 
Option patchdir: /export/pca/. 
Option user: xxxxxx 
Option passwd: yyyyyyyy 
Option debug: 1 
ARGV: 126538 
Version: 20090723-01 
Config files: /etc/pca.conf 
Using /usr/sfw/bin/wget (1.10.2, 11002, https) 
Prerequisites for threads not met, setting threads to 0 
Never update 
Expanded patch list: 126538 
Downloading xref file to /var/tmp/patchdiag.xref 
Trying https://sunsolve.sun.com/patchdiag.xref (1/1) 
/usr/sfw/bin/wget "https://sunsolve.sun.com/patchdiag.xref" --ca-certificate=./pca -O /var/tmp/patchdiag.xref 
--11:20:20--  https://sunsolve.sun.com/patchdiag.xref 
           => `/var/tmp/patchdiag.xref' 
Connecting to 10.20.0.100:8080... connected. 
ERROR: Certificate verification error for sunsolve.sun.com: unable to get local issuer certificate 
To connect to sunsolve.sun.com insecurely, use `--no-check-certificate'. 
Unable to establish SSL connection. 
Failed 
Failed (patchdiag.xref not found) 
Reading from /usr/bin/showrev -p  2>/dev/null 
  
ERROR: Can't open xref file /var/tmp/patchdiag.xref (No such file or directory) 
Cleanup 
===================== 
  
My .wgetrc look like this 
  
proxy_user = xxxxx 
proxy_password = yyyyyyy 
http_proxy = 10.20.0.100:8080 
https_proxy = 10.20.0.100:8080 
ftp_proxy = 10.20.0.100:8080 
use_proxy = on 
# check-certificate=off 
wait = 45 
 ====================== 
  
If I put check-certificate to off, it works 
  
 ========== 
Connecting to 10.20.0.100:8080... connected. 
WARNING: Certificate verification error for sunsolve.sun.com: unable to get local issuer certificate 
Proxy request sent, awaiting response... 200 OK 
Length: 3,057,119 (2.9M) [text/plain] 
  
100%[========================================================================>] 3,057,119      3.63M/s 
  
11:26:00 (3.62 MB/s) - `/var/tmp/patchdiag.xref' saved [3057119/3057119] 
  
Reading from /usr/bin/showrev -p  2>/dev/null 
 ======== 
  

 ________________________________________________ 
Mes nouveaux numéros 
'Direct : +33 (0) 2 48 55 77 32 
'Secrétariat    : +33 (0) 2 48 55 77 46 
*Mobile : +33 (0) 6 68 48 29 94 
7 Fax           : +33 (0) 2 48 55 94 41 
_________________________________________________ 
Daniel BABAULT 
daniel.babault at mbda-systems.com 

Nouvelle adresse : 

MBDA France 
Rond point Marcel Hanriot 
Route d'Issoudun 
18020 Bourges Cedex 
P Avant d'imprimer ce courrier, réfléchissez à l'impact sur l'environnement, merci   
  

-------------- next part --------------
An HTML attachment was scrubbed...
URL: https://lists.univie.ac.at/mailman/private/pca/attachments/20090814/fa78d2a5/attachment-0001.html 


More information about the pca mailing list