[pca] Issue with wget on RHEL6.5

Thomas Bleek bl at gfz-potsdam.de
Mon Jan 13 14:42:28 CET 2014


Hello Martin, hello list,

I just noticed problems with download again. It seems to be a certificate problem (CA). I tried the developer version just downloadad, same problem.
MOS is working.

The debug output below.

Any hints?

Thanks for your wonderful pca!

Thomas

pca -d 150162-02
Option download: 1
Option patchdir: /tmp/.
Option user: <user>
Option passwd: <passwd>
Option ignore: 121735
Option debug: 1
Command: /usr/local/bin/pca
ARGV: 150162-02
Version: 20140107-01
CWD: /tmp
Config files: /usr/local/bin/../etc/pca.conf 
Found /usr/sfw/bin/wget (1.12, 11200, https)
Using /usr/sfw/bin/wget
Found /usr/bin/uname
Prerequisites for threads not met, setting threads to 0
Never update
Expanded patch list: 150162-02
xref mtime: Fri Jan 10 03:45:30 2014
xref now  : Mon Jan 13 14:33:47 2014
xref ctime: Mon Jan 13 14:32:49 2014
xref age  : 58
Local file /var/tmp/patchdiag.xref is up to date
osname from uname: SunOS
Reading from /usr/bin/showrev -p  2>/dev/null
patchdiag.xref size: 2348497
Using /var/tmp/patchdiag.xref from Jan/09/14
All operands are fully qualified patch IDs plus revisions
Host: xxxx (SunOS 5.10/Generic_150401-06/i386/i86pc)
List: 150162-02 (1/0)

Patch  IR   CR RSB Age Synopsis
------ -- - -- --- --- -------------------------------------------------------
150162 02 = 02 ---  91 SunOS 5.10_x86: nfssrv patch

Looking for 150162-02 (1/1)
Trying Oracle
Trying https://getupdates.oracle.com/ (1/1)
src: oracle, srcurl: 
Adding to /tmp/pca.811466: header=Authorization: Basic <base64-user-passwd>
/usr/sfw/bin/wget --progress=dot:binary --ca-certificate=/usr/local/bin/pca --secure-protocol=TLSv1 -O /tmp/./150162-02.zip "https://getupdates.oracle.com/all_unsigned/150162-02.zip"
--2014-01-13 14:33:48--  https://getupdates.oracle.com/all_unsigned/150162-02.zip
Resolving getupdates.oracle.com... 141.146.44.51
Connecting to getupdates.oracle.com|141.146.44.51|:443... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Cookie coming from updates.oracle.com attempted to set domain to updates.oracle.com
Location: https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login?site2pstoretoken=v1.2~E4066BF0~EB48F0A1deletedsomecharsC1EA8D94D847CE1FB145BF9288CDC12D506FF77D1491F1E2F269FC45B3AC795A6AF30E2CED0BA4EB3C49790A9C660493454F598FD38C81C907A9E7F49E3441A73CB687641FC184BD2DA37F0CA1FC8B09F47CD832DBD083ECC6F85D [following]
--2014-01-13 14:33:49--  https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login?site2pstoretoken=v1.2~E4066BF0~EB48F0A1434Adeletedsomechars660493454F598FD38C81C907A9E7F49E3441A73CB687641FC184BD2DA37F0CA1FC8B09F47CD832DBD083ECC6F85D
Resolving login.oracle.com... 209.17.4.8
Connecting to login.oracle.com|209.17.4.8|:443... connected.
ERROR: cannot verify login.oracle.com's certificate, issued by `/C=US/O=VeriSign, Inc./OU=VeriSign Trust Network/OU=Terms of use at https://www.verisign.com/rpa (c)10/CN=VeriSign Class 3 International Server CA - G3':
  Unable to locally verify the issuer's authority.
To connect to login.oracle.com insecurely, use `--no-check-certificate'.
Removing /tmp/pca.811466
Failed (Unknown Error)
Failed (patch not found)
------------------------------------------------------------------------------
Download Summary: 1 total, 0 successful, 0 skipped, 1 failed


Am 07.01.2014 um 12:50 schrieb Martin Paul <martin.paul at univie.ac.at>:

> Happy new year to everbody!
> 
>> I'm running PCA as a proxy on a RHEL6 machine, Apparently, since early
>> December and an update to 6.5, it fails connecting to
>> getupdates.oracle.com (through a web proxy) with a message saying:
>> Unable to establish SSL connection.
> 
> Yeah, you had reported this problem already back in May 2013, and I had added the temporary fix for the CSW version of wget back then. The root cause was (and is) a problem with Oracle's web server:
> 
>  https://www.opencsw.org/mantis/view.php?id=5068
> 
> Oracle's web admin team planned to upgrade the web server to support clients with recent versions of OpenSSL, but it seems as if this never happened. They put a note into Support Document 1199543.1, which is still there:
> 
>  IMPORTANT:
> 
>  https://getupdates.oracle.com web server does not fully support TLS
>  1.2. Only OpenSSL versions from branch 1.0.0 will work - Oracle
>  Solaris does not deliver higher versions at this time.
>  Customers who are trying to access the URL using latest wget/OpenSSL
>  (ie. from www.opencsw.org) version with TLS 1.2 support may get
>  connection failures.
> 
>> I'd say, just always add the parameter. It works with /usr/sfw/bin/wget
>> (in a recently patched S10 at least) as well as with wget on RHEL >= 5.
> 
> Did exactly that in the current development release of PCA now. It seems as if the --secure-protocol option is supported in all relevant versions of wget, so this should do no harm.
> 
> Thanks for the report!
> 
> Martin.
> 

--
Dr. Thomas Bleek, Netzwerkadministrator
Helmholtz-Zentrum Potsdam
Deutsches GeoForschungsZentrum
Telegrafenberg A20/225
D-14473 Potsdam
Tel.: +49 331 288- 1818/1681 Fax.: 1730 Mobil: +49 172 1543233
E-Mail: bl at gfz-potsdam.de

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.univie.ac.at/pipermail/pca/attachments/20140113/3f63ab54/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4685 bytes
Desc: not available
URL: <https://lists.univie.ac.at/pipermail/pca/attachments/20140113/3f63ab54/attachment.bin>


More information about the pca mailing list