<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">Hello Martin, hello list,<div><br></div><div>I just noticed problems with download again. It seems to be a certificate problem (CA). I tried the developer version just downloadad, same problem.</div><div>MOS is working.</div><div><br></div><div>The debug output below.</div><div><br></div><div>Any hints?</div><div><br></div><div>Thanks for your wonderful pca!</div><div><br></div><div>Thomas</div><div><br></div><div>pca -d 150162-02<br>Option download: 1<br>Option patchdir: /tmp/.<br>Option user: <user><br>Option passwd: <passwd><br>Option ignore: 121735<br>Option debug: 1<br>Command: /usr/local/bin/pca<br>ARGV: 150162-02<br>Version: 20140107-01<br>CWD: /tmp<br>Config files: /usr/local/bin/../etc/pca.conf <br>Found /usr/sfw/bin/wget (1.12, 11200, https)<br>Using /usr/sfw/bin/wget<br>Found /usr/bin/uname<br>Prerequisites for threads not met, setting threads to 0<br>Never update<br>Expanded patch list: 150162-02<br>xref mtime: Fri Jan 10 03:45:30 2014<br>xref now  : Mon Jan 13 14:33:47 2014<br>xref ctime: Mon Jan 13 14:32:49 2014<br>xref age  : 58<br>Local file /var/tmp/patchdiag.xref is up to date<br>osname from uname: SunOS<br>Reading from /usr/bin/showrev -p  2>/dev/null<br>patchdiag.xref size: 2348497<br>Using /var/tmp/patchdiag.xref from Jan/09/14<br>All operands are fully qualified patch IDs plus revisions<br>Host: xxxx (SunOS 5.10/Generic_150401-06/i386/i86pc)<br>List: 150162-02 (1/0)<br><br>Patch  IR   CR RSB Age Synopsis<br>------ -- - -- --- --- -------------------------------------------------------<br>150162 02 = 02 ---  91 SunOS 5.10_x86: nfssrv patch<br><br>Looking for 150162-02 (1/1)<br>Trying Oracle<br>Trying <a href="https://getupdates.oracle.com/">https://getupdates.oracle.com/</a> (1/1)<br>src: oracle, srcurl: <br>Adding to /tmp/pca.811466: header=Authorization: Basic <base64-user-passwd><br>/usr/sfw/bin/wget --progress=dot:binary --ca-certificate=/usr/local/bin/pca --secure-protocol=TLSv1 -O /tmp/./150162-02.zip "<a href="https://getupdates.oracle.com/all_unsigned/150162-02.zip">https://getupdates.oracle.com/all_unsigned/150162-02.zip</a>"<br>--2014-01-13 14:33:48--  <a href="https://getupdates.oracle.com/all_unsigned/150162-02.zip">https://getupdates.oracle.com/all_unsigned/150162-02.zip</a><br>Resolving getupdates.oracle.com... 141.146.44.51<br>Connecting to getupdates.oracle.com|141.146.44.51|:443... connected.<br>HTTP request sent, awaiting response... 301 Moved Permanently<br>Cookie coming from updates.oracle.com attempted to set domain to updates.oracle.com<br>Location: https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login?site2pstoretoken=v1.2~E4066BF0~EB48F0A1deletedsomecharsC1EA8D94D847CE1FB145BF9288CDC12D506FF77D1491F1E2F269FC45B3AC795A6AF30E2CED0BA4EB3C49790A9C660493454F598FD38C81C907A9E7F49E3441A73CB687641FC184BD2DA37F0CA1FC8B09F47CD832DBD083ECC6F85D [following]<br>--2014-01-13 14:33:49--  https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login?site2pstoretoken=v1.2~E4066BF0~EB48F0A1434Adeletedsomechars660493454F598FD38C81C907A9E7F49E3441A73CB687641FC184BD2DA37F0CA1FC8B09F47CD832DBD083ECC6F85D<br>Resolving login.oracle.com... 209.17.4.8<br>Connecting to login.oracle.com|209.17.4.8|:443... connected.<br>ERROR: cannot verify login.oracle.com's certificate, issued by `/C=US/O=VeriSign, Inc./OU=VeriSign Trust Network/OU=Terms of use at https://www.verisign.com/rpa (c)10/CN=VeriSign Class 3 International Server CA - G3':<br>  Unable to locally verify the issuer's authority.<br>To connect to login.oracle.com insecurely, use `--no-check-certificate'.<br>Removing /tmp/pca.811466<br>Failed (Unknown Error)<br>Failed (patch not found)<br>------------------------------------------------------------------------------<br>Download Summary: 1 total, 0 successful, 0 skipped, 1 failed</div><div><br></div><div><br><div><div>Am 07.01.2014 um 12:50 schrieb Martin Paul <<a href="mailto:martin.paul@univie.ac.at">martin.paul@univie.ac.at</a>>:</div><br class="Apple-interchange-newline"><blockquote type="cite">Happy new year to everbody!<br><br><blockquote type="cite">I'm running PCA as a proxy on a RHEL6 machine, Apparently, since early<br>December and an update to 6.5, it fails connecting to<br><a href="http://getupdates.oracle.com">getupdates.oracle.com</a> (through a web proxy) with a message saying:<br>Unable to establish SSL connection.<br></blockquote><br>Yeah, you had reported this problem already back in May 2013, and I had added the temporary fix for the CSW version of wget back then. The root cause was (and is) a problem with Oracle's web server:<br><br>  <a href="https://www.opencsw.org/mantis/view.php?id=5068">https://www.opencsw.org/mantis/view.php?id=5068</a><br><br>Oracle's web admin team planned to upgrade the web server to support clients with recent versions of OpenSSL, but it seems as if this never happened. They put a note into Support Document 1199543.1, which is still there:<br><br>  IMPORTANT:<br><br>  <a href="https://getupdates.oracle.com">https://getupdates.oracle.com</a> web server does not fully support TLS<br>  1.2. Only OpenSSL versions from branch 1.0.0 will work - Oracle<br>  Solaris does not deliver higher versions at this time.<br>  Customers who are trying to access the URL using latest wget/OpenSSL<br>  (ie. from <a href="http://www.opencsw.org">www.opencsw.org</a>) version with TLS 1.2 support may get<br>  connection failures.<br><br><blockquote type="cite">I'd say, just always add the parameter. It works with /usr/sfw/bin/wget<br>(in a recently patched S10 at least) as well as with wget on RHEL >= 5.<br></blockquote><br>Did exactly that in the current development release of PCA now. It seems as if the --secure-protocol option is supported in all relevant versions of wget, so this should do no harm.<br><br>Thanks for the report!<br><br>Martin.<br><br></blockquote></div><br><div apple-content-edited="true">
<div style="color: rgb(0, 0, 0); font-family: Verdana;  font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">--<br>Dr. Thomas Bleek, Netzwerkadministrator<br>Helmholtz-Zentrum Potsdam<br>Deutsches GeoForschungsZentrum<br>Telegrafenberg A20/225<br>D-14473 Potsdam<br>Tel.: +49 331 288- 1818/1681 Fax.: 1730 Mobil: +49 172 1543233<br>E-Mail: <a href="mailto:bl@gfz-potsdam.de">bl@gfz-potsdam.de</a></div>
</div>
<br></div></body></html>