<div dir="ltr">I get for example:<div><br></div><div><div>Resolving aru-akam-secure.oracle.com... 104.64.51.207</div><div>Connecting to <a href="http://aru-akam-secure.oracle.com">aru-akam-secure.oracle.com</a>|104.64.51.207|:443... connected.</div><div>ERROR: cannot verify <a href="http://aru-akam-secure.oracle.com">aru-akam-secure.oracle.com</a>'s certificate, issued by `/C=US/O=GeoTrust, Inc./CN=GeoTrust SSL CA':</div><div>  Unable to locally verify the issuer's authority.</div><div>ERROR: certificate common name `<a href="http://download-secure.oracle.com">download-secure.oracle.com</a>' doesn't match requested host name `<a href="http://aru-akam-secure.oracle.com">aru-akam-secure.oracle.com</a>'.</div><div>To connect to <a href="http://aru-akam-secure.oracle.com">aru-akam-secure.oracle.com</a> insecurely, use `--no-check-certificate'.</div><div>Removing /tmp/pca.412347</div><div>Failed (Unknown Error)</div><div>Failed (patch not found)</div></div><div><br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Mar 23, 2015 at 9:06 AM, Martin Paul <span dir="ltr"><<a href="mailto:martin.paul@univie.ac.at" target="_blank">martin.paul@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Thanks for providing the docs, Daniel!<br>
<br>
Doesn't look as if they were updated. Doc ID 1199543.1 (Patch download automation for Sun products using wget) was last updated 11-Feb-2014 and it does only mention the known certificates. Just to be sure - could you/somebody download and post getupdates.pem mentioned in that doc?<br>
<br>
BTW - Bernd Senf said that "--wgetopt=--secure-protocol=<u></u>TLSv1" was required for patch downloads to work as well - are you using a local copy of wget or the one provided with Solaris? See this note in the above document:<br>
<br>
IMPORTANT:<br>
<br>
"<a href="https://getupdates.oracle.com" target="_blank">https://getupdates.oracle.com</a> web server does not fully support TLS 1.2. Only OpenSSL versions from branch 1.0.0 will work - Oracle Solaris does not deliver higher versions at this time. Customers who are trying to access the URL using latest wget/OpenSSL (ie. from <a href="http://www.opencsw.org" target="_blank">www.opencsw.org</a>) version with TLS 1.2 support may get connection failures."<br>
<br>
Best,<br>
Martin.<br>
<br>
<br>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature">Ken Herold<br>Director, Library Information Systems<br>Hamilton College<br>198 College Hill Road<br>Clinton, NY 13323<br>315-859-4487<br><a href="mailto:kherold@hamilton.edu" target="_blank">kherold@hamilton.edu</a></div>
</div>