certificate of ‘debian.opennms.org’ has expired

Description

trying to install 25.2.0 on debian buster x64, the command
wget -O - https://debian.opennms.org/OPENNMS-GPG-KEY | apt-key add -

gives error
ERROR: The certificate of ‘debian.opennms.org’ is not trusted.
ERROR: The certificate of ‘debian.opennms.org’ doesn't have a known issuer.
The certificate's owner does not match hostname ‘debian.opennms.org’

but checking the certificate I've seen expiration date is Jan, 22 2020
so it's impossible any fresh installation on any version on Debian (and probably also on Ubuntu)

since it's not a real bug I changed type to task
the problem affects all versions

Environment

debian 10 x64

Acceptance / Success Criteria

None

Attachments

2

Lucidchart Diagrams

Activity

Show:

Ronny Trommer March 10, 2020 at 12:28 PM
Edited

Just checked from Germany and looks good from my point of the internet bubble.

Carlo Caminati March 10, 2020 at 9:53 AM

problem no longer occurs, but
maybe some mirrors out of date ?

Carlo Caminati March 10, 2020 at 9:46 AM

Hi
mhhh, DNS issue ?
for me debian.opennms.org is resolved to 46.101.211.239 and things seems to be working
unfortunately I did't checked the IP when things weren't working,
anyway if I point my browser to http://debian.opennms.org/dists/OPENNMS-GPG-KEY I can still access to the expired OPENNMS-GPG-KEY
(OPENNMS-GPG-KEY 2015-01-21 15:48 1.7K), maybe there is a mirror out-of-date ?

hint: opening a mirror with browser I get a warning message from my provider (see attached screenshot)

anyway for me the issue can be closed now

Ronny Trommer March 9, 2020 at 6:10 PM
Edited

Just ran this here against ny-1.mirrors.opennms.org

https://www.ssllabs.com/ssltest/analyze.html?d=debian.opennms.org&s=45.55.163.22

It's not super great but B graded and should work against

  • de-1.mirrors.opennms.org

  • debian-mirror.internal.opennms.com

  • debian.mirrors.opennms.org

  • debian.opennms.org

  • docs.mirrors.opennms.org

  • docs.opennms.org

  • maven-mirror.internal.opennms.com

  • maven.mirrors.opennms.org

  • mirror.internal.opennms.com

  • ny-1.mirrors.opennms.org

  • repo.opennms.org

  • sf-1.mirrors.opennms.org

  • tiles.mirrors.opennms.org

  • tiles.opennms.org

  • uk-1.mirrors.opennms.org

  • xmlns.mirrors.opennms.org

  • xmlns.opennms.org

  • yum-mirror.internal.opennms.com

  • yum.mirrors.opennms.org

  • yum.opennms.org/

Chris Manigan March 9, 2020 at 5:54 PM

Carlo, I'm sorry you are experiencing this problem. I have not been able to replicate your issue yet. Can you please let me know the IP address that you are resolving for debian.opennms.org? This will help me better troubleshoot which mirror might be causing an issue for you. I have tested against each of our mirrors and have not had an ssl error. Here is a sample result of my own testing:

Let me know the IP address of the mirror you are reaching and I will investigate further.

Cannot Reproduce

Details

Assignee

Reporter

Original estimate

Time tracking

No time logged1h remaining

Components

Priority

PagerDuty

Created February 25, 2020 at 6:02 PM
Updated March 10, 2020 at 12:32 PM
Resolved March 10, 2020 at 9:53 AM