From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: Robert Pluim Newsgroups: gmane.emacs.bugs Subject: bug#55858: 28.1; process-async-https-with-delay failure Date: Thu, 09 Jun 2022 10:30:52 +0200 Message-ID: <877d5q2q83.fsf@gmail.com> References: <7ab5acbf-67a7-2c78-b9d7-eab2d02c7972@cornell.edu> <83mtem4db9.fsf@gnu.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="33769"; mail-complaints-to="usenet@ciao.gmane.io" Cc: 55858@debbugs.gnu.org, Ken Brown To: Eli Zaretskii Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Thu Jun 09 10:32:35 2022 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1nzDak-0008XP-1q for geb-bug-gnu-emacs@m.gmane-mx.org; Thu, 09 Jun 2022 10:32:34 +0200 Original-Received: from localhost ([::1]:60070 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1nzDaj-0001Qv-1M for geb-bug-gnu-emacs@m.gmane-mx.org; Thu, 09 Jun 2022 04:32:33 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:33508) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nzDaG-0001Q9-HU for bug-gnu-emacs@gnu.org; Thu, 09 Jun 2022 04:32:04 -0400 Original-Received: from debbugs.gnu.org ([209.51.188.43]:51021) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1nzDaE-0000MY-5T for bug-gnu-emacs@gnu.org; Thu, 09 Jun 2022 04:32:03 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1nzDaE-0004k8-2B for bug-gnu-emacs@gnu.org; Thu, 09 Jun 2022 04:32:02 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Robert Pluim Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Thu, 09 Jun 2022 08:32:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 55858 X-GNU-PR-Package: emacs Original-Received: via spool by 55858-submit@debbugs.gnu.org id=B55858.165476346518157 (code B ref 55858); Thu, 09 Jun 2022 08:32:02 +0000 Original-Received: (at 55858) by debbugs.gnu.org; 9 Jun 2022 08:31:05 +0000 Original-Received: from localhost ([127.0.0.1]:44918 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nzDZI-0004in-I6 for submit@debbugs.gnu.org; Thu, 09 Jun 2022 04:31:04 -0400 Original-Received: from mail-wm1-f52.google.com ([209.85.128.52]:38827) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nzDZF-0004iE-J3 for 55858@debbugs.gnu.org; Thu, 09 Jun 2022 04:31:02 -0400 Original-Received: by mail-wm1-f52.google.com with SMTP id m39-20020a05600c3b2700b0039c511ebbacso5529149wms.3 for <55858@debbugs.gnu.org>; Thu, 09 Jun 2022 01:31:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:cc:subject:references:date:in-reply-to:message-id :mime-version:content-transfer-encoding; bh=hUgeV/FEP5sZ3FE3rneKBkP8/jPbpAKUnZq213YBcXM=; b=pGGTVXSG+3zT8kirzGABRmtwlOna0g3N+8ocL1jS3DAmE9T9ICNLJ5YMlLXbD04z6+ LY0UrQw4q2KiMBlAkpNh8XHMt57oM+t437PAjru92aVD0yGw97wrNgfhQNyhokLmN4sG 3Ss2FNxmNeQO7IJRcEluZv7l2dz4Lc/moA4+UADcgWA/PkPXrvb7yOxWncBOfYTm/LKX AlK7xRET69f5ZEgQONfSvrVABadkaDqXB9GZH1rnRcE6iump/t9iYDKVLMVbri0PYgEp lrAFFwaOHVdW6+C5XuSV316QXkhc62Zk1yBRiUJgVFrGSX5xCpG3FE2/DEAFgbcJyJqd bT8Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:references:date:in-reply-to :message-id:mime-version:content-transfer-encoding; bh=hUgeV/FEP5sZ3FE3rneKBkP8/jPbpAKUnZq213YBcXM=; b=MnAN97utkT1+k6seo5W/VJ0HqY5h9G9KrCXUs8dNM46XcgsOckAoOVds8HcgeqcCIb KjySf741wDZW0reRRki94u/J1BSjE04dsXVn1f9QWDdsTaFY3hrUa3WJMsbkwK0W1sdm mNLiuVTv0em4bZS0qRRFqljpS+cpX6Dr1s8bggkkuJlzeuOcq2cB/gsooGcHQiFS9kX6 eld6qAad8lr8tcND08/FDjdoAC2OAhC0czuyxQWCGmbelFE+cG+YuTiC1zwuzM2vbZMl 5HdGoQBHTF5wfv3DMgyL01uSidvd9iJ7mLyyEuShDy/v2WUxpr7MVciF9+nfcbIMAbbd q3tg== X-Gm-Message-State: AOAM531oyra6Ezxe6+lfx5lQaHAbJfuD3bn+bfIkiWaBmF1nmU77Ggon xS0XD22Yyr6d3WCC2jT17w6A111ACOY= X-Google-Smtp-Source: ABdhPJyhS8npXyMyqxj2ii09t6RY9+vfKih2hQhemWGQ2AzV/uNojcgRh7OHmZouxU1pWrCEZesXkg== X-Received: by 2002:a05:600c:1d05:b0:397:6fd1:6959 with SMTP id l5-20020a05600c1d0500b003976fd16959mr2216481wms.202.1654763454789; Thu, 09 Jun 2022 01:30:54 -0700 (PDT) Original-Received: from rltb ([2a01:e0a:3f3:fb50:5cbc:89b2:9d48:3fdb]) by smtp.gmail.com with ESMTPSA id n20-20020a7bc5d4000000b0039aef592ca0sm26538003wmk.35.2022.06.09.01.30.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 09 Jun 2022 01:30:53 -0700 (PDT) In-Reply-To: <83mtem4db9.fsf@gnu.org> (Eli Zaretskii's message of "Thu, 09 Jun 2022 08:26:50 +0300") X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.io gmane.emacs.bugs:234026 Archived-At: >>>>> On Thu, 09 Jun 2022 08:26:50 +0300, Eli Zaretskii said: >> There are two issues here. First, there's obviously something I sho= uld >> do on my system so that the TLS certificate for elpa.gnu.org is >> trusted. I know nothing about TLS certificates and would appreciate >> help here. Eli> Not sure about Cygwin, but in general on MS-Windows GnuTLS uses the Eli> system certificate store to verify certificates. The particular Eli> problem above should be solved by upgrading GnuTLS and perhaps also Eli> updating the system certificate store (which should be in general Eli> always up to date, but I don't know how that system is maintained). This might be the Let's Encrypt cross-signing certificate expiry issue, which is fixed in GnuTLS >=3D 3.6.14 See eg Eli> OTOH, if Cygwin GnuTLS uses the Posix mechanism of certificate sto= res Eli> on disk files, then upgrading the certificate files. If I=CA=BCm right, it=CA=BCs a problem in GnuTLS, not an issue with the certificate store. Alternatively, we could just let-bind `network-security-level' to 'low in that test, which effectively disables the checking. Robert --=20