From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Noam Postavsky Newsgroups: gmane.emacs.bugs Subject: bug#31946: 27.0.50; The NSM should warn about more TLS problems Date: Mon, 09 Jul 2018 22:04:27 -0400 Message-ID: <87d0vvdexg.fsf@gmail.com> References: <87fu1apchn.fsf@gmail.com> <87sh4zlr6e.fsf@gmail.com> <871scdoli3.fsf@mouse.gnus.org> <877em5mva7.fsf@mouse.gnus.org> <87sh4td0kk.fsf@gmail.com> <877em5lcoz.fsf@mouse.gnus.org> NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: blaine.gmane.org 1531188191 10438 195.159.176.226 (10 Jul 2018 02:03:11 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Tue, 10 Jul 2018 02:03:11 +0000 (UTC) User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.1 (gnu/linux) Cc: 31946@debbugs.gnu.org To: Lars Ingebrigtsen Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Tue Jul 10 04:03:07 2018 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fchze-0002cu-VN for geb-bug-gnu-emacs@m.gmane.org; Tue, 10 Jul 2018 04:03:07 +0200 Original-Received: from localhost ([::1]:45375 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fci1m-00059j-40 for geb-bug-gnu-emacs@m.gmane.org; Mon, 09 Jul 2018 22:05:18 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:55382) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fci1a-000586-BO for bug-gnu-emacs@gnu.org; Mon, 09 Jul 2018 22:05:10 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fci1W-0001uk-DM for bug-gnu-emacs@gnu.org; Mon, 09 Jul 2018 22:05:06 -0400 Original-Received: from debbugs.gnu.org ([208.118.235.43]:45010) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1fci1W-0001ug-8r for bug-gnu-emacs@gnu.org; Mon, 09 Jul 2018 22:05:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1fci1W-0006nr-06 for bug-gnu-emacs@gnu.org; Mon, 09 Jul 2018 22:05:02 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Noam Postavsky Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Tue, 10 Jul 2018 02:05:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 31946 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: security Original-Received: via spool by 31946-submit@debbugs.gnu.org id=B31946.153118828526124 (code B ref 31946); Tue, 10 Jul 2018 02:05:01 +0000 Original-Received: (at 31946) by debbugs.gnu.org; 10 Jul 2018 02:04:45 +0000 Original-Received: from localhost ([127.0.0.1]:52907 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fci1B-0006nF-Dj for submit@debbugs.gnu.org; Mon, 09 Jul 2018 22:04:45 -0400 Original-Received: from mail-it0-f42.google.com ([209.85.214.42]:33068) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fci15-0006mv-6P for 31946@debbugs.gnu.org; Mon, 09 Jul 2018 22:04:39 -0400 Original-Received: by mail-it0-f42.google.com with SMTP id y124-v6so13464571itc.0 for <31946@debbugs.gnu.org>; Mon, 09 Jul 2018 19:04:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:references:date:in-reply-to:message-id :user-agent:mime-version; bh=hJyfglHzAiexE7EU8VgMk/1hZ2c6vzbyD3E+HNUatn4=; b=cBKqaJx8nESTAYA61g4tqoJC2vYRV//JL1w+Hce4CWCFK6goMyxZ1mPY7wQmNFqeuq dLVmQUpdvMvOXKZmk5727G9duQYkIJUAZHnCrDeQKTZmr0WxLmB//7Frc6D6qhrGz4Ol +b2bVAtxriAgxJepMvCYUS/nfzJHQzstCoEtWQUl3XnvGZhElJmJcu4s73LYf1xZiAeJ XxXNev3a6vn8DRTTK8Pt2ZqlJvPr6fI+MtTWY0XRRzXuW9aanUXcWHMYXT7S1uC0zD9h +3DiKRCF9Dz+YOYcemDlLns5cpmftox+xkOPPnGoSp5rQBRJvXuuxfV24x9Z56/sEc5t 4AsQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:references:date:in-reply-to :message-id:user-agent:mime-version; bh=hJyfglHzAiexE7EU8VgMk/1hZ2c6vzbyD3E+HNUatn4=; b=Uoc9U7KIu7DzV3YwVquwclxtIe8kEov56WWcAoo8ptZTVZRlK2yDYVCXSIsdTf7XXy D0NI+cY8wnUmc2jMffpsA8nq3LepBAmAxloL6oBpWtH4SeWwKg++67LcxUKlv7ZuJsnY 2/TxiR4JC7mqdDriNcyHdRbNQ7SsBxjHGMttC9VXwgdOjbxKu+Rs4kK93Qq4gXThdJ0G 1cC9qo6HC9tx7z3D3VeHyk2ZC1DEkhRF6iskqQByl50Zw8xqQiJv4p3JdyDZfXqV3/JA XdRaaefjBaORT4TPex1d6jUecqmHGacvMa1j5oDxXD97CMjfddzDj7PLl90cpEGM1bQi oT7A== X-Gm-Message-State: APt69E32r8gtMYmnG4ThfMrNU+hQB88YVC0cbAvhBQqEgJ93HT8Ra3bt LhvOD1n61RPuQqkBJsZF5aVvAw== X-Google-Smtp-Source: AAOMgpf9swxQvWPLxFDUCl8xJyJSwdjxFXhgIFl6MLqEEC7xS2q15VBpnE/yVf/aSn1kZ3VZ46hStA== X-Received: by 2002:a02:1506:: with SMTP id j6-v6mr19130199jad.30.1531188269408; Mon, 09 Jul 2018 19:04:29 -0700 (PDT) Original-Received: from zebian (cbl-45-2-119-34.yyz.frontiernetworks.ca. [45.2.119.34]) by smtp.googlemail.com with ESMTPSA id u125-v6sm6080795ita.4.2018.07.09.19.04.28 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Mon, 09 Jul 2018 19:04:28 -0700 (PDT) In-Reply-To: <877em5lcoz.fsf@mouse.gnus.org> (Lars Ingebrigtsen's message of "Sun, 08 Jul 2018 22:01:00 +0200") X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 208.118.235.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:148400 Archived-At: Lars Ingebrigtsen writes: > So we need a new way to determine whether a certificate is an > intermediate certificate. Unless that really is an intermediate > certificate and the warning is correct. :-) Going by the certificate serial number, Firefox doesn't show this certificate at all in the chain. The first two certificate serial numbers do match up, but Firefox shows 18:DA:D1:9E:26:7D:E8:BB:4A:21:58:CD:CC:6B:3B:4A for the 3rd one (root), while in Emacs the 3rd one has 25:0c:e8:e0:30:61:2e:9f:2b:89:f7:05:4d:7c:f8:fd. I'm even more confused...