From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Noam Postavsky Newsgroups: gmane.emacs.bugs Subject: bug#31946: 27.0.50; The NSM should warn about more TLS problems Date: Sun, 08 Jul 2018 14:50:03 -0400 Message-ID: <87sh4td0kk.fsf@gmail.com> References: <87fu1apchn.fsf@gmail.com> <87sh4zlr6e.fsf@gmail.com> <871scdoli3.fsf@mouse.gnus.org> <877em5mva7.fsf@mouse.gnus.org> NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: blaine.gmane.org 1531075750 32083 195.159.176.226 (8 Jul 2018 18:49:10 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Sun, 8 Jul 2018 18:49:10 +0000 (UTC) User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.1 (gnu/linux) Cc: 31946@debbugs.gnu.org To: Lars Ingebrigtsen Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Sun Jul 08 20:49:05 2018 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fcEk5-0008ES-Cq for geb-bug-gnu-emacs@m.gmane.org; Sun, 08 Jul 2018 20:49:05 +0200 Original-Received: from localhost ([::1]:37922 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fcEmA-0003NQ-Bc for geb-bug-gnu-emacs@m.gmane.org; Sun, 08 Jul 2018 14:51:16 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:41388) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fcEm3-0003LF-AY for bug-gnu-emacs@gnu.org; Sun, 08 Jul 2018 14:51:08 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fcEly-0004M5-9K for bug-gnu-emacs@gnu.org; Sun, 08 Jul 2018 14:51:07 -0400 Original-Received: from debbugs.gnu.org ([208.118.235.43]:43529) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1fcEly-0004Ly-4S for bug-gnu-emacs@gnu.org; Sun, 08 Jul 2018 14:51:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1fcElx-0005oG-R6 for bug-gnu-emacs@gnu.org; Sun, 08 Jul 2018 14:51:01 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Noam Postavsky Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Sun, 08 Jul 2018 18:51:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 31946 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: security Original-Received: via spool by 31946-submit@debbugs.gnu.org id=B31946.153107582122283 (code B ref 31946); Sun, 08 Jul 2018 18:51:01 +0000 Original-Received: (at 31946) by debbugs.gnu.org; 8 Jul 2018 18:50:21 +0000 Original-Received: from localhost ([127.0.0.1]:51426 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fcElE-0005nG-8n for submit@debbugs.gnu.org; Sun, 08 Jul 2018 14:50:21 -0400 Original-Received: from mail-it0-f42.google.com ([209.85.214.42]:33434) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fcEl8-0005n0-UD for 31946@debbugs.gnu.org; Sun, 08 Jul 2018 14:50:14 -0400 Original-Received: by mail-it0-f42.google.com with SMTP id y124-v6so9844117itc.0 for <31946@debbugs.gnu.org>; Sun, 08 Jul 2018 11:50:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:references:date:in-reply-to:message-id :user-agent:mime-version; bh=XerKKAAZTpkrvtQ1D91LZzCbBe1VIleMsQ9pTj526W8=; b=VyPWDvlyUTjnEvBf5YaMSNuaHTq2eTcss2j6auqTsLURnsIlXYfgGDE5I/+F57qVlF MERvw1yhJK/G1z4+6Dx68/B7Ut4quDW23sB7QA4lbDAO1aUaIXRC4+gxqDYIJ5KnsbHt TFoNcBnZEIcB3WjKG02D/RB4t6OyZCV5u2dao2lQcurjsJqRGFtFF4FKMMuUna2K61Z4 g1jKt+LfuE3kA7TwWJ4URVvBcimza4jbaKyeufxuFFD/dgzY9WBxiU6hOLdSZQNU2BmO ERxtmL5p2t8yxdG2tyOGbAmBXRfS6+Pe7wCom/smX4Y7lu53EM8TClGfN6ikDxCxDTK/ EhOg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:references:date:in-reply-to :message-id:user-agent:mime-version; bh=XerKKAAZTpkrvtQ1D91LZzCbBe1VIleMsQ9pTj526W8=; b=h/vLiW9EWZlwyQsL1L5xBFTFTyGXO/MU70ZxBiE1IcIG58cDDr7T8wvnaHfPSaG698 2aRs0N8WDVX6Uayv1khfnsMyplN7p8vv4iIyRr5jARZuDnAjO304iZ1MVN9ZY2VRM78j yaSP8qvVWSUebTXyXPBJvJHotFXteh7gU88yR34IrPX8yGz1ZaQy/b3gt6tsWEcZJ1yj rtYrVINpHF9sm+gzrAdbmRmAJC2JG6R/7ZXHjEG7Ty6r5jzRfuMTnBPX5SdTRnlwdhG/ HF6lNPhjQgWDlJ32GuqnpNjQJcSovCcS564/cA3oSYQuW4z+qFMd1+b2LlY0RLB8R8Rc Qi/A== X-Gm-Message-State: APt69E2YMLUNei5KVTlLRUfBGmmq6T1DcqKNdSUrzPq6fZJnLCbsoLc7 CH2q5rHwPCz4iDYuyxk3nTps/w== X-Google-Smtp-Source: AAOMgpcb35+cCdRY9Pv2xCvagjKTkmbZmAbpyEQ5cw8+pMvSkiQv67GcWRCpCQSMYaIANJSeDDtg8A== X-Received: by 2002:a02:9a10:: with SMTP id b16-v6mr15059552jal.4.1531075805197; Sun, 08 Jul 2018 11:50:05 -0700 (PDT) Original-Received: from zebian (cbl-45-2-119-34.yyz.frontiernetworks.ca. [45.2.119.34]) by smtp.googlemail.com with ESMTPSA id u125-v6sm4538551ita.4.2018.07.08.11.50.04 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Sun, 08 Jul 2018 11:50:04 -0700 (PDT) In-Reply-To: <877em5mva7.fsf@mouse.gnus.org> (Lars Ingebrigtsen's message of "Sun, 08 Jul 2018 20:34:08 +0200") X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 208.118.235.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:148358 Archived-At: Lars Ingebrigtsen writes: > Let's see. Here's the issuer/subjects from the three certificates in > the chain on that site when I use _dn3: > ("OU=Class 3 Public Primary Certification Authority,O=VeriSign\\, Inc.,C=US" . "CN=VeriSign Class 3 Public Primary Certification Authority - G5,OU=(c) 2006 VeriSign\\, Inc. - For authorized use only,OU=VeriSign Trust Network,O=VeriSign\\, Inc.,C=US")) > OK, and this is Firefox: > > CN = VeriSign Class 3 Public Primary Certification Authority - G5 > OU = "(c) 2006 VeriSign, Inc. - For authorized use only" > OU = VeriSign Trust Network > O = "VeriSign, Inc." > C = US > > Hm. Actually, aren't these all the same? Just in different order? The > _dn3 data seems to be the same as the _dn data, only rejuggled... Yeah, the _dn3 data still misses the CN=... from the issuer and is not equal the the subject for the root, so it doesn't seem to help this problem.