Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.
Sign upGitHub is where the world builds software
Millions of developers and companies build, ship, and maintain their software on GitHub — the largest and most advanced development platform in the world.
certificate consern #1460
certificate consern #1460
Comments
|
The root CA is StartCom, which your system doesn't trust. I'll look into alternative certificates. We picked StartCom because it is simple, free and widely distributed. |
|
@phihag is this still an issue since the switch to GlobalSign? |
|
Yes still an issue with wget, curl works: $ wget https://yt-dl.org/downloads/2014.06.04/youtube-dl -O youtube-dl Do you use a CDN possibly? I converted the crt bundle that curl uses into a directory of pem files ( http://www.bsdtips.org/index.php/Split_PEM_certs ) with the names hashed appropriately, used --ca-directory= to point wget at it, and even verified with truss the the correct pem file is opened and read, yet it still fails with the above error. So check your SAN and CN in your cert? |
|
Here's an example showing success for this very https url: $ wget --verbose --ca-directory= 100%[======================================>] 45,586 --.-K/s in 0.04s 2014-06-05 14:00:12 (1.03 MB/s) - `1460.wget' saved [45586/45586] $ grep 'Yes still an' 1460.wget Yes still an issue with wget, curl works: |
|
It's been a while... @msliczniak Could you please confirm that this is still an issue? |
$ wget https://yt-dl.org/downloads/2013.09.17/youtube-dl -O youtube-dl-bin.py
--2013-09-19 16:42:22-- https://yt-dl.org/downloads/2013.09.17/youtube-dl
Resolving yt-dl.org (yt-dl.org)... 95.143.172.170, 2001:1a50:11:0:5f:8f:acaa:177
Connecting to yt-dl.org (yt-dl.org)|95.143.172.170|:443... connected.
ERROR: cannot verify yt-dl.org's certificate, issued by
/C=IL/O=StartCom Ltd./OU=Secure Digital Certificate Signing/CN=StartCom Class 2 Primary Intermediate Server CA': Unable to locally verify the issuer's authority. ERROR: no certificate subject alternative name matches requested host nameyt-dl.org'.To connect to yt-dl.org insecurely, use `--no-check-certificate'.
$ wget --version
GNU Wget 1.13.4 built on freebsd8.3.
+digest +https +ipv6 +iri +large-file +nls +ntlm +opie +ssl/openssl