Bug 26729

Summary: Web Browsers complain about certificates.
Product: Mageia Reporter: Ezequiel Partida <ezequiel_partida>
Component: RPM PackagesAssignee: All Packagers <pkg-bugs>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: High CC: boulshet, davidwhodgins, ftg, luigiwalser, office, olav, sandogan, sorin, stephane.pontier, thierry.vignaud, wilcal.int
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: CVE:
Status comment:

Description Ezequiel Partida 2020-06-04 19:23:43 CEST
Description of problem:

I did a fresh install using the netinstaller for mageia 8.

The installation whent well.. but all browsers complain about bad certificates and it is impossible to browse.

It already has rootcerts-20200527.00-1.mga8.noarch.rpm but the same is installed on another PC with no problems at all.

Regards
Comment 1 Ezequiel Partida 2020-06-04 20:26:21 CEST
just to report that this same problem started happenning on my current system just a couple of minutes ago after an update


Regards
Comment 2 Dave Hodgins 2020-06-04 20:52:57 CEST
It's being discussed on the dev mailing list. It's due to problems getting the
new version of nss (needed for new firefox version) to build. Affects all
browsers, and anything using https connections.

CC: (none) => davidwhodgins

William Kenney 2020-06-04 21:12:28 CEST

CC: (none) => wilcal.int

Comment 3 Ezequiel Partida 2020-06-04 21:13:19 CEST
Thank You Dave!!
Comment 4 Lewis Smith 2020-06-04 22:10:27 CEST
See also bug 26709, bug 26716.

Assignee: bugsquad => pkg-bugs

Comment 5 William Kenney 2020-06-04 22:55:50 CEST
Confirm bug here
Comment 6 David Walser 2020-06-04 23:35:48 CEST
(In reply to Lewis Smith from comment #4)
> See also bug 26709, bug 26716.

The first is related to this, the second is not.

Try with:
p11-kit-0.23.20-4.mga8
nss-3.53.0-4.mga8

Once they are built and uploaded.

CC: (none) => luigiwalser

David Walser 2020-06-04 23:38:19 CEST

See Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=26711

Comment 7 David Walser 2020-06-05 16:27:11 CEST
Thierry said Chromium was still having a problem.  Let's see if p11-kit-0.23.20-5.mga8 helps.
GG HH 2020-06-06 00:42:53 CEST

CC: (none) => boulshet

Comment 8 dogan san 2020-06-07 16:01:52 CEST
David, I tried p11-kit-0.23.20-5.mga8 in my desktop installation but it also did not solve the issue. Meanwhile, I checked my Mageia 8 installation completed some weeks ago in VMware in my laptop and Firefox and Chrome works fine in that. I noticed that one earlier versions of P11(p11-kit-0.23.20-2.mga8) and nss(nss-3.53.0-2.mga8 and nss-3.52.0-2.mga8) has been installed in this PC. My question is do you have any quick or temporary solution to this or is there any way of downgrading these two rpm files ?

CC: (none) => sandogan

Comment 9 David Walser 2020-06-07 16:19:07 CEST
Not really.  Mozilla dropped libnssckbi.so without warning and there isn't a quick and simple solution to the problem that created.  The only workaround that might work is installing the Mageia 7 nss and firefox packages for now.
Comment 10 dogan san 2020-06-07 16:26:33 CEST
Installed ones are p11-kit-0.23.20-3.mga8 and nss-3.52.0-2.mga8.  Can you help me how I can install these Mageia 7 nss and Firefox packages ?
Comment 11 dogan san 2020-06-07 21:14:42 CEST
After several trials with various versions of Mageia 7 Firefox,nss ,library etc, I found a temporary solution with Firefox-78 Beta. Everything , all httpds sites work now. I am actually using Chrome but I can wait until Cauldron team finds a permanent solution
Comment 12 Sorin Toma 2020-06-08 02:25:22 CEST
Following this bug.

CC: (none) => sorin

Stéphane Pontier 2020-06-10 15:05:16 CEST

CC: (none) => stephane.pontier

Comment 13 Cristian Pîrîu 2020-06-11 12:11:34 CEST
This bug also affects KMail, images are not downloaded from servers. Maybe it should be given higher priority? Because it is a major disruption to users' workflow.

CC: (none) => office

Comment 14 GG HH 2020-06-11 13:14:22 CEST
would it be possible to rollback to the last working version until a fix is available ?
Comment 15 Frank Griffin 2020-06-11 14:14:06 CEST
Go to the 7.1 repository, get the lib64nss3-3.52.0-1.mga7.x86_64.rpm package, and then from the download directory issue:

rpm -U --force --nodeps --oldpackage lib64nss3-3.52.0-1.mga7.x86_64.rpm

Then restart firefox (or whatever) and all is well. 

You should add this to the urpmi skip list until a corrected 3.53 is provided, otherwise it will keep upgrading to the bad 3.53 rpm.

CC: (none) => ftg

Comment 16 Frank Griffin 2020-06-11 14:15:01 CEST
Addenda: that rpm is in 7.1/updates.
Comment 17 Cristian Pîrîu 2020-06-11 14:47:20 CEST
(In reply to Frank Griffin from comment #16)
> Addenda: that rpm is in 7.1/updates.


Thanks, I confirm the solution works!
Comment 18 David Walser 2020-06-11 21:40:34 CEST
Olav did work in Cauldron that should fix it.  However, I was hoping to not just copy what Fedora does, as that requires nssckbi.h to be carried in rootcerts, which will make maintaining it twice the work.  The parts that require that file should be able to be done in nss instead.

CC: (none) => olav, thierry.vignaud

Comment 19 Olav Vitters 2020-06-16 11:48:34 CEST
This should be working at the moment in Cauldron, no? I basically just pushed the work that Thierry did. After that other people did more stuff, after which I didn't see any complaints any more on the dev mailing list.

Priority: Normal => High

Comment 20 Cristian Pîrîu 2020-06-16 12:18:37 CEST
After applying the latest updates, everything is fine!
Comment 21 GG HH 2020-06-16 12:39:16 CEST
may be closed for me also
Comment 22 David Walser 2020-06-16 14:36:18 CEST
Olav, please see Comment 18.  It's working, but not really a good long-term solution.
Comment 23 Olav Vitters 2020-06-16 14:39:28 CEST
David: Who should take care of that bit?
Comment 24 David Walser 2020-06-16 14:43:24 CEST
Anyone who understands it well enough to be able to.  I will need to implement the final solution in Mageia 7 as well, and I'm holding off for now.
Comment 25 Thierry Vignaud 2020-06-16 14:47:51 CEST
Let's close the cauldron BZ (one can always clone it for mga7)

Resolution: (none) => FIXED
Status: NEW => RESOLVED

David Walser 2020-06-18 18:30:12 CEST

See Also: https://bugs.mageia.org/show_bug.cgi?id=26711 => (none)