Bug 29858 - Filezilla warns about the certificate but checkbox to trust the certificate is disabled
Summary: Filezilla warns about the certificate but checkbox to trust the certificate i...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal minor
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-01-08 13:03 CET by Muhammad Tailounie
Modified: 2022-01-12 19:25 CET (History)
1 user (show)

See Also:
Source RPM: filezilla-3.55.0-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description Muhammad Tailounie 2022-01-08 13:03:39 CET
I use Letsencrypt certificates for my PureFTPd server on Mageia.

After the latest renewal of my certificate, I got a warning from Filezilla about it, however, this time the checkbox, which allows to trust the certificate, is disabled. This results in a warning about the certificate every time I connect.
Comment 1 Lewis Smith 2022-01-09 10:39:14 CET
Thank you for the report.

> After the latest renewal of my certificate, I got a warning from
> Filezilla about it
Did you get this warning previously, or only since cert updates?

> this time the checkbox, which allows to trust the certificate, is disabled
So have you seen previously the warning with the checkbox enabled? If so, in what circumstances?

CC: (none) => lewyssmith
Source RPM: (none) => filezilla-3.55.0-1.mga8.src.rpm

Comment 2 Muhammad Tailounie 2022-01-09 10:52:22 CET
Hi Lewis;

I used to get this warning whenever the certificate was renewed, that is every three months approximately.

So upon renewal Filezilla did warn me, but I always could tick the checkbox to trust the certificate. This time the checkboxes for trusting the certificate and trust the alternative names within are greyed out, where it is impossible to tick them.
Comment 3 Lewis Smith 2022-01-09 11:08:38 CET
It seems that Filezilla has been updated during M8.
 $ rpm -q --last filezilla
 filezilla-3.55.0-1.mga8.x86_64 <date>
will show when (on my system end July, ages ago).
Can you relate the changed behaviour to the update?

To check behaviour re the previous version:
 # urpmi --downgrade filezilla-3.51.0-3.mga8      [I think]
although this would mean waiting for your next certificate update.
Comment 4 Muhammad Tailounie 2022-01-09 11:18:56 CET
I downgraded it now, but I could not tick the checkbox either.

I'll try to delete the whole configuration for Filezilla and see if it works.
Comment 5 Lewis Smith 2022-01-11 20:01:30 CET
Thank you for the dowbgrade check. Can you report back on:
> I'll try to delete the whole configuration for Filezilla and see if it works
Comment 6 sturmvogel 2022-01-11 20:39:13 CET
In most cases when the checkbox is greyed out, the certificate is broken/invalid/not properly imported so thatt filezilla is forced to deny the acceptance.
https://www.google.com/search?q=filezilla+accept+certificate+greyed+out&oq=filezilla+accept+certificate+grey&aqs=chrome.1.69i57j33i22i29i30.24411j0j4&sourceid=chrome&ie=UTF-8
Comment 7 Muhammad Tailounie 2022-01-11 20:50:00 CET
@Lewis; deleting the configuration did not solve the issue.

@sturmvogel; the same certificate is used for the webserver, chat server and other services. I think that filezilla is just reporting the change of the server certificate upon renewal as usual. In the past it showed the warning and allowed me to trust the certificate. Unless something has changed with Letsencrypt chain, everything is still the same.
Comment 8 sturmvogel 2022-01-11 21:05:51 CET
Hm, maybe the Letsencrypt chain changed indeed:
https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/
Comment 9 Muhammad Tailounie 2022-01-11 22:11:01 CET
But according to this article and considering that the websites and the other services have no problem, I would only assume one of two unlikely issues:

1. Our filezilla in M8 is comiling against an older version of OpenSSL.
2. The ISRG Root X1 is not recognised (or bundled maybe!) by filezilla.

I am lost here!
Comment 10 Muhammad Tailounie 2022-01-12 09:37:26 CET
Solved with todays updates of nss and root certificate bundle :)

nss 3.74.0
rootcerts 20211213.00


Thank you all

Resolution: (none) => FIXED
Status: NEW => RESOLVED

Comment 11 Lewis Smith 2022-01-12 19:25:32 CET
And thank you for solving & closing it.

Note You need to log in before you can comment on or make changes to this bug.