IRC log of #maemo for Tuesday, 2016-02-09

DocScrutinizer05Vajb_: it's no bug, it's an error in wiki or wherever you got the vibrator dbus-send command from. It should have --type=method_call and there's actually no other way than redirecting output >/dev/null00:51
jonwilbah, still no closer to figuring out why so many https sites dont work now that I have updated the root CA certificate store00:55
DocScrutinizer05isn't there a cmdline tool to evaluate the certificate chain of an arbitrary site?00:56 and sslanalyzer.comodoca.com01:01
jonwilAt this point my guess is that NSS in Maemo is too old to handle certain certificates in the new root CA store for some reason01:19
DocScrutinizer05looks like online tools to evaluate a forgein or own server01:19
DocScrutinizer05unrelated nice stuff:
DocScrutinizer05fstab:  /home/jr/Musik                                                   /home/jr/mp3cnv      fuse.mp3fs ro,users,bitrate=192         0 0   #still needs `mount ~/mp3cnv` by user, when root does it the whole thing is completely untouchable in userspace, prolly thanks to systemd and dang cgroups and stuff02:30
DocScrutinizer05if the whole thing goes south (it does sometimes, when there are broken .flac files), you need `fusermount -u ~/mp3cnv` since umount blows chunks02:33
luf_I want to assign and close some bug reports on Who can grant me permission to do it?03:47
luf_Does somebody has such permission to assign/close/... bugs?03:48
OksanaFind assigned/closed bugs and look up who assigned-closed them?03:54
DocScrutinizer05I'd send a mail to council, that's clearly a question for them to answer04:25
DocScrutinizer05last bugmaster I seem to remember was Andre_Klapper(?) - council might have assigned the role to somebody else meanwhile04:28
DocScrutinizer05I guess there are a few guys who can close bugs, however only council could assign the permissions to you to do so04:30
infobotDocScrutinizer05 meant: I guess there are a few guys who can close bugs, however only council could grant the permissions to you to do so04:32
DocScrutinizer05 even04:39
jonwilNo closer to finding a way to get NSS to give me more info on why it isn't working with certain domains/CAs (e.g. entrust)05:40
Vajb_bencoh: ok05:48
Vajb_DocScrutinizer05: I got it from phone control wiki page. Should i add that method-call to script?05:49
* jonwil wishes this community had someone who knew stuff about microb-engine, gecko, nss, certs, ssl etc :(05:51
OksanaSomeday. What's the package with certificates, what's the package using them and complaining about them, and what change started the complaints?05:53
* Oksana wonders why so many people do not register with NickServ; is it such a hardship? It's not like they don't give their email to curious minds on silver platter...05:55
Oksanabug #735705:58
povbotBug MfE is missing some CA cert symlinks on some devices (NuevaSync)05:58
jonwilI updated the root CA store in maemo-security-certman to the latest Mozilla root set and now a bunch of different sites (for example any site using entrust as a CA including the entrust website itself) returns a "secure connection failed" error code sec_error_unknown_issuer. These sites all worked fine with the previous set of root CAs.05:59
jonwilAlso other sites (e.g. google) do work fine05:59
jonwilAnd I would bet that the same "failing" sites would work just fine on a build of Firefox with the same set of root CA certificates that I imported into Maemo06:00
OksanaNot sure...
*** vakkov has joined #maemo06:03
OksanaIn short: there is a chain of certificates, and if there is a link (intermediary) missing, you get an error?06:04
* Oksana does not know how to pick through them and figure out which one is problematic and how06:05
Oksanakeep in mind bug #621106:09
povbotBug Installed root certificates not used until browser restarted.06:09
jonwillets reboot just in case that somehow does something06:11
jonwil not that it will of course06:11
jonwilnope, nothing06:12
jonwilOksana: I am guessing you dont know what maemo-security-certman actually is06:12
jonwilor what it does06:12
OksanaManages SSL certificates for secure connection in everything, like microb, probably telepathy too?06:16
jonwilyes it holds the master root certificate store that microb uses (and other things too although not telepathy)06:16
jonwilwell maybe telepathy does I dont know06:16
jonwilbut definatly microb uses it for its root store06:17
OksanaAnd hence Maps and Conversations, too06:18
jonwilwell conversations doesn't ever use ssl or certificates for the web browser part06:18
OksanaLikely, yes06:19
Oksanajonwil: Rebooting did not help?06:52
jonwilI wasn't expecting it to given how maemo-security-certman works06:52
OksanaAny way to trace error to what exactly is wrong? To figure out the certificate it struggles with?06:53
OksanaEven just a visual tree of certificates depending on each other would help to pinpoint exactly what node is responsible for cascade, though having exact logs from program would be preferable06:54
jonwilI dont know but I am digging further into whether its possible to import a newer nss into microb or not07:02
jonwilthat would in theory give us support for the latest tls standards07:02
OksanaNice :-D07:02
OksanaAs long as it's not a memory-eater ;-) Or CPU-eater. Or space-eater07:03
jonwilhmmm maybe we wont get that support, that code seems to live elsewhere07:07
KotCzarnyjonwil, does openssl on maemo use the same cert store?07:50
jonwilno idea07:50
KotCzarnyopenssl can be handy tool to check such things07:50
KotCzarnylet me google the magic line07:51
jonwilI am using openssl s_client already07:51
KotCzarnydoes it work or fail on that problematic site?07:51
jonwilthat works07:53
KotCzarnywhat is your openssl version?07:54
KotCzarnyalso, can you pastebin openssl s_client -connect ?07:55
*** Sicelo009N has quit IRC07:58
jonwilits not just the one site, its a whole bunch of sites including
KotCzarnyms site works on stock certs08:08
jonwilthe fact that openssl s_client gives correct output when talking to failing sites with the new set of CAs installed means that the root CAs themselves aren08:14
jonwilaren't broken08:14
jonwilor missing08:14
jonwiland its something in nss or microb that is at fault08:14
KotCzarnyor it uses different set08:15
jonwilnope it doesn't08:15
jonwilopenssl and microb are using exactly the same set08:15
jonwilsince I used -CApath argument to openssl to point it at the set in maemo-security-certman (which is what microb is also using)08:15
jonwilso its definatly got something to do with nss or microb-engine code and not the set of root certs08:24
jonwilAt this point we need to find someone that understands nss and gecko and stuff08:41
jonwilFinding someone who understands that will help us get a newer version of all that stuff into microb-engine as well...08:42
*** Oksana has joined #maemo08:46
*** LauRoman has joined #maemo09:46
*** florian has joined #maemo10:23
*** msava has quit IRC12:13
*** msava has quit IRC12:34
*** hashcore has joined #maemo13:03
*** Sicelo009N has joined #maemo13:55
DocScrutinizer05jonwil: did you already add a 144 printf() lines?13:58
DocScrutinizer05I at times had programs that were half their original size after I cleaned out all printfs13:59
DocScrutinizer05ancient programming schemes ;-)14:00
jonwilbah, I cant properly debug browserd with gdb :(14:03
DocScrutinizer05no matter why, that's exactly the age old rationale behind ancient printf() 'debugging'14:18
zGrrmoin :)14:23
jonwiladding debug printfs is a pain when it takes 20 minutes to rebuild microb-engine every time14:53
KotCzarnysometimes its the easiest way15:00
DocScrutinizer05hmm, it took up to 30 minutes back when I used that technique, thus I added a *lot* of them so probability was high I would have one at the right place anyway. However it took a 2 or 3 spins to refine the printfs where stuff turned out te get more interesting15:20
KotCzarnyjonwil, also, add printf as a function or definition15:20
KotCzarnyso you can disable it easily later15:20
KotCzarny(without removing everything)15:20
*** Sicelo009N has joined #maemo15:22
WizzupWhy would gdb not be possible?15:29
*** Vajb_ has joined #maemo16:14
*** Vajb_ has left #maemo16:15
DocScrutinizer05shodan is awesome ;-P  so are some fools e.g. in USA
DocScrutinizer05admin admin16:20
DocScrutinizer05someone parking car. Owner coming home?16:22
DocScrutinizer05hmm no16:23
DocScrutinizer05of course the geolocation is mostly bogus16:39
*** Vajb has joined #maemo17:14
*** Sicelo009N has quit IRC18:25
*** shentey has joined #maemo20:41
*** shentey has quit IRC20:56
*** florian has joined #maemo21:42
xesOh... just noticed why modest was refusing to download last messages without any error notification... syslog: GLIB WARNING ** camel-imap-provider - Unexpected response from IMAP server: A00001 NO [ALERT] Please log in via your web browser: (Failure)22:08
sixwheeledbeast^xes: I have been having trouble with hotmail for a few weeks no idea why.22:10
xes..these gmail (security) warnings are really annoying22:11
xesanyway, it would be nice if modest could report such kind of imap "[ALERT]" messages22:15
sixwheeledbeast^I actually can't get any e-mails now by the looks of it, the other accounts have stopped updating.22:17
*** jonwil has joined #maemo23:30
*** luf_ has joined #maemo23:32
luf_Everything about seems very outdated. Does it mean we don't want change it?23:59

