getnonfreefonts: tug.org certificate errors
tkacvins at gmail.com
Sat Nov 6 23:50:34 CET 2021
On Sat, Nov 6, 2021 at 6:22 PM Karl Berry <karl at freefriends.org> wrote:
> | Resolving www.tug.org... 126.96.36.199
> | Connecting to www.tug.org|188.8.131.52|:443... connected.
> | ERROR: The certificate of 'www.tug.org' is not trusted.
> | ERROR: The certificate of 'www.tug.org' has expired.
> | ! Error: Can't execute wget.
> To the best of my knowledge, the certificates on the user's machine have
> to be updated. It's a network-wide issue, not related to tug.org or
> Here is a brief description and some further references:
I tried building the latest wget with the latest OpenSSL 1.1.1,
with the appropriate flags already set in the wget openssl support
code. That is, X509_VERIFY_PARAM_set_flags is called with the param
X509_V_FLAG_TRUSTED_FIRST. but this did not take. I now get this
Resolving www.tug.org (www.tug.org)... 184.108.40.206
Connecting to www.tug.org (www.tug.org)|220.127.116.11|:443... connected.
ERROR: The certificate of 'www.tug.org' is not trusted.
ERROR: The certificate of 'www.tug.org' has expired.
So the OpenSSL docs on how to work around this seems to be emitting
bogons. Will look at it some more because it seems for this use case,
the weak link is the client code (in this case, wget),
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the tex-live