Server certificate verification failed

srossi

Renowned Member
Sep 8, 2015
3
0
66
When I try to update one of our servers I get this error (Image attached).
 

Attachments

  • Selección_020.png
    Selección_020.png
    16.4 KB · Views: 30
We have license for our servers, I have this problem in only one server.


The repos are correct.
 
Could you check if the '/etc/apt/pve-repo-ca-certificates.crt' from the failing server differs with the file from one of your working?
If so, restore it from the working one.

If nothing differs, could you post the output from:
Code:
openssl x509 -in /etc/apt/pve-repo-ca-certificates.crt -text -noout

in [noparse]
Code:
 ...
[/noparse] tags.
 
The certificates are equals.

This is the output:

Code:
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 1 (0x1)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
        Validity
            Not Before: Sep 17 19:46:36 2006 GMT
            Not After : Sep 17 19:46:36 2036 GMT
        Subject: C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (4096 bit)
                Modulus:
                    00:c1:88:db:09:bc:6c:46:7c:78:9f:95:7b:b5:33:
                    90:f2:72:62:d6:c1:36:20:22:24:5e:ce:e9:77:f2:
                    43:0a:a2:06:64:a4:cc:8e:36:f8:38:e6:23:f0:6e:
                    6d:b1:3c:dd:72:a3:85:1c:a1:d3:3d:b4:33:2b:d3:
                    2f:af:fe:ea:b0:41:59:67:b6:c4:06:7d:0a:9e:74:
                    85:d6:79:4c:80:37:7a:df:39:05:52:59:f7:f4:1b:
                    46:43:a4:d2:85:85:d2:c3:71:f3:75:62:34:ba:2c:
                    8a:7f:1e:8f:ee:ed:34:d0:11:c7:96:cd:52:3d:ba:
                    33:d6:dd:4d:de:0b:3b:4a:4b:9f:c2:26:2f:fa:b5:
                    16:1c:72:35:77:ca:3c:5d:e6:ca:e1:26:8b:1a:36:
                    76:5c:01:db:74:14:25:fe:ed:b5:a0:88:0f:dd:78:
                    ca:2d:1f:07:97:30:01:2d:72:79:fa:46:d6:13:2a:
                    a8:b9:a6:ab:83:49:1d:e5:f2:ef:dd:e4:01:8e:18:
                    0a:8f:63:53:16:85:62:a9:0e:19:3a:cc:b5:66:a6:
                    c2:6b:74:07:e4:2b:e1:76:3e:b4:6d:d8:f6:44:e1:
                    73:62:1f:3b:c4:be:a0:53:56:25:6c:51:09:f7:aa:
                    ab:ca:bf:76:fd:6d:9b:f3:9d:db:bf:3d:66:bc:0c:
                    56:aa:af:98:48:95:3a:4b:df:a7:58:50:d9:38:75:
                    a9:5b:ea:43:0c:02:ff:99:eb:e8:6c:4d:70:5b:29:
                    65:9c:dd:aa:5d:cc:af:01:31:ec:0c:eb:d2:8d:e8:
                    ea:9c:7b:e6:6e:f7:27:66:0c:1a:48:d7:6e:42:e3:
                    3f:de:21:3e:7b:e1:0d:70:fb:63:aa:a8:6c:1a:54:
                    b4:5c:25:7a:c9:a2:c9:8b:16:a6:bb:2c:7e:17:5e:
                    05:4d:58:6e:12:1d:01:ee:12:10:0d:c6:32:7f:18:
                    ff:fc:f4:fa:cd:6e:91:e8:36:49:be:1a:48:69:8b:
                    c2:96:4d:1a:12:b2:69:17:c1:0a:90:d6:fa:79:22:
                    48:bf:ba:7b:69:f8:70:c7:fa:7a:37:d8:d8:0d:d2:
                    76:4f:57:ff:90:b7:e3:91:d2:dd:ef:c2:60:b7:67:
                    3a:dd:fe:aa:9c:f0:d4:8b:7f:72:22:ce:c6:9f:97:
                    b6:f8:af:8a:a0:10:a8:d9:fb:18:c6:b6:b5:5c:52:
                    3c:89:b6:19:2a:73:01:0a:0f:03:b3:12:60:f2:7a:
                    2f:81:db:a3:6e:ff:26:30:97:f5:8b:dd:89:57:b6:
                    ad:3d:b3:af:2b:c5:b7:76:02:f0:a5:d6:2b:9a:86:
                    14:2a:72:f6:e3:33:8c:5d:09:4b:13:df:bb:8c:74:
                    13:52:4b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: 
                CA:TRUE
            X509v3 Key Usage: 
                Digital Signature, Key Encipherment, Key Agreement, Certificate Sign, CRL Sign
            X509v3 Subject Key Identifier: 
                4E:0B:EF:1A:A4:40:5B:A5:17:69:87:30:CA:34:68:43:D0:41:AE:F2
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://cert.startcom.org/sfsca-crl.crl

                Full Name:
                  URI:http://crl.startcom.org/sfsca-crl.crl

            X509v3 Certificate Policies: 
                Policy: 1.3.6.1.4.1.23223.1.1.1
                  CPS: http://cert.startcom.org/policy.pdf
                  CPS: http://cert.startcom.org/intermediate.pdf
                  User Notice:
                    Organization: Start Commercial (StartCom) Ltd.
                    Number: 1
                    Explicit Text: Limited Liability, read the section *Legal Limitations* of the StartCom Certification Authority Policy available at http://cert.startcom.org/policy.pdf

            Netscape Cert Type: 
                SSL CA, S/MIME CA, Object Signing CA
            Netscape Comment: 
                StartCom Free SSL Certification Authority
    Signature Algorithm: sha1WithRSAEncryption
         16:6c:99:f4:66:0c:34:f5:d0:85:5e:7d:0a:ec:da:10:4e:38:
         1c:5e:df:a6:25:05:4b:91:32:c1:e8:3b:f1:3d:dd:44:09:5b:
         07:49:8a:29:cb:66:02:b7:b1:9a:f7:25:98:09:3c:8e:1b:e1:
         dd:36:87:2b:4b:bb:68:d3:39:66:3d:a0:26:c7:f2:39:91:1d:
         51:ab:82:7b:7e:d5:ce:5a:e4:e2:03:57:70:69:97:08:f9:5e:
         58:a6:0a:df:8c:06:9a:45:16:16:38:0a:5e:57:f6:62:c7:7a:
         02:05:e6:bc:1e:b5:f2:9e:f4:a9:29:83:f8:b2:14:e3:6e:28:
         87:44:c3:90:1a:de:38:a9:3c:ac:43:4d:64:45:ce:dd:28:a9:
         5c:f2:73:7b:04:f8:17:e8:ab:b1:f3:2e:5c:64:6e:73:31:3a:
         12:b8:bc:b3:11:e4:7d:8f:81:51:9a:3b:8d:89:f4:4d:93:66:
         7b:3c:03:ed:d3:9a:1d:9a:f3:65:50:f5:a0:d0:75:9f:2f:af:
         f0:ea:82:43:98:f8:69:9c:89:79:c4:43:8e:46:72:e3:64:36:
         12:af:f7:25:1e:38:89:90:77:7e:c3:6b:6a:b9:c3:cb:44:4b:
         ac:78:90:8b:e7:c7:2c:1e:4b:11:44:c8:34:52:27:cd:0a:5d:
         9f:85:c1:89:d5:1a:78:f2:95:10:53:32:dd:80:84:66:75:d9:
         b5:68:28:fb:61:2e:be:84:a8:38:c0:99:12:86:a5:1e:67:64:
         ad:06:2e:2f:a9:70:85:c7:96:0f:7c:89:65:f5:8e:43:54:0e:
         ab:dd:a5:80:39:94:60:c0:34:c9:96:70:2c:a3:12:f5:1f:48:
         7b:bd:1c:7e:6b:b7:9d:90:f4:22:3b:ae:f8:fc:2a:ca:fa:82:
         52:a0:ef:af:4b:55:93:eb:c1:b5:f0:22:8b:ac:34:4e:26:22:
         04:a1:87:2c:75:4a:b7:e5:7d:13:d7:b8:0c:64:c0:36:d2:c9:
         2f:86:12:8c:23:09:c1:1b:82:3b:73:49:a3:6a:57:87:94:e5:
         d6:78:c5:99:43:63:e3:4d:e0:77:2d:e1:65:99:72:69:04:1a:
         47:09:e6:0f:01:56:24:fb:1f:bf:0e:79:a9:58:2e:b9:c4:09:
         01:7e:95:ba:6d:00:06:3e:b2:ea:4a:10:39:d8:d0:2b:f5:bf:
         ec:75:bf:97:02:c5:09:1b:08:dc:55:37:e2:81:fb:37:84:43:
         62:20:ca:e7:56:4b:65:ea:fe:6c:c1:24:93:24:a1:34:eb:05:
         ff:9a:22:ae:9b:7d:3f:f1:65:51:0a:a6:30:6a:b3:f4:88:1c:
         80:0d:fc:72:8a:e8:83:5e