Idk what happened here, or if it is SweeNet or just ZNC #2

Closed
opened 2025-08-16 17:57:57 -07:00 by swee · 1 comment
Owner

(Originally posted by @Depresst0 on Discourse)

For some reason *status in SweeNet dumped the certificate on the 4th of february.

07:11 PM <*status> Disconnected from IRC. Reconnecting...
07:12 PM <*status> Connected!
07:17 PM <*status> Disconnected from IRC. Reconnecting...
07:19 PM <*status> |Certificate:
07:19 PM <*status> Disconnected from IRC (Invalid SSL certificate: unable to get local issuer certificate, unable to verify the first certificate). Reconnecting...
07:19 PM <*status> |        Version: 3 (0x2)
07:19 PM <*status> |    Data:
07:19 PM <*status> |            04:ca:c2:73:18:2b:ac:06:1f:01:f3:14:7e:ac:a0:ce:69:d9
07:19 PM <*status> |        Serial Number:
07:19 PM <*status> |            Not Before: Jan 31 06:55:04 2025 GMT
07:19 PM <*status> |        Validity
07:19 PM <*status> |        Issuer: C=US, O=Let's Encrypt, CN=E5
07:19 PM <*status> |        Signature Algorithm: ecdsa-with-SHA384
07:19 PM <*status> |            Public Key Algorithm: id-ecPublicKey
07:19 PM <*status> |        Subject Public Key Info:
07:19 PM <*status> |        Subject: CN=*.ircat.xyz
07:19 PM <*status> |            Not After : May  1 06:55:03 2025 GMT
07:19 PM <*status> |                    fd:b0:05:8f:01
07:19 PM <*status> |                    98:32:6b:1a:ee:49:a3:5c:c5:72:4e:3e:59:9f:3a:
07:19 PM <*status> |                    c8:52:3a:b6:68:ff:4f:b3:1c:5b:1b:69:65:05:bf:
07:19 PM <*status> |                    e7:7e:3c:df:37:5e:b8:87:6f:90:85:3e:3b:09:11:
07:19 PM <*status> |                    04:76:b7:11:eb:6c:ed:e8:9a:af:72:ef:02:ca:0d:
07:19 PM <*status> |                pub:
07:19 PM <*status> |                Public-Key: (256 bit)
07:19 PM <*status> |        X509v3 extensions:
07:19 PM <*status> |                NIST CURVE: P-256
07:19 PM <*status> |                ASN1 OID: prime256v1
07:19 PM <*status> |            X509v3 Subject Key Identifier: 
07:19 PM <*status> |                CA:FALSE
07:19 PM <*status> |            X509v3 Basic Constraints: critical
07:19 PM <*status> |                TLS Web Server Authentication, TLS Web Client Authentication
07:19 PM <*status> |            X509v3 Extended Key Usage: 
07:19 PM <*status> |                Digital Signature
07:19 PM <*status> |            X509v3 Key Usage: critical
07:19 PM <*status> |            X509v3 Authority Key Identifier: 
07:19 PM <*status> |                AE:83:89:1A:E4:01:DD:5C:54:02:FF:BE:18:2F:4B:92:0D:01:86:E7
07:19 PM <*status> |                Policy: 2.23.140.1.2.1
07:19 PM <*status> |            X509v3 Certificate Policies: 
07:19 PM <*status> |                DNS:*.ircat.xyz
07:19 PM <*status> |            X509v3 Subject Alternative Name: 
07:19 PM <*status> |                CA Issuers - URI:http://e5.i.lencr.org/
07:19 PM <*status> |                OCSP - URI:http://e5.o.lencr.org
07:19 PM <*status> |            Authority Information Access: 
07:19 PM <*status> |                9F:2B:5F:CF:3C:21:4F:9D:04:B7:ED:2B:2C:C4:C6:70:8B:D2:D7:0D
07:19 PM <*status> |                    Timestamp : Jan 31 07:53:34.692 2025 GMT
07:19 PM <*status> |                                87:5C:14:A0:4E:95:9E:B9:03:2F:D9:0E:8C:2E:79:B8
07:19 PM <*status> |                    Log ID    : 7D:59:1E:12:E1:78:2A:7B:1C:61:67:7C:5E:FD:F8:D0:
07:19 PM <*status> |                    Version   : v1 (0x0)
07:19 PM <*status> |                Signed Certificate Timestamp:
07:19 PM <*status> |            CT Precertificate SCTs: 
07:19 PM <*status> |                Signed Certificate Timestamp:
07:19 PM <*status> |                                EB:31:5A:C1:B7:58
07:19 PM <*status> |                                26:63:C0:65:F9:02:B2:D9:5A:4B:1C:CD:83:15:E5:B3:
07:19 PM <*status> |                                68:47:C9:57:02:20:7F:87:B3:B2:12:6F:B2:19:DA:EB:
07:19 PM <*status> |                                5B:A7:CF:A2:11:EA:7B:B3:87:41:D6:99:40:65:CF:58:
07:19 PM <*status> |                                30:44:02:20:2D:FF:BC:A7:25:E2:15:67:87:C3:EB:99:
07:19 PM <*status> |                    Signature : ecdsa-with-SHA256
07:19 PM <*status> |                    Extensions: none
07:19 PM <*status> |                                30:44:02:20:79:20:D7:6D:07:D0:4F:70:95:10:66:55:
07:19 PM <*status> |                    Signature : ecdsa-with-SHA256
07:19 PM <*status> |                    Extensions: none
07:19 PM <*status> |                    Timestamp : Jan 31 07:53:34.882 2025 GMT
07:19 PM <*status> |                                16:B7:23:49:CE:58:57:6A:DF:AE:DA:A7:C2:AB:E0:22
07:19 PM <*status> |                    Log ID    : 13:4A:DF:1A:B5:98:42:09:78:0C:6F:EF:4C:7A:91:A4:
07:19 PM <*status> |                    Version   : v1 (0x0)
07:19 PM <*status> |        30:65:02:30:6c:c5:08:42:5b:ae:02:27:e5:90:a2:3f:7e:96:
07:19 PM <*status> |    Signature Value:
07:19 PM <*status> |    Signature Algorithm: ecdsa-with-SHA384
07:19 PM <*status> |                                00:6C:31:9A:A1:A6
07:19 PM <*status> |                                5D:15:80:21:CE:2A:FD:03:80:B0:A1:8E:24:CE:5A:F9:
07:19 PM <*status> |                                E3:BF:1A:EC:02:20:1C:04:2E:17:2E:23:EE:E3:24:6A:
07:19 PM <*status> |                                8D:1A:50:04:00:20:1B:4A:53:C3:3E:A9:B2:B4:A9:2F:
07:19 PM <*status> |        5c:43:60:4a:4a:1b:df:75:d6:89:29:9b:2e
07:19 PM <*status> |        84:93:7f:f2:b3:c0:86:cb:6a:df:dc:8f:b5:67:9a:5d:63:90:
07:19 PM <*status> |        00:e5:87:ea:53:c6:c3:bf:ad:6d:b6:93:e0:d6:a9:73:7c:be:
07:19 PM <*status> |        a0:92:7e:82:06:0e:5f:bd:1b:db:7d:91:58:85:a6:8b:02:31:
07:19 PM <*status> |        f6:6f:b4:65:eb:05:3b:e4:a7:90:09:90:bf:29:af:9f:35:29:
07:19 PM <*status> If you trust this certificate, do /znc AddTrustedServerFingerprint 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34
07:19 PM <*status> SHA-256: 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34
07:19 PM <*status> SHA1: 21:2f:0f:67:89:4d:be:c2:99:55:0b:d2:45:03:14:d1:10:0e:ab:fd
07:19 PM <*status> Disconnected from IRC. Reconnecting...
07:22 PM <*status> |Certificate:
07:22 PM <*status> Disconnected from IRC (Invalid SSL certificate: unable to get local issuer certificate, unable to verify the first certificate). Reconnecting...
07:22 PM <*status> |        Serial Number:
07:22 PM <*status> |        Version: 3 (0x2)
07:22 PM <*status> |    Data:
07:22 PM <*status> |            04:ca:c2:73:18:2b:ac:06:1f:01:f3:14:7e:ac:a0:ce:69:d9
07:22 PM <*status> |            Not After : May  1 06:55:03 2025 GMT
07:22 PM <*status> |            Not Before: Jan 31 06:55:04 2025 GMT
07:22 PM <*status> |        Validity
07:22 PM <*status> |        Issuer: C=US, O=Let's Encrypt, CN=E5
07:22 PM <*status> |        Signature Algorithm: ecdsa-with-SHA384
07:22 PM <*status> |                Public-Key: (256 bit)
07:22 PM <*status> |            Public Key Algorithm: id-ecPublicKey
07:22 PM <*status> |        Subject Public Key Info:
07:22 PM <*status> |        Subject: CN=*.ircat.xyz
07:22 PM <*status> |                    04:76:b7:11:eb:6c:ed:e8:9a:af:72:ef:02:ca:0d:
07:22 PM <*status> |                pub:
07:22 PM <*status> |                NIST CURVE: P-256
07:22 PM <*status> |                ASN1 OID: prime256v1
07:22 PM <*status> |                    fd:b0:05:8f:01
07:22 PM <*status> |                    98:32:6b:1a:ee:49:a3:5c:c5:72:4e:3e:59:9f:3a:
07:22 PM <*status> |                    c8:52:3a:b6:68:ff:4f:b3:1c:5b:1b:69:65:05:bf:
07:22 PM <*status> |                    e7:7e:3c:df:37:5e:b8:87:6f:90:85:3e:3b:09:11:
07:22 PM <*status> |                Digital Signature
07:22 PM <*status> |            X509v3 Key Usage: critical
07:22 PM <*status> |        X509v3 extensions:
07:22 PM <*status> |            X509v3 Subject Key Identifier: 
07:22 PM <*status> |                CA:FALSE
07:22 PM <*status> |            X509v3 Basic Constraints: critical
07:22 PM <*status> |                TLS Web Server Authentication, TLS Web Client Authentication
07:22 PM <*status> |            X509v3 Extended Key Usage: 
07:22 PM <*status> |                CA Issuers - URI:http://e5.i.lencr.org/
07:22 PM <*status> |                OCSP - URI:http://e5.o.lencr.org
07:22 PM <*status> |            Authority Information Access: 
07:22 PM <*status> |                9F:2B:5F:CF:3C:21:4F:9D:04:B7:ED:2B:2C:C4:C6:70:8B:D2:D7:0D
07:22 PM <*status> |            X509v3 Authority Key Identifier: 
07:22 PM <*status> |                AE:83:89:1A:E4:01:DD:5C:54:02:FF:BE:18:2F:4B:92:0D:01:86:E7
07:22 PM <*status> |            CT Precertificate SCTs: 
07:22 PM <*status> |                Policy: 2.23.140.1.2.1
07:22 PM <*status> |            X509v3 Certificate Policies: 
07:22 PM <*status> |                DNS:*.ircat.xyz
07:22 PM <*status> |            X509v3 Subject Alternative Name: 
07:22 PM <*status> |                    Timestamp : Jan 31 07:53:34.692 2025 GMT
07:22 PM <*status> |                                87:5C:14:A0:4E:95:9E:B9:03:2F:D9:0E:8C:2E:79:B8
07:22 PM <*status> |                    Log ID    : 7D:59:1E:12:E1:78:2A:7B:1C:61:67:7C:5E:FD:F8:D0:
07:22 PM <*status> |                    Version   : v1 (0x0)
07:22 PM <*status> |                Signed Certificate Timestamp:
07:22 PM <*status> |                                68:47:C9:57:02:20:7F:87:B3:B2:12:6F:B2:19:DA:EB:
07:22 PM <*status> |                                5B:A7:CF:A2:11:EA:7B:B3:87:41:D6:99:40:65:CF:58:
07:22 PM <*status> |                                30:44:02:20:2D:FF:BC:A7:25:E2:15:67:87:C3:EB:99:
07:22 PM <*status> |                    Signature : ecdsa-with-SHA256
07:22 PM <*status> |                    Extensions: none
07:22 PM <*status> |                    Log ID    : 13:4A:DF:1A:B5:98:42:09:78:0C:6F:EF:4C:7A:91:A4:
07:22 PM <*status> |                    Version   : v1 (0x0)
07:22 PM <*status> |                Signed Certificate Timestamp:
07:22 PM <*status> |                                EB:31:5A:C1:B7:58
07:22 PM <*status> |                                26:63:C0:65:F9:02:B2:D9:5A:4B:1C:CD:83:15:E5:B3:
07:22 PM <*status> |                                30:44:02:20:79:20:D7:6D:07:D0:4F:70:95:10:66:55:
07:22 PM <*status> |                    Signature : ecdsa-with-SHA256
07:22 PM <*status> |                    Extensions: none
07:22 PM <*status> |                    Timestamp : Jan 31 07:53:34.882 2025 GMT
07:22 PM <*status> |                                16:B7:23:49:CE:58:57:6A:DF:AE:DA:A7:C2:AB:E0:22
07:22 PM <*status> |                                5D:15:80:21:CE:2A:FD:03:80:B0:A1:8E:24:CE:5A:F9:
07:22 PM <*status> |                                E3:BF:1A:EC:02:20:1C:04:2E:17:2E:23:EE:E3:24:6A:
07:22 PM <*status> |                                8D:1A:50:04:00:20:1B:4A:53:C3:3E:A9:B2:B4:A9:2F:
07:22 PM <*status> |        f6:6f:b4:65:eb:05:3b:e4:a7:90:09:90:bf:29:af:9f:35:29:
07:22 PM <*status> |        30:65:02:30:6c:c5:08:42:5b:ae:02:27:e5:90:a2:3f:7e:96:
07:22 PM <*status> |    Signature Value:
07:22 PM <*status> |    Signature Algorithm: ecdsa-with-SHA384
07:22 PM <*status> |                                00:6C:31:9A:A1:A6
07:22 PM <*status> SHA1: 21:2f:0f:67:89:4d:be:c2:99:55:0b:d2:45:03:14:d1:10:0e:ab:fd
07:22 PM <*status> |        5c:43:60:4a:4a:1b:df:75:d6:89:29:9b:2e
07:22 PM <*status> |        84:93:7f:f2:b3:c0:86:cb:6a:df:dc:8f:b5:67:9a:5d:63:90:
07:22 PM <*status> |        00:e5:87:ea:53:c6:c3:bf:ad:6d:b6:93:e0:d6:a9:73:7c:be:
07:22 PM <*status> |        a0:92:7e:82:06:0e:5f:bd:1b:db:7d:91:58:85:a6:8b:02:31:
07:22 PM <*status> If you trust this certificate, do /znc AddTrustedServerFingerprint 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34
07:22 PM <*status> SHA-256: 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34
07:22 PM <*status> Disconnected from IRC. Reconnecting...
07:25 PM <*status> Disconnected from IRC (Invalid SSL certificate: unable to get local issuer certificate, unable to verify the first certificate). Reconnecting...
07:25 PM <*status> |        Version: 3 (0x2)
07:25 PM <*status> |    Data:
07:25 PM <*status> |Certificate:
07:25 PM <*status> |            Not After : May  1 06:55:03 2025 GMT
07:25 PM <*status> |            Not Before: Jan 31 06:55:04 2025 GMT
07:25 PM <*status> |        Validity
07:25 PM <*status> |        Issuer: C=US, O=Let's Encrypt, CN=E5
07:25 PM <*status> |        Signature Algorithm: ecdsa-with-SHA384
07:25 PM <*status> |            04:ca:c2:73:18:2b:ac:06:1f:01:f3:14:7e:ac:a0:ce:69:d9
07:25 PM <*status> |        Serial Number:
07:25 PM <*status> |                    c8:52:3a:b6:68:ff:4f:b3:1c:5b:1b:69:65:05:bf:
07:25 PM <*status> |                    e7:7e:3c:df:37:5e:b8:87:6f:90:85:3e:3b:09:11:
07:25 PM <*status> |                    04:76:b7:11:eb:6c:ed:e8:9a:af:72:ef:02:ca:0d:
07:25 PM <*status> |                pub:
07:25 PM <*status> |                Public-Key: (256 bit)
07:25 PM <*status> |            Public Key Algorithm: id-ecPublicKey
07:25 PM <*status> |        Subject Public Key Info:
07:25 PM <*status> |        Subject: CN=*.ircat.xyz
07:25 PM <*status> |                ASN1 OID: prime256v1
07:25 PM <*status> |                    fd:b0:05:8f:01
07:25 PM <*status> |                    98:32:6b:1a:ee:49:a3:5c:c5:72:4e:3e:59:9f:3a:
07:25 PM <*status> |            X509v3 Extended Key Usage: 
07:25 PM <*status> |                Digital Signature
07:25 PM <*status> |            X509v3 Key Usage: critical
07:25 PM <*status> |        X509v3 extensions:
07:25 PM <*status> |                NIST CURVE: P-256
07:25 PM <*status> |                CA:FALSE
07:25 PM <*status> |            X509v3 Basic Constraints: critical
07:25 PM <*status> |                TLS Web Server Authentication, TLS Web Client Authentication
07:25 PM <*status> |                CA Issuers - URI:http://e5.i.lencr.org/
07:25 PM <*status> |                OCSP - URI:http://e5.o.lencr.org
07:25 PM <*status> |            Authority Information Access: 
07:25 PM <*status> |                9F:2B:5F:CF:3C:21:4F:9D:04:B7:ED:2B:2C:C4:C6:70:8B:D2:D7:0D
07:25 PM <*status> |            X509v3 Authority Key Identifier: 
07:25 PM <*status> |                AE:83:89:1A:E4:01:DD:5C:54:02:FF:BE:18:2F:4B:92:0D:01:86:E7
07:25 PM <*status> |            X509v3 Subject Key Identifier: 
07:25 PM <*status> |                Policy: 2.23.140.1.2.1
07:25 PM <*status> |            X509v3 Certificate Policies: 
07:25 PM <*status> |                DNS:*.ircat.xyz
07:25 PM <*status> |            X509v3 Subject Alternative Name: 
07:25 PM <*status> |                    Timestamp : Jan 31 07:53:34.692 2025 GMT
07:25 PM <*status> |                                87:5C:14:A0:4E:95:9E:B9:03:2F:D9:0E:8C:2E:79:B8
07:25 PM <*status> |                    Log ID    : 7D:59:1E:12:E1:78:2A:7B:1C:61:67:7C:5E:FD:F8:D0:
07:25 PM <*status> |                    Version   : v1 (0x0)
07:25 PM <*status> |                Signed Certificate Timestamp:
07:25 PM <*status> |            CT Precertificate SCTs: 
07:25 PM <*status> |                Signed Certificate Timestamp:
07:25 PM <*status> |                                EB:31:5A:C1:B7:58
07:25 PM <*status> |                                26:63:C0:65:F9:02:B2:D9:5A:4B:1C:CD:83:15:E5:B3:
07:25 PM <*status> |                                68:47:C9:57:02:20:7F:87:B3:B2:12:6F:B2:19:DA:EB:
07:25 PM <*status> |                                5B:A7:CF:A2:11:EA:7B:B3:87:41:D6:99:40:65:CF:58:
07:25 PM <*status> |                                30:44:02:20:2D:FF:BC:A7:25:E2:15:67:87:C3:EB:99:
07:25 PM <*status> |                    Signature : ecdsa-with-SHA256
07:25 PM <*status> |                    Extensions: none
07:25 PM <*status> |                                30:44:02:20:79:20:D7:6D:07:D0:4F:70:95:10:66:55:
07:25 PM <*status> |                    Signature : ecdsa-with-SHA256
07:25 PM <*status> |                    Extensions: none
07:25 PM <*status> |                    Timestamp : Jan 31 07:53:34.882 2025 GMT
07:25 PM <*status> |                                16:B7:23:49:CE:58:57:6A:DF:AE:DA:A7:C2:AB:E0:22
07:25 PM <*status> |                    Log ID    : 13:4A:DF:1A:B5:98:42:09:78:0C:6F:EF:4C:7A:91:A4:
07:25 PM <*status> |                    Version   : v1 (0x0)
07:25 PM <*status> |    Signature Value:
07:25 PM <*status> |    Signature Algorithm: ecdsa-with-SHA384
07:25 PM <*status> |                                00:6C:31:9A:A1:A6
07:25 PM <*status> |                                5D:15:80:21:CE:2A:FD:03:80:B0:A1:8E:24:CE:5A:F9:
07:25 PM <*status> |                                E3:BF:1A:EC:02:20:1C:04:2E:17:2E:23:EE:E3:24:6A:
07:25 PM <*status> |                                8D:1A:50:04:00:20:1B:4A:53:C3:3E:A9:B2:B4:A9:2F:
07:25 PM <*status> |        5c:43:60:4a:4a:1b:df:75:d6:89:29:9b:2e
07:25 PM <*status> |        84:93:7f:f2:b3:c0:86:cb:6a:df:dc:8f:b5:67:9a:5d:63:90:
07:25 PM <*status> |        00:e5:87:ea:53:c6:c3:bf:ad:6d:b6:93:e0:d6:a9:73:7c:be:
07:25 PM <*status> |        a0:92:7e:82:06:0e:5f:bd:1b:db:7d:91:58:85:a6:8b:02:31:
07:25 PM <*status> |        f6:6f:b4:65:eb:05:3b:e4:a7:90:09:90:bf:29:af:9f:35:29:
07:25 PM <*status> |        30:65:02:30:6c:c5:08:42:5b:ae:02:27:e5:90:a2:3f:7e:96:
07:25 PM <*status> SHA-256: 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34
07:25 PM <*status> SHA1: 21:2f:0f:67:89:4d:be:c2:99:55:0b:d2:45:03:14:d1:10:0e:ab:fd
07:25 PM <*status> If you trust this certificate, do /znc AddTrustedServerFingerprint 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34
07:25 PM <*status> Disconnected from IRC. Reconnecting...
07:28 PM <*status> Connected!
07:52 PM <*status> Disconnected from IRC. Reconnecting...
07:54 PM <*status> Connected!

I cannot understand why. and it’s only in SweeNet that it happened.

(Originally posted by @Depresst0 on Discourse) For some reason *status in SweeNet dumped the certificate on the 4th of february. ``` 07:11 PM <*status> Disconnected from IRC. Reconnecting... 07:12 PM <*status> Connected! 07:17 PM <*status> Disconnected from IRC. Reconnecting... 07:19 PM <*status> |Certificate: 07:19 PM <*status> Disconnected from IRC (Invalid SSL certificate: unable to get local issuer certificate, unable to verify the first certificate). Reconnecting... 07:19 PM <*status> | Version: 3 (0x2) 07:19 PM <*status> | Data: 07:19 PM <*status> | 04:ca:c2:73:18:2b:ac:06:1f:01:f3:14:7e:ac:a0:ce:69:d9 07:19 PM <*status> | Serial Number: 07:19 PM <*status> | Not Before: Jan 31 06:55:04 2025 GMT 07:19 PM <*status> | Validity 07:19 PM <*status> | Issuer: C=US, O=Let's Encrypt, CN=E5 07:19 PM <*status> | Signature Algorithm: ecdsa-with-SHA384 07:19 PM <*status> | Public Key Algorithm: id-ecPublicKey 07:19 PM <*status> | Subject Public Key Info: 07:19 PM <*status> | Subject: CN=*.ircat.xyz 07:19 PM <*status> | Not After : May 1 06:55:03 2025 GMT 07:19 PM <*status> | fd:b0:05:8f:01 07:19 PM <*status> | 98:32:6b:1a:ee:49:a3:5c:c5:72:4e:3e:59:9f:3a: 07:19 PM <*status> | c8:52:3a:b6:68:ff:4f:b3:1c:5b:1b:69:65:05:bf: 07:19 PM <*status> | e7:7e:3c:df:37:5e:b8:87:6f:90:85:3e:3b:09:11: 07:19 PM <*status> | 04:76:b7:11:eb:6c:ed:e8:9a:af:72:ef:02:ca:0d: 07:19 PM <*status> | pub: 07:19 PM <*status> | Public-Key: (256 bit) 07:19 PM <*status> | X509v3 extensions: 07:19 PM <*status> | NIST CURVE: P-256 07:19 PM <*status> | ASN1 OID: prime256v1 07:19 PM <*status> | X509v3 Subject Key Identifier: 07:19 PM <*status> | CA:FALSE 07:19 PM <*status> | X509v3 Basic Constraints: critical 07:19 PM <*status> | TLS Web Server Authentication, TLS Web Client Authentication 07:19 PM <*status> | X509v3 Extended Key Usage: 07:19 PM <*status> | Digital Signature 07:19 PM <*status> | X509v3 Key Usage: critical 07:19 PM <*status> | X509v3 Authority Key Identifier: 07:19 PM <*status> | AE:83:89:1A:E4:01:DD:5C:54:02:FF:BE:18:2F:4B:92:0D:01:86:E7 07:19 PM <*status> | Policy: 2.23.140.1.2.1 07:19 PM <*status> | X509v3 Certificate Policies: 07:19 PM <*status> | DNS:*.ircat.xyz 07:19 PM <*status> | X509v3 Subject Alternative Name: 07:19 PM <*status> | CA Issuers - URI:http://e5.i.lencr.org/ 07:19 PM <*status> | OCSP - URI:http://e5.o.lencr.org 07:19 PM <*status> | Authority Information Access: 07:19 PM <*status> | 9F:2B:5F:CF:3C:21:4F:9D:04:B7:ED:2B:2C:C4:C6:70:8B:D2:D7:0D 07:19 PM <*status> | Timestamp : Jan 31 07:53:34.692 2025 GMT 07:19 PM <*status> | 87:5C:14:A0:4E:95:9E:B9:03:2F:D9:0E:8C:2E:79:B8 07:19 PM <*status> | Log ID : 7D:59:1E:12:E1:78:2A:7B:1C:61:67:7C:5E:FD:F8:D0: 07:19 PM <*status> | Version : v1 (0x0) 07:19 PM <*status> | Signed Certificate Timestamp: 07:19 PM <*status> | CT Precertificate SCTs: 07:19 PM <*status> | Signed Certificate Timestamp: 07:19 PM <*status> | EB:31:5A:C1:B7:58 07:19 PM <*status> | 26:63:C0:65:F9:02:B2:D9:5A:4B:1C:CD:83:15:E5:B3: 07:19 PM <*status> | 68:47:C9:57:02:20:7F:87:B3:B2:12:6F:B2:19:DA:EB: 07:19 PM <*status> | 5B:A7:CF:A2:11:EA:7B:B3:87:41:D6:99:40:65:CF:58: 07:19 PM <*status> | 30:44:02:20:2D:FF:BC:A7:25:E2:15:67:87:C3:EB:99: 07:19 PM <*status> | Signature : ecdsa-with-SHA256 07:19 PM <*status> | Extensions: none 07:19 PM <*status> | 30:44:02:20:79:20:D7:6D:07:D0:4F:70:95:10:66:55: 07:19 PM <*status> | Signature : ecdsa-with-SHA256 07:19 PM <*status> | Extensions: none 07:19 PM <*status> | Timestamp : Jan 31 07:53:34.882 2025 GMT 07:19 PM <*status> | 16:B7:23:49:CE:58:57:6A:DF:AE:DA:A7:C2:AB:E0:22 07:19 PM <*status> | Log ID : 13:4A:DF:1A:B5:98:42:09:78:0C:6F:EF:4C:7A:91:A4: 07:19 PM <*status> | Version : v1 (0x0) 07:19 PM <*status> | 30:65:02:30:6c:c5:08:42:5b:ae:02:27:e5:90:a2:3f:7e:96: 07:19 PM <*status> | Signature Value: 07:19 PM <*status> | Signature Algorithm: ecdsa-with-SHA384 07:19 PM <*status> | 00:6C:31:9A:A1:A6 07:19 PM <*status> | 5D:15:80:21:CE:2A:FD:03:80:B0:A1:8E:24:CE:5A:F9: 07:19 PM <*status> | E3:BF:1A:EC:02:20:1C:04:2E:17:2E:23:EE:E3:24:6A: 07:19 PM <*status> | 8D:1A:50:04:00:20:1B:4A:53:C3:3E:A9:B2:B4:A9:2F: 07:19 PM <*status> | 5c:43:60:4a:4a:1b:df:75:d6:89:29:9b:2e 07:19 PM <*status> | 84:93:7f:f2:b3:c0:86:cb:6a:df:dc:8f:b5:67:9a:5d:63:90: 07:19 PM <*status> | 00:e5:87:ea:53:c6:c3:bf:ad:6d:b6:93:e0:d6:a9:73:7c:be: 07:19 PM <*status> | a0:92:7e:82:06:0e:5f:bd:1b:db:7d:91:58:85:a6:8b:02:31: 07:19 PM <*status> | f6:6f:b4:65:eb:05:3b:e4:a7:90:09:90:bf:29:af:9f:35:29: 07:19 PM <*status> If you trust this certificate, do /znc AddTrustedServerFingerprint 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34 07:19 PM <*status> SHA-256: 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34 07:19 PM <*status> SHA1: 21:2f:0f:67:89:4d:be:c2:99:55:0b:d2:45:03:14:d1:10:0e:ab:fd 07:19 PM <*status> Disconnected from IRC. Reconnecting... 07:22 PM <*status> |Certificate: 07:22 PM <*status> Disconnected from IRC (Invalid SSL certificate: unable to get local issuer certificate, unable to verify the first certificate). Reconnecting... 07:22 PM <*status> | Serial Number: 07:22 PM <*status> | Version: 3 (0x2) 07:22 PM <*status> | Data: 07:22 PM <*status> | 04:ca:c2:73:18:2b:ac:06:1f:01:f3:14:7e:ac:a0:ce:69:d9 07:22 PM <*status> | Not After : May 1 06:55:03 2025 GMT 07:22 PM <*status> | Not Before: Jan 31 06:55:04 2025 GMT 07:22 PM <*status> | Validity 07:22 PM <*status> | Issuer: C=US, O=Let's Encrypt, CN=E5 07:22 PM <*status> | Signature Algorithm: ecdsa-with-SHA384 07:22 PM <*status> | Public-Key: (256 bit) 07:22 PM <*status> | Public Key Algorithm: id-ecPublicKey 07:22 PM <*status> | Subject Public Key Info: 07:22 PM <*status> | Subject: CN=*.ircat.xyz 07:22 PM <*status> | 04:76:b7:11:eb:6c:ed:e8:9a:af:72:ef:02:ca:0d: 07:22 PM <*status> | pub: 07:22 PM <*status> | NIST CURVE: P-256 07:22 PM <*status> | ASN1 OID: prime256v1 07:22 PM <*status> | fd:b0:05:8f:01 07:22 PM <*status> | 98:32:6b:1a:ee:49:a3:5c:c5:72:4e:3e:59:9f:3a: 07:22 PM <*status> | c8:52:3a:b6:68:ff:4f:b3:1c:5b:1b:69:65:05:bf: 07:22 PM <*status> | e7:7e:3c:df:37:5e:b8:87:6f:90:85:3e:3b:09:11: 07:22 PM <*status> | Digital Signature 07:22 PM <*status> | X509v3 Key Usage: critical 07:22 PM <*status> | X509v3 extensions: 07:22 PM <*status> | X509v3 Subject Key Identifier: 07:22 PM <*status> | CA:FALSE 07:22 PM <*status> | X509v3 Basic Constraints: critical 07:22 PM <*status> | TLS Web Server Authentication, TLS Web Client Authentication 07:22 PM <*status> | X509v3 Extended Key Usage: 07:22 PM <*status> | CA Issuers - URI:http://e5.i.lencr.org/ 07:22 PM <*status> | OCSP - URI:http://e5.o.lencr.org 07:22 PM <*status> | Authority Information Access: 07:22 PM <*status> | 9F:2B:5F:CF:3C:21:4F:9D:04:B7:ED:2B:2C:C4:C6:70:8B:D2:D7:0D 07:22 PM <*status> | X509v3 Authority Key Identifier: 07:22 PM <*status> | AE:83:89:1A:E4:01:DD:5C:54:02:FF:BE:18:2F:4B:92:0D:01:86:E7 07:22 PM <*status> | CT Precertificate SCTs: 07:22 PM <*status> | Policy: 2.23.140.1.2.1 07:22 PM <*status> | X509v3 Certificate Policies: 07:22 PM <*status> | DNS:*.ircat.xyz 07:22 PM <*status> | X509v3 Subject Alternative Name: 07:22 PM <*status> | Timestamp : Jan 31 07:53:34.692 2025 GMT 07:22 PM <*status> | 87:5C:14:A0:4E:95:9E:B9:03:2F:D9:0E:8C:2E:79:B8 07:22 PM <*status> | Log ID : 7D:59:1E:12:E1:78:2A:7B:1C:61:67:7C:5E:FD:F8:D0: 07:22 PM <*status> | Version : v1 (0x0) 07:22 PM <*status> | Signed Certificate Timestamp: 07:22 PM <*status> | 68:47:C9:57:02:20:7F:87:B3:B2:12:6F:B2:19:DA:EB: 07:22 PM <*status> | 5B:A7:CF:A2:11:EA:7B:B3:87:41:D6:99:40:65:CF:58: 07:22 PM <*status> | 30:44:02:20:2D:FF:BC:A7:25:E2:15:67:87:C3:EB:99: 07:22 PM <*status> | Signature : ecdsa-with-SHA256 07:22 PM <*status> | Extensions: none 07:22 PM <*status> | Log ID : 13:4A:DF:1A:B5:98:42:09:78:0C:6F:EF:4C:7A:91:A4: 07:22 PM <*status> | Version : v1 (0x0) 07:22 PM <*status> | Signed Certificate Timestamp: 07:22 PM <*status> | EB:31:5A:C1:B7:58 07:22 PM <*status> | 26:63:C0:65:F9:02:B2:D9:5A:4B:1C:CD:83:15:E5:B3: 07:22 PM <*status> | 30:44:02:20:79:20:D7:6D:07:D0:4F:70:95:10:66:55: 07:22 PM <*status> | Signature : ecdsa-with-SHA256 07:22 PM <*status> | Extensions: none 07:22 PM <*status> | Timestamp : Jan 31 07:53:34.882 2025 GMT 07:22 PM <*status> | 16:B7:23:49:CE:58:57:6A:DF:AE:DA:A7:C2:AB:E0:22 07:22 PM <*status> | 5D:15:80:21:CE:2A:FD:03:80:B0:A1:8E:24:CE:5A:F9: 07:22 PM <*status> | E3:BF:1A:EC:02:20:1C:04:2E:17:2E:23:EE:E3:24:6A: 07:22 PM <*status> | 8D:1A:50:04:00:20:1B:4A:53:C3:3E:A9:B2:B4:A9:2F: 07:22 PM <*status> | f6:6f:b4:65:eb:05:3b:e4:a7:90:09:90:bf:29:af:9f:35:29: 07:22 PM <*status> | 30:65:02:30:6c:c5:08:42:5b:ae:02:27:e5:90:a2:3f:7e:96: 07:22 PM <*status> | Signature Value: 07:22 PM <*status> | Signature Algorithm: ecdsa-with-SHA384 07:22 PM <*status> | 00:6C:31:9A:A1:A6 07:22 PM <*status> SHA1: 21:2f:0f:67:89:4d:be:c2:99:55:0b:d2:45:03:14:d1:10:0e:ab:fd 07:22 PM <*status> | 5c:43:60:4a:4a:1b:df:75:d6:89:29:9b:2e 07:22 PM <*status> | 84:93:7f:f2:b3:c0:86:cb:6a:df:dc:8f:b5:67:9a:5d:63:90: 07:22 PM <*status> | 00:e5:87:ea:53:c6:c3:bf:ad:6d:b6:93:e0:d6:a9:73:7c:be: 07:22 PM <*status> | a0:92:7e:82:06:0e:5f:bd:1b:db:7d:91:58:85:a6:8b:02:31: 07:22 PM <*status> If you trust this certificate, do /znc AddTrustedServerFingerprint 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34 07:22 PM <*status> SHA-256: 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34 07:22 PM <*status> Disconnected from IRC. Reconnecting... 07:25 PM <*status> Disconnected from IRC (Invalid SSL certificate: unable to get local issuer certificate, unable to verify the first certificate). Reconnecting... 07:25 PM <*status> | Version: 3 (0x2) 07:25 PM <*status> | Data: 07:25 PM <*status> |Certificate: 07:25 PM <*status> | Not After : May 1 06:55:03 2025 GMT 07:25 PM <*status> | Not Before: Jan 31 06:55:04 2025 GMT 07:25 PM <*status> | Validity 07:25 PM <*status> | Issuer: C=US, O=Let's Encrypt, CN=E5 07:25 PM <*status> | Signature Algorithm: ecdsa-with-SHA384 07:25 PM <*status> | 04:ca:c2:73:18:2b:ac:06:1f:01:f3:14:7e:ac:a0:ce:69:d9 07:25 PM <*status> | Serial Number: 07:25 PM <*status> | c8:52:3a:b6:68:ff:4f:b3:1c:5b:1b:69:65:05:bf: 07:25 PM <*status> | e7:7e:3c:df:37:5e:b8:87:6f:90:85:3e:3b:09:11: 07:25 PM <*status> | 04:76:b7:11:eb:6c:ed:e8:9a:af:72:ef:02:ca:0d: 07:25 PM <*status> | pub: 07:25 PM <*status> | Public-Key: (256 bit) 07:25 PM <*status> | Public Key Algorithm: id-ecPublicKey 07:25 PM <*status> | Subject Public Key Info: 07:25 PM <*status> | Subject: CN=*.ircat.xyz 07:25 PM <*status> | ASN1 OID: prime256v1 07:25 PM <*status> | fd:b0:05:8f:01 07:25 PM <*status> | 98:32:6b:1a:ee:49:a3:5c:c5:72:4e:3e:59:9f:3a: 07:25 PM <*status> | X509v3 Extended Key Usage: 07:25 PM <*status> | Digital Signature 07:25 PM <*status> | X509v3 Key Usage: critical 07:25 PM <*status> | X509v3 extensions: 07:25 PM <*status> | NIST CURVE: P-256 07:25 PM <*status> | CA:FALSE 07:25 PM <*status> | X509v3 Basic Constraints: critical 07:25 PM <*status> | TLS Web Server Authentication, TLS Web Client Authentication 07:25 PM <*status> | CA Issuers - URI:http://e5.i.lencr.org/ 07:25 PM <*status> | OCSP - URI:http://e5.o.lencr.org 07:25 PM <*status> | Authority Information Access: 07:25 PM <*status> | 9F:2B:5F:CF:3C:21:4F:9D:04:B7:ED:2B:2C:C4:C6:70:8B:D2:D7:0D 07:25 PM <*status> | X509v3 Authority Key Identifier: 07:25 PM <*status> | AE:83:89:1A:E4:01:DD:5C:54:02:FF:BE:18:2F:4B:92:0D:01:86:E7 07:25 PM <*status> | X509v3 Subject Key Identifier: 07:25 PM <*status> | Policy: 2.23.140.1.2.1 07:25 PM <*status> | X509v3 Certificate Policies: 07:25 PM <*status> | DNS:*.ircat.xyz 07:25 PM <*status> | X509v3 Subject Alternative Name: 07:25 PM <*status> | Timestamp : Jan 31 07:53:34.692 2025 GMT 07:25 PM <*status> | 87:5C:14:A0:4E:95:9E:B9:03:2F:D9:0E:8C:2E:79:B8 07:25 PM <*status> | Log ID : 7D:59:1E:12:E1:78:2A:7B:1C:61:67:7C:5E:FD:F8:D0: 07:25 PM <*status> | Version : v1 (0x0) 07:25 PM <*status> | Signed Certificate Timestamp: 07:25 PM <*status> | CT Precertificate SCTs: 07:25 PM <*status> | Signed Certificate Timestamp: 07:25 PM <*status> | EB:31:5A:C1:B7:58 07:25 PM <*status> | 26:63:C0:65:F9:02:B2:D9:5A:4B:1C:CD:83:15:E5:B3: 07:25 PM <*status> | 68:47:C9:57:02:20:7F:87:B3:B2:12:6F:B2:19:DA:EB: 07:25 PM <*status> | 5B:A7:CF:A2:11:EA:7B:B3:87:41:D6:99:40:65:CF:58: 07:25 PM <*status> | 30:44:02:20:2D:FF:BC:A7:25:E2:15:67:87:C3:EB:99: 07:25 PM <*status> | Signature : ecdsa-with-SHA256 07:25 PM <*status> | Extensions: none 07:25 PM <*status> | 30:44:02:20:79:20:D7:6D:07:D0:4F:70:95:10:66:55: 07:25 PM <*status> | Signature : ecdsa-with-SHA256 07:25 PM <*status> | Extensions: none 07:25 PM <*status> | Timestamp : Jan 31 07:53:34.882 2025 GMT 07:25 PM <*status> | 16:B7:23:49:CE:58:57:6A:DF:AE:DA:A7:C2:AB:E0:22 07:25 PM <*status> | Log ID : 13:4A:DF:1A:B5:98:42:09:78:0C:6F:EF:4C:7A:91:A4: 07:25 PM <*status> | Version : v1 (0x0) 07:25 PM <*status> | Signature Value: 07:25 PM <*status> | Signature Algorithm: ecdsa-with-SHA384 07:25 PM <*status> | 00:6C:31:9A:A1:A6 07:25 PM <*status> | 5D:15:80:21:CE:2A:FD:03:80:B0:A1:8E:24:CE:5A:F9: 07:25 PM <*status> | E3:BF:1A:EC:02:20:1C:04:2E:17:2E:23:EE:E3:24:6A: 07:25 PM <*status> | 8D:1A:50:04:00:20:1B:4A:53:C3:3E:A9:B2:B4:A9:2F: 07:25 PM <*status> | 5c:43:60:4a:4a:1b:df:75:d6:89:29:9b:2e 07:25 PM <*status> | 84:93:7f:f2:b3:c0:86:cb:6a:df:dc:8f:b5:67:9a:5d:63:90: 07:25 PM <*status> | 00:e5:87:ea:53:c6:c3:bf:ad:6d:b6:93:e0:d6:a9:73:7c:be: 07:25 PM <*status> | a0:92:7e:82:06:0e:5f:bd:1b:db:7d:91:58:85:a6:8b:02:31: 07:25 PM <*status> | f6:6f:b4:65:eb:05:3b:e4:a7:90:09:90:bf:29:af:9f:35:29: 07:25 PM <*status> | 30:65:02:30:6c:c5:08:42:5b:ae:02:27:e5:90:a2:3f:7e:96: 07:25 PM <*status> SHA-256: 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34 07:25 PM <*status> SHA1: 21:2f:0f:67:89:4d:be:c2:99:55:0b:d2:45:03:14:d1:10:0e:ab:fd 07:25 PM <*status> If you trust this certificate, do /znc AddTrustedServerFingerprint 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34 07:25 PM <*status> Disconnected from IRC. Reconnecting... 07:28 PM <*status> Connected! 07:52 PM <*status> Disconnected from IRC. Reconnecting... 07:54 PM <*status> Connected! ``` I cannot understand why. and it’s only in SweeNet that it happened.
Author
Owner

(Originally posted by @swee on Discourse)

Hi @Depresst0

This error was when I was migrating the built in ssl module to PyOpenSSL, (I have reverted that change recently)

I accidentally made OpenSSL load the certificate chain as a certificate file instead of chain

This problem was not reported here since it required only a small patch.

Ref: Commit 6577098a60

(Originally posted by @swee on Discourse) Hi @Depresst0 This error was when I was migrating the built in `ssl` module to `PyOpenSSL`, (I have reverted that change recently) I accidentally made OpenSSL load the certificate chain as a certificate file instead of chain This problem was not reported here since it required only a small patch. Ref: Commit 6577098a60
swee 2025-08-16 17:59:18 -07:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: swee/IRCat#2
No description provided.