Crashes in OpenBSD, DragonFly BSD, and Electron due to the expiration of the IdenTrust root certificate

The expiration of the root certificate from IdenTrust (DST Root CA X3), which was used to cross-sign the root certificate for the Let’s Encrypt certificate authority, has caused issues with validating Let’s Encrypt certificates in projects using older versions of OpenSSL and GnuTLS. These issues also affected the LibreSSL library, whose developers did not consider past experiences related to failures that occurred after the expiration of the AddTrust root certificate from the Sectigo (Comodo) certificate authority.

Let us remind you that in OpenSSL releases up to and including branch 1.0.2 and in GnuTLS up to release 3.6.14, there was a bug that prevented the proper handling of cross-signed certificates in the event of the expiration of one of the root certificates used in the signing, even if other valid trust chains were maintained (in the case of Let’s Encrypt, the expiration of the IdenTrust root certificate prevents validation even if the system has support for its own Let’s Encrypt root certificate, valid until 2030). The essence of the bug is that older versions of OpenSSL and GnuTLS parsed the certificate as a linear chain, whereas according to RFC 4158, a certificate can represent a directed distributed cyclic graph with multiple trust anchors to consider.

As a workaround to address the failure, it is suggested to remove the certificate "DST Root CA X3" from the system storage (/etc/ca-certificates.conf and /etc/ssl/certs), and then run the command "update-ca-certificates -f -v". In CentOS and RHEL, you can blacklist the certificate "DST Root CA X3": trust dump —filter "pkcs11:id=" | openssl x509 | sudo tee /etc/pki/ca-trust/source/blacklist/DST-Root-CA-X3.pem sudo update-ca-trust extract

Some of the failures observed after the expiration of the IdenTrust root certificate:

  • The syspatch utility used for installing binary system updates has stopped working in OpenBSD. The OpenBSD project has urgently released patches today for versions 6.8 and 6.9, addressing issues in LibreSSL related to the validation of cross-signed certificates, one of which has an expired root certificate in the trust chain. As a workaround, it is recommended to switch from HTTPS to HTTP in /etc/installurl (this does not pose a security threat as updates are additionally verified by digital signature) or select an alternative mirror (ftp.usa.openbsd.org, ftp.hostserver.de, cdn.openbsd.org). It is also possible to remove the expired root certificate DST Root CA X3 from the file /etc/ssl/cert.pem.
  • Similar issues are observed in DragonFly BSD while working with DPorts. When launching the pkg package manager, a certificate validation error occurs. A fix has been added today to the branches master, DragonFly_RELEASE_6_0, and DragonFly_RELEASE_5_8. As a workaround, you can remove the DST Root CA X3 certificate.
  • The process of validating Let’s Encrypt certificates in applications based on the Electron platform has been disrupted. The issue has been resolved in updates 12.2.1, 13.5.1, 14.1.0, and 15.1.0.
  • Some distributions are experiencing problems accessing package repositories when using the APT package manager, related to outdated versions of the GnuTLS library. Debian 9 is affected by this issue, where an unpatched GnuTLS package caused problems for users who did not timely install updates (the fix gnutls28-3.5.8-5+deb9u6 was proposed on September 17). As a workaround, it is recommended to remove DST_Root_CA_X3.crt from the file /etc/ca-certificates.conf.
  • The acme-client functionality has been disrupted in the OPNsense firewall distribution. The issue was reported in advance, but the developers were unable to release a patch in time.
  • The issue affected the OpenSSL 1.0.2k package in RHEL/CentOS 7, but a week ago an update for the ca-certificates-2021.2.50-72.el7_9.noarch package was released for RHEL 7 and CentOS 7, removing the IdenTrust certificate, thus preemptively blocking the manifestation of the problem. A similar update was published a week ago for Ubuntu 16.04, Ubuntu 14.04, Ubuntu 21.04, Ubuntu 20.04, and Ubuntu 18.04. Since updates were released in advance, the issue with Let's Encrypt certificate validation only affected users on older branches of RHEL/CentOS and Ubuntu who do not regularly apply updates.
  • Certificate validation process disrupted in grpc.
  • Build failure on the Cloudflare Pages platform.
  • Issues in Amazon Web Services (AWS).
  • Database connection problems for DigitalOcean users.
  • Failure in the Netlify cloud platform.
  • Access issues with Xero services.
  • Failed to establish TLS connection to the MailGun Web API service.
  • Failures on macOS and iOS versions (11, 13, 14) that theoretically shouldn't have been affected.
  • Failure in Catchpoint services.
  • Certificate validation error when accessing the PostMan API.
  • Failure in Guardian Firewall.
  • Issues with the monday.com support page.
  • Failure in the Cerb platform.
  • Uptime check failure in Google Cloud Monitoring.
  • Certificate validation issues in Cisco Umbrella Secure Web Gateway.
  • Issues connecting to Bluecoat and Palo Alto proxies.
  • Connection issues with the OpenStack API at OVHcloud.
  • Problems generating reports in Shopify.
  • Issues observed when accessing the Heroku API.
  • Failure in Ledger Live Manager.
  • Certificate validation error in Facebook app development tools.
  • Issues with Sophos SG UTM.
  • Certificate validation problems in cPanel.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster