IRC logs of Libera.Chat #BZFlag for Friday, 2021-10-01

SpringTankbzflag list server down?00:07
*** blast007[m] <blast007[m]!~blast007m@2001:470:69fc:105::7ec> has joined #bzflag00:07
*** sean[m]1 <sean[m]1!~brlcadmat@2001:470:69fc:105::1ff> has joined #bzflag00:07
SpringTankhey blast. bzflag list server down?00:08
SpringTanknot authenticating usernames when direct connection to servers either00:09
blast007ah, it may be servers that need to update their root CA's00:14
blast007I see a lot less servers on the list right now00:14
blast007https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/00:15
blast007including mine, it seems00:15
SpringTank"Can't talk with list servers"00:17
SpringTank^client error00:17
blast007is that your client saying that when you try to get the server list?00:20
blast007if so, what operating system and OS version are you running?00:20
blast007I just updated the packages on my Debian 9 server hosting bzfs (which included openssl and curl updates) and now my servers are back on the list00:21
blast007what operating system are you running?00:21
SpringTankwin700:22
SpringTankfor my client00:22
blast007let me try on Windows00:22
blast007this is the latest 2.4.22 client?00:23
SpringTankyes00:23
blast007worked on my Windows 700:25
SpringTankhmmm, im using at&t fiber00:26
blast007can you access this site in Internet Explorer?  https://my.bzflag.org/db/?action=LIST00:26
SpringTankeverything else seems to be working. let me try on my debian system00:26
blast007(and yes, Internet Explorer specifically)  :)00:26
SpringTanknope00:27
blast007what kind of error do you get?00:27
SpringTankbut it works on firefox00:27
SpringTank"There is a problem with this website's security certificate."00:27
blast007yeah, firefox uses their own SSL/TLS system00:27
SpringTankbut I can skip past that and it works fine00:27
blast007our curl is compiled to use schannel/winssl, which is also what IE uses00:27
blast007is your Windows 7 fully updated?00:28
SpringTankit is not00:28
SpringTanki usually install updates manually00:28
blast007you're probably missing Trusted Root updates00:28
SpringTankguess ill have to find that update00:28
blast007https://support.microsoft.com/en-us/topic/support-for-urgent-trusted-root-updates-for-windows-root-certificate-program-in-windows-a4ac4d6c-7c62-3b6e-dfd2-377982bf3ea500:29
blast007that may be it?  you'd need to check that page over more00:29
SpringTanklooks to be KB300439400:29
blast007or check in Windows Update for anything about root certificates00:29
SpringTankinstalling KB3004394 has fixed the issue00:32
blast007cool00:32
SpringTankthanks00:32
blast007I'll post on the forums about the issue for servers00:33
blast007I was dealing with this certificate problem at work today.  Our site uses a Let's Encrypt certificate, and a hosted service we use is failing to communicate with our site because they can no longer validate the certificate trust chain00:36
SpringTanksounds fun00:56
SpringTanklol00:56
*** kbar <kbar!~kbar@cpe-69-76-15-233.natnow.res.rr.com> has joined #bzflag03:47
*** kbar <kbar!~kbar@cpe-69-76-15-233.natnow.res.rr.com> has quit IRC (Quit: Client closed)04:01
BZNotifymaster @ bzflag.org: allejo pushed 1 commit (https://git.io/JgliA):04:08
BZNotifymaster @ bzflag.org: allejo 9351b3: Update MOTD to include know about SSL issues (https://git.io/Jglix)04:08
*** kbar <kbar!~kbar@cpe-69-76-15-233.natnow.res.rr.com> has joined #bzflag04:09
*** kbar <kbar!~kbar@cpe-69-76-15-233.natnow.res.rr.com> has quit IRC (Client Quit)04:10
*** kbar <kbar!~kbar@cpe-69-76-15-233.natnow.res.rr.com> has joined #bzflag04:16
*** kbar <kbar!~kbar@cpe-69-76-15-233.natnow.res.rr.com> has quit IRC (Quit: Ping timeout (120 seconds))04:41
*** I_Died_Once <I_Died_Once!~I_Died_On@c-73-184-170-223.hsd1.ga.comcast.net> has quit IRC (Ping timeout: 240 seconds)06:01
*** the-map <the-map!~the_map@user/the-map/x-5158391> has joined #bzflag06:06
*** TD--Linux <TD--Linux!~Thomas@user/td-linux> has joined #bzflag06:11
*** rodgort` <rodgort`!~rodgort@static.38.6.217.95.clients.your-server.de> has joined #bzflag06:13
*** rodgort <rodgort!~rodgort@static.38.6.217.95.clients.your-server.de> has quit IRC (*.net *.split)06:14
*** the_map <the_map!~the_map@user/the-map/x-5158391> has quit IRC (*.net *.split)06:14
*** catay <catay!~smertens@user/catay> has quit IRC (*.net *.split)06:14
*** TD-Linux <TD-Linux!~Thomas@user/td-linux> has quit IRC (*.net *.split)06:14
*** rodgort` <rodgort`!~rodgort@static.38.6.217.95.clients.your-server.de> has quit IRC (Ping timeout: 252 seconds)07:12
*** rodgort <rodgort!~rodgort@static.38.6.217.95.clients.your-server.de> has joined #bzflag07:13
*** sean[m]11 <sean[m]11!~brlcadmat@2001:470:69fc:105::1ff> has joined #bzflag07:20
*** sean[m]1 <sean[m]1!~brlcadmat@2001:470:69fc:105::1ff> has quit IRC (Ping timeout: 252 seconds)07:21
*** allejo <allejo!~allejo@user/allejo> has quit IRC (Ping timeout: 252 seconds)07:21
*** allejo <allejo!~allejo@104.243.40.186> has joined #bzflag07:21
*** ChanServ sets mode: +v allejo07:21
*** Sgeo <Sgeo!~Sgeo@user/sgeo> has quit IRC (Read error: Connection reset by peer)07:33
*** librebob[m] <librebob[m]!~librebobm@2001:470:69fc:105::88d6> has quit IRC (Ping timeout: 250 seconds)07:44
*** librebob[m] <librebob[m]!~librebobm@2001:470:69fc:105::88d6> has joined #bzflag07:44
*** alezakos_ <alezakos_!~kongr45gp@user/alezakos> has joined #bzflag07:45
*** alezakos <alezakos!~kongr45gp@user/alezakos> has quit IRC (Ping timeout: 250 seconds)07:45
*** TD--Linux is now known as TD-Linux08:04
*** allejo <allejo!~allejo@user/allejo> has quit IRC (Remote host closed the connection)09:07
*** allejo <allejo!~allejo@104.243.40.186> has joined #bzflag09:08
*** ChanServ sets mode: +v allejo09:08
*** alezakos_ is now known as alezakos10:47
*** allejo <allejo!~allejo@user/allejo> has quit IRC (Remote host closed the connection)11:37
*** allejo <allejo!~allejo@104.243.40.186> has joined #bzflag11:38
*** ChanServ sets mode: +v allejo11:38
*** I_Died_Once <I_Died_Once!~I_Died_On@c-73-184-170-223.hsd1.ga.comcast.net> has joined #bzflag12:45
*** Sgeo <Sgeo!~Sgeo@user/sgeo> has joined #bzflag14:12
*** catay <catay!~smertens@user/catay> has joined #bzflag15:23
*** blast007_ <blast007_!~blast@user/blast007> has joined #bzflag16:25
*** blast007 <blast007!~blast@user/blast007> has quit IRC (Ping timeout: 265 seconds)16:26
*** blast007_ is now known as blast00716:27
*** jfindlay_ is now known as jfindlay16:38
*** BZuser790 <BZuser790!~BZuser790@201.141.123.92> has joined #bzflag16:41
*** BZuser790 <BZuser790!~BZuser790@201.141.123.92> has quit IRC (Client Quit)16:42
*** the-map is now known as the_map21:12
*** _I_Died_Once <_I_Died_Once!~I_Died_On@c-73-184-170-223.hsd1.ga.comcast.net> has joined #bzflag21:24
*** I_Died_Once <I_Died_Once!~I_Died_On@c-73-184-170-223.hsd1.ga.comcast.net> has quit IRC (Ping timeout: 252 seconds)21:26
*** alfa1 <alfa1!~alfa1@host30.181-14-186.telecom.net.ar> has joined #bzflag22:09
alfa1is there any problem about TLS/others on the game? I have problems as well on known web sites too.22:11
allejohttps://forums.bzflag.org/viewtopic.php?f=8&t=2052422:12
*** ChanServ sets mode: +o allejo22:13
blast007alfa1: what operating system and OS version are you running?22:13
*** allejo changes topic to "BZFlag Support and Development || Latest version: 2.4.22 || https://www.bzflag.org || https://www.bzflag.org/help/ || https://www.openhub.net/p/bzflag || https://logs.bzexcess.com || Having trouble connecting to the server list? Follow this thread https://forums.bzflag.org/viewtopic.php?f=8&t=20524"22:14
*** allejo sets mode: -o allejo22:14
alfa1it is an old operating system; I don't want to give lot of info, sorry22:16
alfa1I am reading that thread tho22:17
alfa1I still can connect to servers by strayer info; tho no auth; which is not big problem except for my own server22:18
blast007if you're using  OpenSSL 1.0.2 (check with 'openssl version' in a terminal), the first workaround may help you22:19
blast007or are you using Windows?22:20
alfa1no, linux22:20
alfa1you mean "installing updates, which included some for curl and openssl" (second workaround)?22:20
blast007oh, sorry, I had forgot to paste the link with that message above22:20
blast007https://www.openssl.org/blog/blog/2021/09/13/LetsEncryptRootCertExpire/22:20
blast007the first workaround here22:21
*** Zehra <Zehra!~Yukari@user/yukari> has joined #bzflag22:22
alfa1my openssl version is older than that. Is there any way to avoid using TLS/others to run my server (or to use auth)? Someting like an optional way?22:34
alfa1(something like the previous method)22:34
alfa1I will see if I can update it tho.22:35
catayif you get rid of the X3 root cert and install the ISRG root one, it should also work with older openssl versions22:40
alfa1ok, I will see if I can try that, thank you22:42
catay check /etc/ca-certificates.conf ,  you can exclude there the X3 one, download the new one and also add it in there22:43
catayand run update-ca-certificates22:44
blast007if it's a Debian-based distro, you could try 'sudo dpkg-reconfigure ca-certificates' and uncheck the old cert22:44
catayyou can download the ISRG one here: https://letsencrypt.org/certs/isrgrootx1.pem22:45
blast007(on Debian, I have a local CA certificate I used for internal dev, which I've placed in /usr/share/ca-certificates/ as a .crt file, and then added to the trust using the dpkg-reconfigure above)22:46
alfa1thanks all; with that info I have material to work with for now :)22:50
alfa1"man update-ca-certificates" is helpìng me too22:51
alfa1I should rename the file as "ISRG_Root_X1.pem" right?23:02
*** Agatha <Agatha!~agatha@user/agatha> has joined #bzflag23:03
blast007check 'ls -l /etc/ssl/cert/' to see if the files there are actually symbolic links elsewhere23:05
blast007ls -l /etc/ssl/certs/23:05
*** Agatha <Agatha!~agatha@user/agatha> has quit IRC (Read error: Connection reset by peer)23:08
alfa1are IRC connections having trouble too?23:09
blast007Freenode also uses Let's Encrypt for their SSL ports.23:10
alfa1it seems those links are automatically added with "update-ca-certificates" command, blast00723:11
blast007okay, so Debian's dpkg-reconfigure probably calls that same thing23:12
blast007so just put the new cert in the same area as where those symlinks point to, and with the same file extension as the target files23:12
blast007so, on Debian, the link names end in .pem, but the actual files ends in .crt23:12
blast007adjust as needed for your system23:13
alfa1yes23:15
alfa1guiding me mainly by the man page to avoid any risk :)23:15
alfa1but that seems the way23:15
blast007might want to name the file in a way that's clear you added it23:16
blast007that way if you upgrade later, there's little chance of a filename conflict23:16
alfa1I will have that in mind23:21
alfa1bzflag not working, should I reset machine?23:22
alfa1firefox also not; resetting...23:23
*** alfa1 <alfa1!~alfa1@host30.181-14-186.telecom.net.ar> has quit IRC (Remote host closed the connection)23:24
blast007rebooting the server list real quick23:34

Generated by irclog2html.py 2.17.3.dev0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!