Unable to verify Apple IST CA 2 on Chromium and curl but Firefox works

Hey all,

I'm running into some issues regarding TLS certificates. For a few weeks already, several `` sites no longer properly load for me, because assets they use (CSS files, etc) can't be loaded. An example that does not load is … v-plus.css.

It seems that the certificate of is signed by Apple IST CA 2 (SHA1: 31:13:4A:0F:94:F8:A5:A6:15:4B:5D:09:5F:68:37:E8:35:8D:39:1D), which appears as the root when inspecting the certificate from Chromium. However, Chromium does not trust it. This can be reproduced with curl as well:

$ curl
curl: (60) SSL certificate problem: unable to get local issuer certificate
More details here:

curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and
how to fix it, please visit the web page mentioned above.

When using Firefox on the same machine however, the page loads just fine. Inspecting the certificate using Firefox, it actually finds a certificate authority above Apple IST CA 2, namely Baltimore CyberTrust Root (SHA1: D4:DE:20:D0:5E:66:FC:53:FE:1A:50:88:2C:78:DB:28:52:CA:E4:74).

I assume this is related to the fact that Firefox uses its own trust store, while Chromium and curl use the system one.

Is this a known problem? Shall I file a bug with ArchLinux?

Thanks a lot!


Re: Unable to verify Apple IST CA 2 on Chromium and curl but Firefox works

Hi, I encountered the same problem. I don't think it is Archlinux's problem.
Basically, the Applt IST CA 2 is signed by two root CA. One of them (GeoTrust Global CA) got removed by upstream ( … ease_notes) while the other one (Baltimore CyberTrust) remains valid.
However, the apple cdn is configured to return the GeoTrust certificate chain, which of course gets rejected. Firefox is able to discover the other valid certificate chain, regardless of apple cdn returning the wrong chain.

I won't recommend, but as a workaround, you may want to install the intermediate certificate discovered by Firefox to your system/browser. (refer to … rtificate)

Baltimore -> Apple IST CA 2 cert wrote:



Re: Unable to verify Apple IST CA 2 on Chromium and curl but Firefox works

Same issue here, but also on Firefox.
I've rollback ca-certificates-mozilla to an older version (3.59.1-1) and it works fine.


