You are not logged in.

#1 2017-10-06 18:55:52

crobe2
Member
Registered: 2011-08-09
Posts: 27

[Solved] AqBanking/GnuTLS certificate trust problem

Good evening,

I am trying to use aqbanking (in kmymoney) for internet banking. In the setup I see an error message regarding the certificate trust, in this example for ING DiBa

$ aqhbci-tool4 getsysid -b XXXXXX
[...]
Using GnuTLS default ciphers.
TLS: SSL-Ciphers negotiated: TLS1.2:ECDHE-RSA-AES-256-GCM:AEAD
Signer not found
Certificate is not trusted
===== Certificate Received =====
The following certificate has been received:
Name        : fints.ing-diba.de
Organisation: ING-DiBa AG
Department  : unknown
Country     : DE
City        : Frankfurt am Main
State       : unknown
Valid after : 2017/02/14 09:31:11
Valid until : 2018/02/14 10:01:09
Hash        : BC:73:B4:DD:14:94:72:D6:2C:B2:08:86:F6:40:8F:A6
Status      : Signer not found; Certificate is not trusted
Do you wish to accept this certificate?
(1) Yes  (2) No

When I verify the certificate with

$ gnutls-cli --print-cert fints.ing-diba.de
[...]
- Status: The certificate is trusted. 
- Description: (TLS1.2)-(ECDHE-RSA-SECP256R1)-(AES-256-GCM)
[...]

I get the complete certificate chain and it is correctly verified.

AqBanking is based on gnutls:

$ ldd /usr/bin/aqhbci-tool4 | grep gnutls
        libgnutls.so.30 => /usr/lib/libgnutls.so.30

Do you have any idea, what is going wrong here? And which hash is shown there?

Thanks.

Last edited by crobe2 (2017-10-07 17:31:28)

Offline

#2 2017-10-07 10:45:10

crobe2
Member
Registered: 2011-08-09
Posts: 27

Re: [Solved] AqBanking/GnuTLS certificate trust problem

I upgraded to gwenhywfar 4.18 and aqbanking 5.7.6beta (just changed the PKGBUILDS and rebuild) and the certificate verification works now as expected. SHA256 checksum is shown now too.

Offline

#3 2017-10-07 12:15:36

x33a
Forum Fellow
Registered: 2009-08-15
Posts: 4,587

Re: [Solved] AqBanking/GnuTLS certificate trust problem

Please mark the the thread as solved.

Offline

Board footer

Powered by FluxBB