You are not logged in.
Everything was running fine but i don't know how yesterday when i tried using firefox it just didn't work. Every time when i tried opening a website it timed out, i then downloaded chromiun and when i tried opening google or any website it told me that it's not a private network and something like NET_CERT_ERROR. The only browser that works right now is konquerer and even it gives me annoying pop-ups like "server failed the authenticity check", i have checked my date and time and they're not causing the problem. Please help me.
Last edited by anonguy_2017 (2020-04-15 14:11:47)
Offline
When reporting errors, please post them in full, without changing. It will help debugging the issue.
First things first: since it seems you have ignored the warnings, which tried to prevent you from doing something very irresponsible: consider all accounts, which you have used since then, to be already breached.
My guess, without actual errors, is that either:
Something went wrong during the last update of nss. The update required manual intervention and if one failed to do so, but instead forced the update in some other way, possibly something gor broken. I have no slightest idea how would that happen, but this is closest to the subject of your problems of all things in the recent updates.
Someone is in fact intercepting your traffic and the update just coincided with that.⁽¹⁾
In any case, post the output of:
echo | openssl s_client -connect archlinux.org:443 2>/dev/null | openssl x509 -textThis should at least let us know what certificate is the network presenting.
You may also watch the Browser access problem NET::ERR_CERT_AUTHORITY_INVALID thread: it seems someone else has a similarly looking problem that happened at the same time.
____
⁽¹⁾ While it would be an ineffective attempt in some cases, in a corporate environment it is possible that the firewall or antivirus software is doing that, expecting that workers have specific certificate installed.
Last edited by mpan (2020-04-15 05:19:10)
Offline
here's the output you asked for:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
03:23:70:75:11:4a:14:34:f4:7e:b0:75:ab:cc:e9:19:94:0c
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
Validity
Not Before: Mar 3 12:40:27 2020 GMT
Not After : Jun 1 12:40:27 2020 GMT
Subject: CN = [url=http://www.archlinux.org]www.archlinux.org[/url]
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (4096 bit)
Modulus:
00:c1:da:14:10:06:4f:72:e5:06:16:cc:e9:23:8d:
d8:ab:8d:67:07:bb:b4:ae:a0:35:5c:6f:86:9c:98:
9d:2b:31:15:c8:83:f7:e4:ac:0d:56:15:08:fa:8a:
5d:d0:de:1a:ec:98:83:44:52:31:38:72:b3:ef:77:
94:a0:73:02:7e:5d:f3:7a:35:16:f5:c5:d6:f5:8d:
92:6d:46:6d:c7:fc:8f:b4:19:07:6a:92:fb:bc:14:
87:db:95:48:99:73:ef:64:fc:71:0a:8e:bb:e6:01:
32:dd:5b:84:c4:4d:04:e1:93:01:b5:45:9c:31:82:
7e:96:13:7d:1f:3e:ef:fe:8a:e6:4e:f0:da:bc:c2:
46:19:d9:37:a8:83:50:c9:13:6e:5c:a0:f4:00:67:
6f:37:f9:40:4d:69:85:4b:e6:89:06:65:0d:76:d9:
ac:a2:69:ff:17:e2:24:32:86:ea:29:17:20:c9:b2:
cd:8d:ee:77:74:cb:ec:b4:ed:ef:95:1c:9b:ea:e6:
62:cb:3e:cf:1a:fd:d0:f8:52:66:60:74:e2:a4:e3:
f9:9e:87:a1:1b:6a:9b:33:51:1b:ec:c2:4f:7d:24:
79:eb:6e:a0:fb:eb:b6:d0:3a:70:a7:4a:b3:79:73:
09:61:47:47:ed:2e:aa:24:60:aa:e7:4b:5f:42:48:
7e:14:af:77:d0:02:f9:f7:8b:32:35:85:a4:d5:25:
f8:08:e9:25:ae:c4:c8:a3:eb:12:a3:1e:35:9a:0e:
0f:e9:09:dd:a3:96:de:4c:98:2a:73:96:fb:c5:6a:
96:8f:c1:b3:72:9d:e3:67:5f:3d:24:52:6c:73:a2:
cb:30:27:f7:1e:8c:36:8a:aa:49:1a:63:6b:4b:2c:
ed:e8:ab:6d:e5:b1:3c:91:2e:bb:7d:b8:f1:be:b8:
7f:28:5c:3c:4b:2c:9c:97:1c:24:c5:69:db:0d:13:
ef:80:34:6c:1e:a3:ff:e1:69:fc:1b:c6:fa:52:f9:
09:01:22:d3:8a:1b:41:f2:ee:af:02:a9:0f:26:91:
4a:c6:8e:de:67:e4:bc:14:6f:4a:31:07:8a:a4:a1:
82:49:a6:6a:a0:81:d9:0e:2b:bf:a6:df:31:fe:b8:
fd:13:a0:88:e2:3e:7f:28:04:31:1c:41:e8:4e:ad:
da:ce:23:a5:ae:6d:57:f4:f1:01:cd:98:b3:3d:3b:
dc:ff:40:f1:77:66:b0:13:b0:d7:11:ad:f6:73:df:
16:63:3b:55:ba:55:95:b4:b4:7b:a7:2e:bc:f2:1a:
19:e9:ff:39:f0:de:dc:8e:b2:1f:cd:36:a6:0e:24:
49:04:53:a1:30:f9:84:9b:63:36:7f:f3:a0:52:16:
2a:82:e3
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Subject Key Identifier:
1E:07:3E:17:04:98:7C:4E:18:21:61:B9:03:58:75:05:40:F2:8A:E6
X509v3 Authority Key Identifier:
keyid:A8:4A:6A:63:04:7D:DD:BA:E6:D1:39:B7:A6:45:65:EF:F3:A8:EC:A1
Authority Information Access:
OCSP - URI:http://ocsp.int-x3.letsencrypt.org
CA Issuers - URI:http://cert.int-x3.letsencrypt.org/
X509v3 Subject Alternative Name:
DNS:archlinux.org, DNS:dev.archlinux.org, DNS:ipxe.archlinux.org, DNS:master-key.archlinux.org, DNS:packages.archlinux.org, DNS:planet.archlinux.org, DNS:www.archlinux.org
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
Policy: 1.3.6.1.4.1.44947.1.1.1
CPS: [url]http://cps.letsencrypt.org[/url]
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : F0:95:A4:59:F2:00:D1:82:40:10:2D:2F:93:88:8E:AD:
4B:FE:1D:47:E3:99:E1:D0:34:A6:B0:A8:AA:8E:B2:73
Timestamp : Mar 3 13:40:27.922 2020 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:46:02:21:00:8A:80:3D:6E:D1:03:CB:DF:30:45:1C:
4D:71:1D:9E:F7:E8:9B:6F:CA:BE:1C:96:4B:E1:D6:B2:
83:E3:D8:96:D0:02:21:00:E2:74:2B:D6:52:FB:51:E3:
35:3A:AC:88:16:F1:CE:2D:86:E7:1A:7D:76:D7:96:D2:
2E:EB:1A:8F:60:C7:F2:89
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : B2:1E:05:CC:8B:A2:CD:8A:20:4E:87:66:F9:2B:B9:8A:
25:20:67:6B:DA:FA:70:E7:B2:49:53:2D:EF:8B:90:5E
Timestamp : Mar 3 13:40:27.949 2020 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:45:02:21:00:F0:02:54:3E:56:04:56:C9:07:8C:CA:
F3:AB:1A:63:08:84:C1:01:B5:A7:F5:88:5B:77:C4:43:
0E:BF:13:53:2B:02:20:3B:63:41:28:9A:0F:64:11:5B:
D3:36:3A:92:5D:AB:70:E3:59:0C:2C:4E:C0:9A:CB:1F:
8D:57:54:8A:E1:BC:30
Signature Algorithm: sha256WithRSAEncryption
57:3b:01:a9:4d:6f:b3:34:12:52:50:c3:82:be:44:dd:e4:4a:
ae:66:97:83:38:d6:3f:26:9e:a2:71:f5:1a:fb:51:50:07:19:
a0:cf:b7:25:02:60:49:33:85:56:23:66:b6:50:e3:84:5d:8c:
13:06:7d:85:09:42:ab:3d:a8:a8:99:99:32:ee:1d:aa:6d:cc:
6e:96:1c:90:39:10:e4:cc:aa:b4:be:0a:09:80:c4:4b:5d:39:
cb:d8:1f:35:a3:f5:d4:bd:20:3e:55:a2:8e:96:d7:ce:c9:64:
8e:82:40:ed:a4:63:c0:75:f8:25:59:92:2f:96:6f:11:0d:3e:
11:22:e7:64:d3:eb:70:fe:45:48:74:3f:68:98:24:80:06:0e:
30:23:4b:ad:a8:2d:6b:51:90:c0:c1:3a:3f:a5:41:63:10:47:
c4:be:33:1c:03:98:c6:27:7c:1c:f7:ee:35:de:29:a0:e1:27:
06:6a:41:db:7a:41:04:c6:59:09:72:09:cc:a4:6a:b4:45:b4:
0a:ff:51:d4:43:02:03:7d:8f:c2:9b:69:6e:e5:ad:b9:31:5a:
ca:2e:b8:ae:a6:27:0a:fe:d9:90:12:5c:2f:6e:bd:cf:b2:57:
59:02:ca:ab:11:aa:9f:d3:3c:22:e1:93:21:d5:04:27:30:2f:
a7:87:7f:1a
-----BEGIN CERTIFICATE-----
MIIG3DCCBcSgAwIBAgISAyNwdRFKFDT0frB1q8zpGZQMMA0GCSqGSIb3DQEBCwUA
MEoxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQD
ExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBYMzAeFw0yMDAzMDMxMjQwMjdaFw0y
MDA2MDExMjQwMjdaMBwxGjAYBgNVBAMTEXd3dy5hcmNobGludXgub3JnMIICIjAN
BgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAwdoUEAZPcuUGFszpI43Yq41nB7u0
rqA1XG+GnJidKzEVyIP35KwNVhUI+opd0N4a7JiDRFIxOHKz73eUoHMCfl3zejUW
9cXW9Y2SbUZtx/yPtBkHapL7vBSH25VImXPvZPxxCo675gEy3VuExE0E4ZMBtUWc
MYJ+lhN9Hz7v/ormTvDavMJGGdk3qINQyRNuXKD0AGdvN/lATWmFS+aJBmUNdtms
omn/F+IkMobqKRcgybLNje53dMvstO3vlRyb6uZiyz7PGv3Q+FJmYHTipOP5noeh
G2qbM1Eb7MJPfSR5626g++u20Dpwp0qzeXMJYUdH7S6qJGCq50tfQkh+FK930AL5
94syNYWk1SX4COklrsTIo+sSox41mg4P6Qndo5beTJgqc5b7xWqWj8Gzcp3jZ189
JFJsc6LLMCf3How2iqpJGmNrSyzt6Ktt5bE8kS67fbjxvrh/KFw8SyyclxwkxWnb
DRPvgDRsHqP/4Wn8G8b6UvkJASLTihtB8u6vAqkPJpFKxo7eZ+S8FG9KMQeKpKGC
SaZqoIHZDiu/pt8x/rj9E6CI4j5/KAQxHEHoTq3aziOlrm1X9PEBzZizPTvc/0Dx
d2awE7DXEa32c98WYztVulWVtLR7py688hoZ6f858N7cjrIfzTamDiRJBFOhMPmE
m2M2f/OgUhYqguMCAwEAAaOCAugwggLkMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUE
FjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU
Hgc+FwSYfE4YIWG5A1h1BUDyiuYwHwYDVR0jBBgwFoAUqEpqYwR93brm0Tm3pkVl
7/Oo7KEwbwYIKwYBBQUHAQEEYzBhMC4GCCsGAQUFBzABhiJodHRwOi8vb2NzcC5p
bnQteDMubGV0c2VuY3J5cHQub3JnMC8GCCsGAQUFBzAChiNodHRwOi8vY2VydC5p
bnQteDMubGV0c2VuY3J5cHQub3JnLzCBnAYDVR0RBIGUMIGRgg1hcmNobGludXgu
b3JnghFkZXYuYXJjaGxpbnV4Lm9yZ4ISaXB4ZS5hcmNobGludXgub3JnghhtYXN0
ZXIta2V5LmFyY2hsaW51eC5vcmeCFnBhY2thZ2VzLmFyY2hsaW51eC5vcmeCFHBs
YW5ldC5hcmNobGludXgub3JnghF3d3cuYXJjaGxpbnV4Lm9yZzBMBgNVHSAERTBD
MAgGBmeBDAECATA3BgsrBgEEAYLfEwEBATAoMCYGCCsGAQUFBwIBFhpodHRwOi8v
Y3BzLmxldHNlbmNyeXB0Lm9yZzCCAQUGCisGAQQB1nkCBAIEgfYEgfMA8QB3APCV
pFnyANGCQBAtL5OIjq1L/h1H45nh0DSmsKiqjrJzAAABcKCgWJIAAAQDAEgwRgIh
AIqAPW7RA8vfMEUcTXEdnvfom2/KvhyWS+HWsoPj2JbQAiEA4nQr1lL7UeM1OqyI
FvHOLYbnGn1215bSLusaj2DH8okAdgCyHgXMi6LNiiBOh2b5K7mKJSBna9r6cOey
SVMt74uQXgAAAXCgoFitAAAEAwBHMEUCIQDwAlQ+VgRWyQeMyvOrGmMIhMEBtaf1
iFt3xEMOvxNTKwIgO2NBKJoPZBFb0zY6kl2rcONZDCxOwJrLH41XVIrhvDAwDQYJ
KoZIhvcNAQELBQADggEBAFc7AalNb7M0ElJQw4K+RN3kSq5ml4M41j8mnqJx9Rr7
UVAHGaDPtyUCYEkzhVYjZrZQ44RdjBMGfYUJQqs9qKiZmTLuHaptzG6WHJA5EOTM
qrS+CgmAxEtdOcvYHzWj9dS9ID5Voo6W187JZI6CQO2kY8B1+CVZki+WbxENPhEi
52TT63D+RUh0P2iYJIAGDjAjS62oLWtRkMDBOj+lQWMQR8S+MxwDmMYnfBz37jXe
KaDhJwZqQdt6QQTGWQlyCcykarRFtAr/UdRDAgN9j8KbaW7lrbkxWsouuK6mJwr+
2ZASXC9uvc+yV1kCyqsRqp/TPCLhkyHVBCcwL6eHfxo=
-----END CERTIFICATE-----And regarding that nss update, i moved that file that won't let me update, updates my system then placed it back again and i don't think my network is pwned because i use my phone's data using usb and i don't have any logins or account on konqueror
Last edited by anonguy_2017 (2020-04-15 09:14:13)
Offline
You shouldn't have manually moved around files, read: https://www.archlinux.org/news/nss3511- … ervention/ reinstall nss.
Please wrap that output in [ code ] [ /code ] tags without the spaces.
Offline
actually that was the first thing that i did but it didn't work so then i decided that i should move the files
Offline
Then something seems to have been broken even beforehand. Post your pacman.log. And what exactly "didn't work", which error did you get? Also
pacman -Qkk nssOffline
so the output was
warning: nss: /usr/lib/p11-kit-trust.so (Symlink path mismatch)
warning: nss: /usr/lib/p11-kit-trust.so (Modification time mismatch)
nss: 143 total files, 1 altered fileJust went through my history and found out that i accidentally typed
sudo pacman -Syu --overwrite /usr/lib/p11-kit-trust.sinstead of
sudo pacman -Syu --overwrite /usr/lib\*/p11-kit-trust.soand when it didn't work then i moved that files and updated it.
Offline
If you now rerun the correct command, do you still get the errors (both the one that caused this thread and the mismatch from the package check)?
Offline
just did what op on this thread did https://bbs.archlinux.org/viewtopic.php?id=254684, Everything works fine now. Thanks.
Offline