From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from ciao.gmane.io (ciao.gmane.io [116.202.254.214]) by sourceware.org (Postfix) with ESMTPS id 3F2653858415 for ; Tue, 5 Oct 2021 22:45:03 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.1 sourceware.org 3F2653858415 Received: from list by ciao.gmane.io with local (Exim 4.92) (envelope-from ) id 1mXtBF-0009HY-Me for cygwin@cygwin.com; Wed, 06 Oct 2021 00:45:01 +0200 X-Injected-Via-Gmane: http://gmane.org/ To: cygwin@cygwin.com From: Jib Style Subject: Emacs, GnuTLS, and DST Root CA X3 Date: Tue, 05 Oct 2021 01:22:22 -0700 Message-ID: Mime-Version: 1.0 Content-Type: text/plain User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (cygwin) Cancel-Lock: sha1:u0UEulDY94rbN6xZBg8F4sHmE5I= X-Spam-Status: No, score=2.0 required=5.0 tests=BAYES_00, DATE_IN_PAST_12_24, DKIM_ADSP_CUSTOM_MED, FORGED_GMAIL_RCVD, FREEMAIL_FORGED_FROMDOMAIN, FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS, KAM_DMARC_STATUS, KAM_NUMSUBJECT, NML_ADSP_CUSTOM_MED, SPF_HELO_NONE, SPF_PASS, TXREP autolearn=no autolearn_force=no version=3.4.4 X-Spam-Level: * X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on server2.sourceware.org X-BeenThere: cygwin@cygwin.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: General Cygwin discussions and problem reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 05 Oct 2021 22:45:04 -0000 Several days ago, root certificate "DST Root CA X3" expired, breaking TLS for many clients. I believe the lastest version of GnuTLS available on Cygwin (3.6.9, 2 years ago) is impacted. Is anyone able to publish a newer version of this package? This impacts me as I use Cygwin Emacs and can no longer open TLS connections to many hosts for the purposes of web browsing and newsgroups. I believe all other Cygwin Emacs users would be impacted also. Repro steps: 1. Install Cygwin default packages. 2. Install Cygwin package emacs-w32 27.2-1. 3. In Cygwin terminal: emacs -nw -Q 4. In Emacs: M-: (url-retrieve-synchronously "https://gnu.org") Expected: Emacs should load webpage and return a buffer. Actual: Emacs network security manager says certificate expired/could not be verified. After discussing this in the #emacs Libera.chat IRC, the consensus was that the old GnuTLS version is to blame, and that a newer version would fix the problem. Does anyone have similar issues or tips on how to resolve? Thank you.