eworm-de / routeros-scripts

a collection of scripts for MikroTik RouterOS
GNU General Public License v3.0
1.28k stars 286 forks source link

www.spamhouse.org always fails certificate in fw-adr-lists #82

Closed ackstorm23 closed 13 hours ago

ackstorm23 commented 16 hours ago

Every time fw-update-lists runs, it shows this failure for www.spamhaus.org when trying to grab Cloudflare Inc ECC CA-3

> /system/script/run fw-addr-lists
info: Certificate with CommonName 'Cloudflare Inc ECC CA-3' not available.
info: Downloading and importing certificate with CommonName 'Cloudflare Inc ECC CA-3'.
warning: Failed downloading certificate with CommonName 'Cloudflare Inc ECC CA-3' from repository! Trying fallback to mkcert.org...
warning: Failed downloading certificate with CommonName 'Cloudflare Inc ECC CA-3'!
warning: Downloading required certificate (block / https://www.spamhaus.org/drop/drop.txt) failed, trying anyway.
warning: Failed downloading for list 'block' from: https://www.spamhaus.org/drop/drop.txt
info: Certificate with CommonName 'Cloudflare Inc ECC CA-3' not available.
info: Downloading and importing certificate with CommonName 'Cloudflare Inc ECC CA-3'.
warning: Failed downloading certificate with CommonName 'Cloudflare Inc ECC CA-3' from repository! Trying fallback to mkcert.org...
warning: Failed downloading certificate with CommonName 'Cloudflare Inc ECC CA-3'!
warning: Downloading required certificate (block / https://www.spamhaus.org/drop/edrop.txt) failed, trying anyway.
warning: Failed downloading for list 'block' from: https://www.spamhaus.org/drop/edrop.txt

From what I can gather, that cert is not available to the general public anymore

So what is the correct certificate to use for www.spamhaus.org and can we get that updated in the default config?

UPDATE:

"GTS Root R4" seems to work now.

eworm-de commented 13 hours ago

Already reported in #78 and fixed in 917be4b42574cd66254a4559330e83bc5c2ed233. I did not send notification as this is commented by default.

Also note that there are other changes, have a look at global-config.