hiqdev / asset-packagist

Asset Packagist
https://asset-packagist.org
BSD 3-Clause "New" or "Revised" License
247 stars 24 forks source link

SSL problem #161

Closed thiagotalma closed 10 months ago

thiagotalma commented 10 months ago

Please provide your composer.json if appropriate.

Is anyone else having trouble running composer update?

I'm finding it strange that the Subject CN is pointing to the wrong domain.

packagist.org instead of asset-packagist.org

How do you fix this?

$ openssl s_client -connect asset-packagist.org:443 </dev/null 2>/dev/null | openssl x509 -noout -text

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            04:db:6b:b9:50:6a:7f:99:74:12:13:d4:98:a1:b9:dd:0b:bf
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C = US, O = Let's Encrypt, CN = R3
        Validity
            Not Before: Sep 20 05:15:57 2023 GMT
            Not After : Dec 19 05:15:56 2023 GMT
        Subject: CN = packagist.org <<<<<-----------------------
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:c6:ce:e5:11:a5:85:8e:c3:8a:fa:c2:4f:fd:b4:
                    90:88:1b:ff:f4:70:12:25:7d:a0:b5:06:b5:78:df:
                    15:9e:1a:c5:32:61:f5:ce:ba:ec:1c:16:15:7e:6c:
                    8d:c9:16:d3:94:1d:dd:74:7a:8d:fd:54:bf:b0:ef:
                    ca:91:18:20:9d:26:3c:2b:c6:62:76:bc:99:8c:0a:
                    62:80:3d:0b:cf:bf:bc:c4:5b:10:74:66:69:8d:0f:
                    fe:b0:0c:29:bf:57:28:bd:31:51:91:e7:ef:7b:4c:
                    75:be:48:f7:c8:6b:e7:de:52:ff:9e:10:c0:59:a7:
                    78:64:94:63:9d:a7:2a:cd:47:fe:35:3e:83:86:70:
                    a8:7b:0d:7e:9b:1d:79:c7:50:07:dc:1e:6a:6e:46:
                    66:5b:b7:13:ff:25:4c:fc:01:d3:84:44:c4:57:48:
                    eb:aa:07:2b:df:41:7c:20:fa:12:c8:14:90:0b:97:
                    21:9d:07:bf:6b:89:1d:e7:a6:70:38:88:09:40:2d:
                    88:35:27:dc:04:b3:cc:52:33:fd:2f:bf:5c:1f:79:
                    eb:53:63:e5:43:9e:29:e1:16:fb:dc:a0:ad:fe:df:
                    48:75:f4:17:01:63:04:be:c0:46:78:a1:5d:40:9f:
                    eb:b3:3c:00:4a:f3:ec:c7:2b:2b:f9:11:08:aa:36:
                    28:e3
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Key Encipherment
            X509v3 Extended Key Usage:
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Subject Key Identifier:
                E6:D6:BF:72:FA:8E:43:75:E7:D4:02:90:17:13:63:E2:73:3B:22:27
            X509v3 Authority Key Identifier:
                keyid:14:2E:B3:17:B7:58:56:CB:AE:50:09:40:E6:1F:AF:9D:8B:14:C2:C6

            Authority Information Access:
                OCSP - URI:http://r3.o.lencr.org
                CA Issuers - URI:http://r3.i.lencr.org/

            X509v3 Subject Alternative Name:
                DNS:packagist.org, DNS:repo-ca-bhs-2.packagist.org, DNS:repo.packagist.org, DNS:www.packagist.org
            X509v3 Certificate Policies:
                Policy: 2.23.140.1.2.1

            CT Precertificate SCTs:
                Signed Certificate Timestamp:
                    Version   : v1 (0x0)
                    Log ID    : 7A:32:8C:54:D8:B7:2D:B6:20:EA:38:E0:52:1E:E9:84:
                                16:70:32:13:85:4D:3B:D2:2B:C1:3A:57:A3:52:EB:52
                    Timestamp : Sep 20 06:15:57.733 2023 GMT
                    Extensions: none
                    Signature : ecdsa-with-SHA256
                                30:46:02:21:00:A6:58:B2:C1:C2:BB:3E:0D:98:ED:0A:
                                33:DB:72:4D:EF:F8:15:1D:24:BD:B5:85:5B:AF:8C:67:
                                CD:7E:96:EA:98:02:21:00:D4:E8:E2:FC:31:23:7D:5F:
                                70:8F:81:0E:B9:F3:04:8C:18:F4:29:07:C3:E8:88:A0:
                                6E:DE:D9:95:92:1A:4D:93
                Signed Certificate Timestamp:
                    Version   : v1 (0x0)
                    Log ID    : E8:3E:D0:DA:3E:F5:06:35:32:E7:57:28:BC:89:6B:C9:
                                03:D3:CB:D1:11:6B:EC:EB:69:E1:77:7D:6D:06:BD:6E
                    Timestamp : Sep 20 06:15:57.716 2023 GMT
                    Extensions: none
                    Signature : ecdsa-with-SHA256
                                30:45:02:21:00:B6:67:E1:AA:CC:DA:3C:C8:40:6E:F1:
                                6A:A7:A2:1D:77:E0:31:28:D0:24:62:20:1A:E0:C0:AB:
                                AD:58:0A:C7:11:02:20:58:D4:E9:CA:A1:30:1C:08:3A:
                                0C:E5:24:33:66:7F:2F:5E:4A:7C:1A:80:DC:5D:5E:25:
                                D8:21:C9:AB:0B:4C:F3
    Signature Algorithm: sha256WithRSAEncryption
         2b:62:d3:22:04:8a:4a:0d:51:4c:db:12:15:14:80:35:f0:d2:
         3e:4b:71:45:8a:bf:88:3d:ce:84:c1:89:f9:ce:73:31:96:24:
         c5:93:80:e8:59:32:ad:97:5b:12:d1:30:0e:34:36:e8:74:47:
         36:53:97:35:6f:b2:a9:18:bb:0e:c7:31:2a:25:ee:d8:b6:34:
         c5:c6:e7:4a:fe:5f:36:98:d8:08:51:5c:d3:83:d2:6d:8d:b0:
         78:8b:01:dd:0f:2c:8c:93:f2:5a:d9:0d:db:df:27:3a:18:6a:
         58:41:7d:b8:c2:2d:c6:66:54:08:05:1b:47:ea:da:8a:33:82:
         1b:9e:00:9b:73:7c:2d:3f:45:c4:eb:c0:21:e4:d1:31:ee:04:
         0c:6c:19:b5:df:67:2f:d1:eb:d3:4b:98:f7:1d:a2:88:c3:18:
         35:08:ba:6b:79:83:43:f0:f8:ee:80:ce:97:2d:f4:6d:3b:b1:
         4b:e0:57:3e:83:2b:d7:8b:28:f2:05:83:6d:93:9c:6d:25:bd:
         80:6c:73:3e:b8:8f:88:18:0e:11:a8:77:1d:13:13:3b:2b:f6:
         d6:15:ea:08:0b:53:95:f2:c0:de:90:e4:c0:f9:52:33:74:30:
         70:42:fd:4b:f8:33:7c:21:b1:b6:71:c6:d8:e1:ec:91:2a:2e:
         0a:51:df:54
SilverFire commented 10 months ago

Hello. I guess you have a local DNS override. Could you show dig +trace asset-packagist.org output?

thiagotalma commented 10 months ago

Thank you for your attention.

I solved it by creating a new machine.