Package Details: ca-certificates-fnmt 20250406-1

Git Clone URL: https://aur.archlinux.org/ca-certificates-fnmt.git (read-only, click to copy)
Package Base: ca-certificates-fnmt
Description: Spanish Fabrica Nacional de Moneda y Timbre (FNMT) y Real Casa de la Moneda (RCM) certificates
Upstream URL: https://www.sede.fnmt.gob.es
Licenses: unknown
Submitter: blackleg
Maintainer: sl1pkn07
Last Packager: sl1pkn07
Votes: 19
Popularity: 0.000156
First Submitted: 2015-10-02 20:07 (UTC)
Last Updated: 2025-04-06 13:26 (UTC)

Latest Comments

1 2 3 4 5 6 Next › Last »

poinu commented on 2025-04-05 17:51 (UTC) (edited on 2025-04-05 17:55 (UTC) by poinu)

Thanks @sl1pkn07 for maintaining this package, it's very helpful.

As someone else posted, I also get the following curl error while trying to download the certificates:

curl: (60) SSL certificate problem: unable to get local issuer certificate

I've investigated a bit and the issue is caused by the following: The package gets all the FNMT certs from https://www.sede.fnmt.gob.es, but the website itself is reached through HTTPS, and it is signed with a certificate chain.

The certificate chain is composed with: AC RAIZ FNMT-RCM > AC Componentes Informáticos > www.sede.fnmt.gob.es (server cert)

'AC RAIZ FNMT-RCM' is provided by the ca-certificates-mozilla package and will most likely be found in your system CA certs. The server cert for www.sede.fnmt.gob.es is provided by the webserver serving the page, but the webserver doesn't provide the intermediate certificate ('AC Componentes Informáticos'), and curl fails to verify the server certificate and gives the previous error.

The browsers don't give an error because they are able to obtain the intermediate certificate through the AIA (Authority Information Access) extension, which tells them where to download the missing intermediate certificate. Curl, however, doesn't do this automatically.

In this case the server certificate contains the following AIA details:

            Authority Information Access: 
                OCSP - URI:http://ocspcomp.cert.fnmt.es/ocsp/OcspResponder
                CA Issuers - URI:http://www.cert.fnmt.es/certs/ACCOMP.crt

From this we can pull the intermediate cert ACCOMP.crt (through HTTP!) and use that to complete the certificate chain. Note that ACCOMP.crt is nothing but the cert for 'AC Componentes Informáticos' which is also downloaded by this package, they have the exact same SHA sum.

Once we have the cert we can extract the pem with the following command:

openssl x509 -in ACCOMP.crt -out ACCOMP.pem

And make it available to curl it to curl with:

CURL_CA_BUNDLE=./ACCOMP.pem curl ...

with which it should no longer fail.

As per the changes required to fix this in the PKGBUILD, we should probably add ca-certificates-mozilla package as a dependency (to make sure the root cert is in the CA), and download and install ACCOMP.pem from http://www.cert.fnmt.es/certs/ before trying to download any other certs, but I don't know what would be the best way to achieve this (maybe playing with DLAGENTS?).

pmestre commented on 2024-12-20 12:11 (UTC) (edited on 2024-12-20 12:14 (UTC) by pmestre)

Working as today sha256sums=(

'ebc5570c29018c4d67b1aa127baf12f703b4611ebc17b7dab5573894179b93fa'

'601293ca20b09a03295d196256c6953ff9eba811db8e3ce140413c1bffe9a869'

'8fd16a179944d5d1d420af09405eda7abf2a9c742883e8c2f89e0d90afaf754b'

'830ff205ae69485059c3fb2376a7f2f9ee1c2a61de259dd09d0bb6ad69f88832'

'f038421f07f20d63a20d3691e5a178ab8459ebe570c1647b7690554ef23876ab'

'8265756dd5cd8a37ee61e40351288e4b16a89dd248c1ec4eba25aaf161abf498'

'9ce630b35f8ae2c6419e734ad9d2fa30476dd9e7394b1e93b27f83f776a024ea'

'554153b13d2cf9ddb753bfbe1a4e0ae08d0aa4187058fe60a2b862b2e4b87bcb'

'1edb6bd91274882db795bfc514f8aabe10ad955cbccfd3fd5a5b5febb2ce5b68'

'9ff23cb9387b9e0083bd5aa1954eeddf792890aa8e67cd4d38dd28af4a439ad8'

'19001c4ba4846d17809b25f90a94d1cab20a86777968737ce4b34bb9d7eae078'

'5320d7a5dfc8023cedb0c233363a318eb1daa3d35d02b5d986dca2b5b98393b3'

'9dd74806fd1e3ed1cf65cf04764f034e7e04bf23c753f2aff3c749cd45227f11'

'4c7d254f258cb71db48d17f6134e7e8d8b47a5f886bd85f397bd47a2750297f2'

'e40f1d8891bbe0243306e70f4c0d34199f788958be1e40261b3ab4b957382c29'

'988a86178185162999bb6f0ade55c3ff0047b58ba0088f0e308e194456cf22d2'

'b1ae56dfacbb14838b9208567a8952ef977ea5ae61609dc4dd1140f4ac8b60e3'

'f91deaa0faef3bd9d2c9764ab9b14d17ce69427f785a1bf76d38222660976619'

'10f54909204a9ec23e9e9317739a521499018ed5316fdae6a7367ac00d5a5660'

'b03f7cc682d2f0a7c1d195692cc0de4c35ad017294955d35f6eb743fe78595f3'

'fcfd3df490b9a21b3fad582011a2e6d039561796ac5d850d01b65ac5dda4a3e9'

'baf597d97d16bc697f8eb2a1e20ce68c08ad11024f9b1f5264271c1525eeb500'

)

marcosag commented on 2024-12-11 16:38 (UTC)

I get this errors: curl: (60) SSL peer certificate or SSH remote key was not OK More details here: https://curl.se/docs/sslcerts.html

curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it. To learn more about this situation and how to fix it, please visit the webpage mentioned above.

bike-bill commented on 2024-09-28 22:50 (UTC) (edited on 2024-09-28 22:51 (UTC) by bike-bill)

Here is a working set as of 2024 Sept 24:

'ebc5570c29018c4d67b1aa127baf12f703b4611ebc17b7dab5573894179b93fa'

'601293ca20b09a03295d196256c6953ff9eba811db8e3ce140413c1bffe9a869'

'8fd16a179944d5d1d420af09405eda7abf2a9c742883e8c2f89e0d90afaf754b'

'830ff205ae69485059c3fb2376a7f2f9ee1c2a61de259dd09d0bb6ad69f88832'

'f038421f07f20d63a20d3691e5a178ab8459ebe570c1647b7690554ef23876ab'

'8265756dd5cd8a37ee61e40351288e4b16a89dd248c1ec4eba25aaf161abf498'

'9ce630b35f8ae2c6419e734ad9d2fa30476dd9e7394b1e93b27f83f776a024ea'

'554153b13d2cf9ddb753bfbe1a4e0ae08d0aa4187058fe60a2b862b2e4b87bcb'

'1edb6bd91274882db795bfc514f8aabe10ad955cbccfd3fd5a5b5febb2ce5b68'

'9ff23cb9387b9e0083bd5aa1954eeddf792890aa8e67cd4d38dd28af4a439ad8'

'19001c4ba4846d17809b25f90a94d1cab20a86777968737ce4b34bb9d7eae078'

'f921bc412987e9b0871d152c3ee0423334a83667eda7a4980732363a9e6b4231'

'2d562c72e69fac3a1a7c4599d37f3a02bdca7da595bff65137dbc77c355aade2'

'4c7d254f258cb71db48d17f6134e7e8d8b47a5f886bd85f397bd47a2750297f2'

'c858c2a5acfd415670587de6b395bf881690d667f90f61e2dc9e4b97c818a6ee'

'81ab67051af044545d2b1a4d6564787e2e2bfd47f14af5b9e243fdf625077612'

'7b3447ef0dea618c80d1a5be4af0fb6b81ba7e580a2c437a45385c465679b17f'

'7605176d4ed4526b5a104ca27c105e301936f76ac3b58645c551a212bfe8c6d0'

'2334b1fec4ff67bb00f82bf1dda9062eb070dbcf1d0228038f89731803b52905'

'b03f7cc682d2f0a7c1d195692cc0de4c35ad017294955d35f6eb743fe78595f3'

'5d93e19f26bcdcc9744f3f342a7d09b3d4d11f3e2dfd4c6079821625878be10a'

'baf597d97d16bc697f8eb2a1e20ce68c08ad11024f9b1f5264271c1525eeb500'

CapNovolin commented on 2024-08-05 18:16 (UTC) (edited on 2024-08-05 18:17 (UTC) by CapNovolin)

Correct sha256sums for version 20240608-1 (edited: fixed line breaks)

'ebc5570c29018c4d67b1aa127baf12f703b4611ebc17b7dab5573894179b93fa'

'601293ca20b09a03295d196256c6953ff9eba811db8e3ce140413c1bffe9a869'

'8fd16a179944d5d1d420af09405eda7abf2a9c742883e8c2f89e0d90afaf754b'

'830ff205ae69485059c3fb2376a7f2f9ee1c2a61de259dd09d0bb6ad69f88832'

'f038421f07f20d63a20d3691e5a178ab8459ebe570c1647b7690554ef23876ab'

'8265756dd5cd8a37ee61e40351288e4b16a89dd248c1ec4eba25aaf161abf498'

'9ce630b35f8ae2c6419e734ad9d2fa30476dd9e7394b1e93b27f83f776a024ea'

'554153b13d2cf9ddb753bfbe1a4e0ae08d0aa4187058fe60a2b862b2e4b87bcb'

'1edb6bd91274882db795bfc514f8aabe10ad955cbccfd3fd5a5b5febb2ce5b68'

'9ff23cb9387b9e0083bd5aa1954eeddf792890aa8e67cd4d38dd28af4a439ad8'

'65c1ae74210a30a24e53360a4e1f60a9b3339e14750311edc7c9773f0dcb482f'

'f921bc412987e9b0871d152c3ee0423334a83667eda7a4980732363a9e6b4231'

'2d562c72e69fac3a1a7c4599d37f3a02bdca7da595bff65137dbc77c355aade2'

'4c7d254f258cb71db48d17f6134e7e8d8b47a5f886bd85f397bd47a2750297f2'

'c858c2a5acfd415670587de6b395bf881690d667f90f61e2dc9e4b97c818a6ee'

'81ab67051af044545d2b1a4d6564787e2e2bfd47f14af5b9e243fdf625077612'

'7b3447ef0dea618c80d1a5be4af0fb6b81ba7e580a2c437a45385c465679b17f'

'7605176d4ed4526b5a104ca27c105e301936f76ac3b58645c551a212bfe8c6d0'

'2334b1fec4ff67bb00f82bf1dda9062eb070dbcf1d0228038f89731803b52905'

'b03f7cc682d2f0a7c1d195692cc0de4c35ad017294955d35f6eb743fe78595f3'

'5d93e19f26bcdcc9744f3f342a7d09b3d4d11f3e2dfd4c6079821625878be10a'

'baf597d97d16bc697f8eb2a1e20ce68c08ad11024f9b1f5264271c1525eeb500'

Dequei commented on 2024-06-07 17:34 (UTC)

What is the correct sha256sum now?

It's failing for me now.

Thank you

makhlaghi commented on 2024-04-09 15:15 (UTC) (edited on 2024-04-09 15:29 (UTC) by makhlaghi)

In version 20240317-1, the following checksums for OSCP_AC_Servidores_Seguros_Tipo1_20240317.cer and OSCP_AC_Servidores_Seguros_Tipo2_20240317.cer need to be changed otherwise the package will not build because of FAILED validations:

  • f657d5413727807f0f140420700bad226259031544524d37848626252fef1334 should be 797a960349282702090b8e083d827eab94fea3824d23402ebf2df42c4573b806.

  • dbb48cd3754d315341d14697e8608c76910f406fd4eb6ef357e042498c89a557 should be 2dd5b347c0bba8fedb40b0cdbaf6581ced46fa3b2e68a6bf98dee3423171c35f.

c0r3dump3d commented on 2024-02-15 17:09 (UTC) (edited on 2024-02-15 17:10 (UTC) by c0r3dump3d)

With theses sha256sum it's working for me:

sha256sums=( 'ebc5570c29018c4d67b1aa127baf12f703b4611ebc17b7dab5573894179b93fa'

'601293ca20b09a03295d196256c6953ff9eba811db8e3ce140413c1bffe9a869'

'8fd16a179944d5d1d420af09405eda7abf2a9c742883e8c2f89e0d90afaf754b'

'830ff205ae69485059c3fb2376a7f2f9ee1c2a61de259dd09d0bb6ad69f88832'

'f038421f07f20d63a20d3691e5a178ab8459ebe570c1647b7690554ef23876ab'

'8265756dd5cd8a37ee61e40351288e4b16a89dd248c1ec4eba25aaf161abf498'

'9ce630b35f8ae2c6419e734ad9d2fa30476dd9e7394b1e93b27f83f776a024ea'

'554153b13d2cf9ddb753bfbe1a4e0ae08d0aa4187058fe60a2b862b2e4b87bcb'

'1edb6bd91274882db795bfc514f8aabe10ad955cbccfd3fd5a5b5febb2ce5b68'

'9ff23cb9387b9e0083bd5aa1954eeddf792890aa8e67cd4d38dd28af4a439ad8'

'd997e488f49127ac2df825f895cbb461a25b79d696b984123c66305282dc5ebb'

'a0a1426a65ad1344bd73af71d21d98bdf643b4b3baf8d252b76673294e136b70'

'a521d79b9e4d5f94646aafefe365e2eb51158aaef2134ee22e96d6a34fda7e99'

'4c7d254f258cb71db48d17f6134e7e8d8b47a5f886bd85f397bd47a2750297f2'

'ee81b63c1f8761a1875f197c8b0f53b8dd4e87533756b9b63504b56f8a1a5c55'

'2fafc47838bb09da94ecfdbaa999d14303c44d0d680685efae03fb2c84179ee5'

'2ac88ecd7f70bbee01fbd5d7290bc07bb57e5f885ae871a6eadee9d1f069475f'

'f657d5413727807f0f140420700bad226259031544524d37848626252fef1334'

'dbb48cd3754d315341d14697e8608c76910f406fd4eb6ef357e042498c89a557'

'b03f7cc682d2f0a7c1d195692cc0de4c35ad017294955d35f6eb743fe78595f3'

'5d93e19f26bcdcc9744f3f342a7d09b3d4d11f3e2dfd4c6079821625878be10a'

'baf597d97d16bc697f8eb2a1e20ce68c08ad11024f9b1f5264271c1525eeb500'

'62b9267266212832a8e22dab933d91c7011274acf71703f9cc97833751a6e94f'

)

was commented on 2024-02-13 09:59 (UTC)

Wrong sha256 in some certificates.

usuariopolivalen commented on 2024-01-10 10:57 (UTC)

Error en las verificaciones SHA