Bug 1215288

Summary: OpenVPN certificate for yellowzone has expired
Product: [SUSE Tools] YellowZone Reporter: Heikki Ylipiessa <heikki.ylipiessa>
Component: Austin:SUSE-YZAssignee: Héctor Orón Martínez <hector.oron>
Status: NEW --- QA Contact: Héctor Orón Martínez <hector.oron>
Severity: Major    
Priority: P2 - High CC: bugproxy, gery.schneider, kanderssen, sarahw
Version: unspecified   
Target Milestone: ---   
Hardware: PowerPC-64   
OS: SLES 15   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Heikki Ylipiessa 2023-09-13 08:55:22 UTC
Our openvpn certificate is valid:
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            d3:91:a8:b9:2f:41:b6:9f
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN = SGN-NOC
        Validity
            Not Before: Jun  9 15:55:08 2021 GMT
            Not After : Jun  7 15:55:08 2031 GMT
        Subject: CN = SGN-NOC


But we are currently getting following error while connecting to YellowZone:
2023-09-13 10:38:31 VERIFY OK: depth=1, CN=SGN-NOC
2023-09-13 10:38:31 VERIFY ERROR: depth=0, error=certificate has expired: CN=sgn-ngc-zone0, serial=87273420346256416325144107893323437506
2023-09-13 10:38:31 OpenSSL: error:0A000086:SSL routines::certificate verify failed:
2023-09-13 10:38:31 TLS_ERROR: BIO read tls_read_plaintext error
2023-09-13 10:38:31 TLS Error: TLS object -> incoming plaintext read error
2023-09-13 10:38:31 TLS Error: TLS handshake failed
2023-09-13 10:38:31 SIGUSR1[soft,tls-error] received, process restarting


Problem seems to be with the cert in IBM side.
Comment 1 Knut Alejandro Anderssen González 2023-09-14 06:17:21 UTC
Sarah, we are having problems due to the certificate when trying to connect the VPN, could you take a look?
Comment 2 Géry Schneider 2023-09-19 08:43:16 UTC
(In reply to Knut Alejandro Anderssen González from comment #1)
> Sarah, we are having problems due to the certificate when trying to connect
> the VPN, could you take a look?

Hello Knut,
I am removuing the NeedInfo Flag.
If the problem is not solved yet, please do not hesitate to set it back.
Thank you for your support.