Hi,
I use a local certification installtion on my Windows 11 Laptop for development with XAMPP 7.4.29. It worked fine, but starting yesterday, my local sites cannot use S… (funda kabanzi)
Hi,
I use a local certification installtion on my Windows 11 Laptop for development with XAMPP 7.4.29. It worked fine, but starting yesterday, my local sites cannot use SSL.
Test: echo QUIT | wsl openssl s_client -CAfile /mnt/c/.../rootCA.crt -connect dev.fd:443
CONNECTED(00000003)
depth=1 C = DE, ST = Hessen, L = Frankfurt, O = syncgw.com, OU = Cybertrust, CN = Syncgw CyberTrust Root
verify return:1
depth=0 C = DE, ST = Hessen, L = Frankfurt, O = syncgw.com, OU = Cybertrust, CN = dev.fd
verify return:1
---
Certificate chain
0 s:C = DE, ST = Hessen, L = Frankfurt, O = syncgw.com, OU = Cybertrust, CN = dev.fd
i:C = DE, ST = Hessen, L = Frankfurt, O = syncgw.com, OU = Cybertrust, CN = Syncgw CyberTrust Root
BEGIN CERTIFICATE-----
MIIFcTCCA1kCFA0BuGGXuXPtO9lWXP86w9icnnucMA0GCSqGSIb3DQEBDQUAMH0x
CzAJBgNVBAYTAkRFMQ8wDQYDVQQIDAZIZXNzZW4xEjAQBgNVBAcMCUZyYW5rZnVy
dDETMBEGA1UECgwKc3luY2d3LmNvbTETMBEGA1UECwwKQ3liZXJ0cnVzdDEfMB0G
A1UEAwwWU3luY2d3IEN5YmVyVHJ1c3QgUm9vdDAeFw0yMjA2MDYxMDUxNDlaFw0z
MjA2MDMxMDUxNDlaMG0xCzAJBgNVBAYTAkRFMQ8wDQYDVQQIDAZIZXNzZW4xEjAQ
BgNVBAcMCUZyYW5rZnVydDETMBEGA1UECgwKc3luY2d3LmNvbTETMBEGA1UECwwK
Q3liZXJ0cnVzdDEPMA0GA1UEAwwGZGV2LmZkMIICIjANBgkqhkiG9w0BAQEFAAOC
Ag8AMIICCgKCAgEAy3D3wSnaaUsA8NHLIxT5UOj0hPj0gCUZF1sxgkm19YaJzOXq
du2KktRPeCrFU9yCMCPYg6e03Np3zicbcNomCYwuIsV1ItdDSd/M+hlkbSiHNIGf
5wcu8OSHVP5Z8kQY70u3pldyLTw7cKrIsqTZ4p4pBWSCMxvxc/LNaYjURpF/TIGi
funS90aO1NdetMKB4nATwNvsUMJzbgplVY+nB9Zx8Bvh36UeN6iAac8QjBzjD61I
P2lul+0U3RnzG8e5ERnFU39aKF3BCn2j4H5jX6uS7sthNfanT1HlelH2P0nIQUBX
89f692K3a3cmO17b6Jf4AO4HzZaHcfzAyiibpKq0QtHQWOTfw8FEFwLuE+/3sCJy
hV5K5GdAgYAlHKVZhZfpIlhm37npGIRexQkSdON0X5wDFSyeFCF+x1UUq5izVtId
JfPOlzsOgSoHvGrABkVqPDxxLXrHUSLn3EiwzbvYbd2zmew3g472RYCEWUYenP1Z
tvNngj/Z9bRTebyvhDNGxUJVHDt+/Wv/kI57XktYN+2EeMhSNxYO1pfkin5QgK80
3w2vd4oKi9C1URgQjzUDsR63IaeuQVVNCJv1eEnfm9e97KWpYrvj/E1g4A/Npugj
MmPvSAgMcE5U3N8Ey+w+lKCEVXFjkAJRR5o4iGmxcn81VIibgU59oEblHdECAwEA
ATANBgkqhkiG9w0BAQ0FAAOCAgEAn7THYqQEeaznJKf/CMY3pzpO9kt2N1xtqafn
Dy28hhb+xbFQd1nKnYMe0SqxsocynQgsMp/oKni0USyHjqPMqctQ4t3R+JTb9SjL
NujqwrFBh9kgBQX9LO043LQeMd/QAV05iR/Hhuodd47KkSjeNIexqd+2FJFFnVrU
C3HT1EkHltchSPPhmOFIPlPOgnhUXW4MWnkby8DrjzVNc6XU5nCkjKqplWscLVsI
/Bn/kyhsLrOF+BxFU6DxkHabzmfokvv/XZ/A39xw9tlJQsWy8+9ytGZZYgwZEz33
O2g71PUtwlZxx1ogRibf4YdEzeBOxLhafrn/KCXH7/0cELaj82gt0x8jstInXkFS
bIgkvQD3mjFtCO3OgzvtxGf/LhmZ+kpHfOelA7vEgFHUC5trRJbubR6ZIGo3WwZF
T8BXlXGgRZSBA1hl1YSoX/MdUmslwdEDY3ZOCYdRVlnpaXyeLClCFjKZdrTlFD67
gB4TRnNU4d3AJgjJLcPO3SIkcW3+ejP7uwbv3dt7QA7qkfO/I8Tnk59FixKHowl4
OEzUxZxheWh8TzRyXWUxIwo5e8/5mGttxUqrps3sss/Ne/8GgMK7+xXKFvioq8oB
1IqJC5/uDCfEmOrKJONp+8GZWStUinw3nMNcbIQppKF7Z6n8k2ASrhOfpwaT0QCo
RjAYKmw=
END CERTIFICATE-----
1 s:C = DE, ST = Hessen, L = Frankfurt, O = syncgw.com, OU = Cybertrust, CN = Syncgw CyberTrust Root
i:C = DE, ST = Hessen, L = Frankfurt, O = syncgw.com, OU = Cybertrust, CN = Syncgw CyberTrust Root
BEGIN CERTIFICATE-----
MIIF+jCCA+KgAwIBAgIUHcdr321V63+5Qfw4cUg4X5IkHxkwDQYJKoZIhvcNAQEN
BQAwfTELMAkGA1UEBhMCREUxDzANBgNVBAgMBkhlc3NlbjESMBAGA1UEBwwJRnJh
bmtmdXJ0MRMwEQYDVQQKDApzeW5jZ3cuY29tMRMwEQYDVQQLDApDeWJlcnRydXN0
MR8wHQYDVQQDDBZTeW5jZ3cgQ3liZXJUcnVzdCBSb290MB4XDTIyMDYwNjEwMzUy
NloXDTMyMDYwMzEwMzUyNlowfTELMAkGA1UEBhMCREUxDzANBgNVBAgMBkhlc3Nl
bjESMBAGA1UEBwwJRnJhbmtmdXJ0MRMwEQYDVQQKDApzeW5jZ3cuY29tMRMwEQYD
VQQLDApDeWJlcnRydXN0MR8wHQYDVQQDDBZTeW5jZ3cgQ3liZXJUcnVzdCBSb290
MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA2tKX7aFLbUhKEd1NY8eh
rCeH9HFWQyxtW2JaVsczkA68++r4mhnED/WXe3haSJPC3B05eClApg4ikneYTtqg
UJJtVUTTeAUSruVtsa84gj/WJKdS+Po+CROLvUtmhV97Q3CuVC9X4vxvG4W/ALvO
H0IJJ01As/ENyn/ChVuOH46uU5tH1p75/YYfmPXoGnWsr49kOU5vNHRhqLuyl7qH
PWmTbpKGztiTRc3qf0QNBIYuhldo9bXqVWOg2UOb4V35mLTgFMGRDbyVVR7qJNJp
DCmXjeiGvC6GIg/zXBUe7qDvehBeMkwyqIhBX1nRNFFGDnaJHgvp/ikPzI6QkhCF
gkyrxk9xuHx7n3oRlxdTS2DZAjVp9uCBIL4MpNjz7andIJUEwXLW4voEXwQPJH/u
waGS4+JMDMcliur5APXePz7wFSwkhBV6SMaEVmuhz+4LODDPn6pd1CdA0M6TSFCM
Q1qY+VzUL9ZqmBmh0pv9IofbpVtQZyTMxXqqRyJI5VeLCN1zhnHDg+frDD/cIGfk
kbaHHTIvp/Ws8Nt+UK+lOgG8TBAujHwUTLju4MQz+3FUl52pUAiB/aTMR3FfmrJk
wPEVadCtHl3v+NMXgrmkU/CuS+WFxbM5cv4vuQBggbNR6C6yUR6DJVA5V/VeDAOV
CkKl6O9hMIxOifndnlzc3U8CAwEAAaNyMHAwHQYDVR0OBBYEFHAAleKO5J9deb6g
2+1NUFVdXnKgMB8GA1UdIwQYMBaAFHAAleKO5J9deb6g2+1NUFVdXnKgMA8GA1Ud
EwEB/wQFMAMBAf8wHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMA0GCSqG
SIb3DQEBDQUAA4ICAQBCFPYWGsPqAKRbZJAw1h+bnmsef0TzT4pO4BYnnkpELRMS
jFxMfi3g+6opc5ED3hdVkC4X8wJ31MoSPvv1HEX/47YDvUb6Hj4SYBUAtsb1blQg
QOwKphV7w2Ob8zlzT1Up+IiOAXEMEZ8PLoyPw4dvdQxYD4cgsB2bd+5RWxYDlSam
z/1VbCC61Zy2JexITPpEyDkmJjFxRqdQNtUHHVCi14QjmqwA6CocZgC0bEu9bUXN
XRXqbmw9xv0SSV76vjk1jUMM/HUBVdM5hHT9Ks79gOJIfGWjmlil5RHi4i9IFZEp
PAmnk5gxSuRkysWfv9eTFol/YC6Gorvkvyboniir425oUsKkFLjTB5lgC8chAHWV
VsArO7wbXL4Nx7rLlbtf3prbnwQ+B2sHYQeai09OhEc56FN7OoNavFppnCAHGOlj
wI7GZ5AKFlU8bwuWL8XpMEsjmWDe+KKNOLd6EEfR8Jc6I62grZkVeF6/JYrXyDwG
k1SdmX3tdqvBlydMoHqsaTXgcD3s9C1q/yXJFKR81j3hZ8gluLfgFsMerroV7lXe
H1PJELAvtAKz8noHWgzkDPV1OmZVfcQtqhSBaprS30Oz39eEs8Heepn+3yjA7bkP
XrwYJedR93IiWeVc2nvKLn0FfFw0dc5Q48v5DOeBMQCaW63iSmqgzuEyRTXzHQ==
END CERTIFICATE-----
---
Server certificate
subject=C = DE, ST = Hessen, L = Frankfurt, O = syncgw.com, OU = Cybertrust, CN = dev.fd
issuer=C = DE, ST = Hessen, L = Frankfurt, O = syncgw.com, OU = Cybertrust, CN = Syncgw CyberTrust Root
---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: RSA-PSS
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 3752 bytes and written 378 bytes
Verification: OK
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Server public key is 4096 bit
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)
---
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : TLS_AES_256_GCM_SHA384
Session-ID: 00D34E49472E80485284B56C9B218665FFAC8226ADD6DAAB2AC53D0E8E88BD45
Session-ID-ctx:
Resumption PSK: 8C1604A0D76C3E47BF754E49A0CE9D29FEE363CAAF2594A1D4419C65FA2B96161735EDB309F86E6B7BD5492DB8C544C7
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 300 (seconds)
TLS session ticket:
0000 - fc b7 7b 35 8f 90 d9 e1-04 b0 56 df fe 01 a8 8b ..{5......V.....
0010 - a9 b9 7b 21 4e a2 9e 48-99 15 ad 91 1a 31 7a 70 ..{!N..H.....1zp
0020 - 59 c1 e1 af 2c 89 ea fd-1c 16 af 19 e4 2f 89 61 Y...,......../.a
0030 - 70 d3 e5 e3 81 14 b4 02-39 43 dc 0e c2 54 21 56 p.......9C...T!V
0040 - 62 04 0c 59 ce d8 61 72-b5 fb b6 9d c5 29 1e 47 b..Y..ar.....).G
0050 - f4 15 27 e3 0a 74 de 8a-68 23 71 4b 75 08 e7 e6 ..'..t..h#qKu...
0060 - d6 c3 ad a4 5f 52 da 69-2e 87 d9 3a e6 ea 08 4f ...._R.i...:...O
0070 - bc b6 f5 a5 64 47 d3 21-57 bb 8f 76 2d d0 72 09 ....dG.!W..v-.r.
0080 - 89 31 de 95 13 e5 f9 02-26 d8 a2 69 37 83 9c 6e .1......&..i7..n
0090 - f3 c4 a1 05 0a 65 05 4e-cd 5f 5f 55 e2 1c 6e f4 .....e.N.__U..n.
00a0 - b4 ef 1a c4 df 4d 45 d7-2d af 4b c5 f1 c0 04 9f .....ME.-.K.....
00b0 - 7b 07 0a e7 84 cb 66 e1-80 ea aa a6 21 65 da b5 {.....f.....!e..
00c0 - 51 d5 54 f9 50 55 ca de-54 74 c6 c0 52 a9 9b be Q.T.PU..Tt..R...
00d0 - da bf c9 27 c6 64 d0 f9-da 52 df ea ee 99 8c 63 ...'.d...R.....c
00e0 - f6 1c 43 f1 e2 c4 e0 d7-77 fe 51 82 20 e9 29 62 ..C.....w.Q. .)b
Start Time: 1654519569
Timeout : 7200 (sec)
Verify return code: 0 (ok)
Extended master secret: no
Max Early Data: 0
---
read R BLOCK
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : TLS_AES_256_GCM_SHA384
Session-ID: F65E2ECB27B70555857D4625B6A9B2916C9E219D9399C5D7DDD5AF520FBC98C1
Session-ID-ctx:
Resumption PSK: DD83A1DB73E4407301EBC77C937553868937008999712C04B1865930B22DE9BFB67511B1BF1198D0B16210C655049F0A
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 300 (seconds)
TLS session ticket:
0000 - fc b7 7b 35 8f 90 d9 e1-04 b0 56 df fe 01 a8 8b ..{5......V.....
0010 - 92 6b e5 d9 c3 0d ba ea-fb 73 66 50 2b b8 2d 8e .k.......sfP+.-.
0020 - 49 6e 18 8e ce e6 9a 82-ba a1 d0 75 83 57 09 30 In.........u.W.0
0030 - 67 da 73 bc f0 1e fd 46-2e ac 95 e6 d6 88 7e e2 g.s....F......~.
0040 - 2e 0f 9e 53 59 46 0c 2f-d3 05 8b b2 47 d4 44 c8 ...SYF./....G.D.
0050 - 09 05 57 16 d7 3e 36 02-66 84 55 1d 08 37 45 ff ..W..>6.f.U..7E.
0060 - a5 ff f7 69 2f c2 36 b6-e3 8b 80 13 06 72 10 43 ...i/.6......r.C
0070 - ab 8b a1 13 ce ea 7a a5-21 5c 41 f3 f5 38 58 ee ......z.!\A..8X.
0080 - 13 c5 ca b9 71 93 81 cb-ae 7e c2 27 a1 ae 61 43 ....q....~.'..aC
0090 - e5 db 70 d9 13 b0 3c 4e-57 27 60 45 2c 7c e7 b7 ..p...<NW'`E,|..
00a0 - 9e 70 97 de a2 9a 57 47-60 7c 1f 78 3d 2e 80 3c .p....WG`|.x=..<
00b0 - 51 3b 6c a5 c7 39 bc 12-e9 93 f1 3c be 2e 43 ed Q;l..9.....<..C.
00c0 - 45 6a 05 dc 50 aa fe 3b-86 89 6b 7d a9 13 b3 c4 Ej..P..;..k}....
00d0 - fb 7e 84 14 d6 11 d3 06-46 72 9f 62 c9 1e fb d4 .~......Fr.b....
00e0 - 1d 96 b5 3f 70 93 34 95-c4 65 2b df ee bb 73 d3 ...?p.4..e+...s.
</pre>
Start Time: 1654519569
Timeout : 7200 (sec)
Verify return code: 0 (ok)
Extended master secret: no
Max Early Data: 0
---
read R BLOCK
DONE
But, If I enter https://dev.fd as URL, I get SSL_ERROR_BAD_CERT_DOMAIN. I tried both
1. local-settings.js -> about:config -> security.enterprise_roots.enabled = true
2. Import of CA certificate in settings
Any suggestions how to solve?