-
Notifications
You must be signed in to change notification settings - Fork 18k
cmd/go: cannot get anything from a private repository, x509: certificate signed by unknown authority on OS X #29059
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
go get
can't get anything from a private repository, x509: certificate signed by unknown authority
go get
can't get anything from a private repository, x509: certificate signed by unknown authority
Thank you for filing this issue @cvigo! Kindly paging @FiloSottile @bcmills |
Worth to mention that the key issue is not |
@FiloSottile, any insight as to what we might be missing to make the |
@cvigo Did you have to install this CA? I don't have it in my keychain on 10.14.1. If so, the problem might be #24652 / #24652 (comment) |
sure, it is a private CA |
Can you run the test linked in that comment to check if Go picks up the cert? |
The test fails... Suprisingly I have another Root CA for test environments that returns different results ( Test Resultscrypto/x509: verify-cert approved CN=Apple Worldwide Developer Relations Certification Authority,OU=Apple Worldwide Developer Relations,O=Apple Inc.,C=US crypto/x509: verify-cert rejected CN=com.apple.systemdefault,O=System Identity: "Cert Verify Result: CSSMERR_TP_NOT_TRUSTED" crypto/x509: verify-cert rejected CN=com.apple.kerberos.kdc,O=System Identity: "Cert Verify Result: CSSMERR_TP_NOT_TRUSTED" crypto/x509: verify-cert approved CN=AutoFirma ROOT crypto/x509: verify-cert approved CN=127.0.0.1 crypto/x509: verify-cert approved CN=BBVA Autoridad de Certificacion Digital,O=Banco Bilbao Vizcaya Argentaria crypto/x509: verify-cert approved CN=BBVA CA Servidores,O=BBVA crypto/x509: verify-cert approved CN=BBVA CA Raiz,O=BBVA crypto/x509: verify-cert approved CN=BBVA Servidores Autoridad de Certificacion Digital,OU=Para Uso Interno BBVA,O=Banco Bilbao Vizcaya Argentaria crypto/x509: verify-cert approved CN=Global Root CA,OU=Security Architecture Cryptography,O=BBVA,C=ES crypto/x509: verify-cert approved CN=Global Root CA Work,OU=Security Architecture Cryptography,O=BBVA,C=ES crypto/x509: verify-cert approved CN=DigiCert Global Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US crypto/x509: verify-cert approved CN=DigiCert SHA2 Secure Server CA,O=DigiCert Inc,C=US crypto/x509: verify-cert approved CN=wifiaccess.grupobbva.com,OU=Comunicaciones,O=BBVA,L=Bilbao,C=ES crypto/x509: verify-cert rejected CN=vpnaas_live.es.nextgen.igrupobbva,OU=Architecture Security,O=BBVA,L=Madrid,ST=Madrid,C=ES: "Cert Verify Result: Invalid Extended Key Usage for policy" crypto/x509: verify-cert approved CN=vpnaas_live.es.nextgen.igrupobbva,OU=Security Architecture,O=BBVA,L=Madrid,ST=Madrid,C=ES crypto/x509: verify-cert approved CN=vpnaas.es.nextgen.igrupobbva,OU=Security Architecture,O=BBVA,L=Madrid,ST=Madrid,C=ES crypto/x509: verify-cert approved CN=isepsncorpeditc2.igrupobbva,O=BBVA,L=Madrid,ST=Madrid,C=ES crypto/x509: verify-cert approved CN=link.live.es.platform.bbva.com,OU=SECURITY,O=BBVA,L=MADRID,ST=MADRID,C=ES crypto/x509: verify-cert rejected CN=armadillo.smlb.secaas-live-es.ext.es.iaas.igrupobbva,OU=Dyd,O=BBVA,L=Madrid,ST=Madrid,C=ES: "Cert Verify Result: CSSMERR_TP_NOT_TRUSTED" crypto/x509: verify-cert approved CN=Developer ID Certification Authority,OU=Apple Certification Authority,O=Apple Inc.,C=US crypto/x509: verify-cert approved CN=Apple Worldwide Developer Relations Certification Authority,OU=Apple Worldwide Developer Relations,O=Apple Inc.,C=US crypto/x509: verify-cert approved CN=Developer Authentication Certification Authority,OU=Apple Worldwide Developer Relations,O=Apple Inc.,C=US crypto/x509: verify-cert rejected CN=Adobe Content Certificate 10-6,OU=Cloud Technology,O=Adobe Systems,L=San Jose,ST=California,C=US: "Cert Verify Result: CSSMERR_TP_NOT_TRUSTED" crypto/x509: verify-cert rejected CN=Adobe Intermediate CA 10-4,OU=Cloud Technology,O=Adobe Systems,L=San Jose,ST=California,C=US: "Cert Verify Result: CSSMERR_TP_NOT_TRUSTED" crypto/x509: verify-cert rejected CN=Adobe Intermediate CA 10-3,OU=Cloud Technology,O=Adobe Systems,L=San Jose,ST=California,C=US: "Cert Verify Result: CSSMERR_TP_NOT_TRUSTED" crypto/x509: verify-cert rejected CN=Adobe Content Certificate 10-5,OU=Cloud Technology,O=Adobe Systems,L=San Jose,ST=California,C=US: "Cert Verify Result: CSSMERR_TP_NOT_TRUSTED" crypto/x509: verify-cert rejected CN=Xcode Server Builder (05/11/2018\, 09:57:44): "Cert Verify Result: Invalid Extended Key Usage for policy" crypto/x509: verify-cert rejected SERIALNUMBER=IDCES-87654321K,CN=NAME REMOVED FOR PRIVACY - 87654321K,C=ES: "Cert Verify Result: Invalid Extended Key Usage for policy" crypto/x509: verify-cert rejected SERIALNUMBER=IDCES-12345678K,CN=NAME REMOVED FOR PRIVACY - 12345678K,C=ES: "Cert Verify Result: Invalid Extended Key Usage for policy" crypto/x509: verify-cert approved CN=DigiCert Global Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US crypto/x509: verify-cert approved CN=Ether R3 ES Issuing CA Work,OU=Security Architecture Cryptography,O=BBVA,C=ES crypto/x509: verify-cert approved CN=DigiCert SHA2 Secure Server CA,O=DigiCert Inc,C=US crypto/x509: verify-cert approved CN=wifiaccess.grupobbva.com,OU=Comunicaciones,O=BBVA,L=Bilbao,C=ES crypto/x509: verify-cert rejected CN=vpnaas_live.es.nextgen.igrupobbva,OU=Architecture Security,O=BBVA,L=Madrid,ST=Madrid,C=ES: "Cert Verify Result: Invalid Extended Key Usage for policy" crypto/x509: verify-cert approved CN=vpnaas_live.es.nextgen.igrupobbva,OU=Security Architecture,O=BBVA,L=Madrid,ST=Madrid,C=ES crypto/x509: verify-cert approved CN=vpnaas.es.nextgen.igrupobbva,OU=Security Architecture,O=BBVA,L=Madrid,ST=Madrid,C=ES crypto/x509: verify-cert approved CN=isepsncorpeditc2.igrupobbva,O=BBVA,L=Madrid,ST=Madrid,C=ES crypto/x509: verify-cert approved CN=link.live.es.platform.bbva.com,OU=SECURITY,O=BBVA,L=MADRID,ST=MADRID,C=ES crypto/x509: verify-cert approved CN=Apple Worldwide Developer Relations Certification Authority,OU=Apple Worldwide Developer Relations,O=Apple Inc.,C=US crypto/x509: verify-cert rejected CN=armadillo.smlb.secaas-live-es.ext.es.iaas.igrupobbva,OU=Dyd,O=BBVA,L=Madrid,ST=Madrid,C=ES: "Cert Verify Result: CSSMERR_TP_NOT_TRUSTED" crypto/x509: verify-cert approved CN=Developer ID Certification Authority,OU=Apple Certification Authority,O=Apple Inc.,C=US crypto/x509: verify-cert approved CN=Developer Authentication Certification Authority,OU=Apple Worldwide Developer Relations,O=Apple Inc.,C=US crypto/x509: verify-cert rejected CN=Adobe Content Certificate 10-6,OU=Cloud Technology,O=Adobe Systems,L=San Jose,ST=California,C=US: "Cert Verify Result: CSSMERR_TP_NOT_TRUSTED" crypto/x509: verify-cert rejected CN=Adobe Intermediate CA 10-4,OU=Cloud Technology,O=Adobe Systems,L=San Jose,ST=California,C=US: "Cert Verify Result: CSSMERR_TP_NOT_TRUSTED" crypto/x509: verify-cert rejected CN=Adobe Content Certificate 10-5,OU=Cloud Technology,O=Adobe Systems,L=San Jose,ST=California,C=US: "Cert Verify Result: CSSMERR_TP_NOT_TRUSTED" crypto/x509: verify-cert rejected CN=Adobe Intermediate CA 10-3,OU=Cloud Technology,O=Adobe Systems,L=San Jose,ST=California,C=US: "Cert Verify Result: CSSMERR_TP_NOT_TRUSTED" crypto/x509: verify-cert rejected CN=Xcode Server Builder (05/11/2018\, 09:57:44): "Cert Verify Result: Invalid Extended Key Usage for policy" crypto/x509: verify-cert rejected SERIALNUMBER=IDCES-87654321K,CN=NAME REMOVED FOR PRIVACY - 87654321K,C=ES: "Cert Verify Result: Invalid Extended Key Usage for policy" crypto/x509: verify-cert rejected SERIALNUMBER=IDCES-12345678K,CN=NAME REMOVED FOR PRIVACY - 12345678K,C=ES: "Cert Verify Result: Invalid Extended Key Usage for policy" crypto/x509: verify-cert approved CN=Ether R3 ES Issuing CA Work,OU=Security Architecture Cryptography,O=BBVA,C=ES crypto/x509: ran security verify-cert 51 times cgo sys roots: 366.462356ms non-cgo sys roots: 671.314532ms signed certificate only present in non-cgo pool (acceptable): CN=Apple Worldwide Developer Relations Certification Authority,OU=Apple Worldwide Developer Relations,O=Apple Inc.,C=US signed certificate only present in non-cgo pool (acceptable): CN=DigiCert SHA2 Secure Server CA,O=DigiCert Inc,C=US signed certificate only present in non-cgo pool (acceptable): CN=wifiaccess.grupobbva.com,OU=Comunicaciones,O=BBVA,L=Bilbao,C=ES signed certificate only present in non-cgo pool (acceptable): CN=vpnaas_live.es.nextgen.igrupobbva,OU=Security Architecture,O=BBVA,L=Madrid,ST=Madrid,C=ES signed certificate only present in non-cgo pool (acceptable): CN=isepsncorpeditc2.igrupobbva,O=BBVA,L=Madrid,ST=Madrid,C=ES signed certificate only present in non-cgo pool (acceptable): CN=Developer ID Certification Authority,OU=Apple Certification Authority,O=Apple Inc.,C=US signed certificate only present in non-cgo pool (acceptable): CN=Developer Authentication Certification Authority,OU=Apple Worldwide Developer Relations,O=Apple Inc.,C=US signed certificate only present in non-cgo pool (acceptable): CN=Ether R3 ES Issuing CA Work,OU=Security Architecture Cryptography,O=BBVA,C=ES certificate only present in cgo pool: SERIALNUMBER=IDCES-87654321K,CN=NAME REMOVED FOR PRIVACY - 87654321K,C=ES certificate only present in cgo pool: CN=Xcode Server Builder (05/11/2018\, 09:57:44) certificate only present in cgo pool: CN=armadillo.smlb.secaas-live-es.ext.es.iaas.igrupobbva,OU=Dyd,O=BBVA,L=Madrid,ST=Madrid,C=ES certificate only present in cgo pool: SERIALNUMBER=IDCES-12345678K,CN=NAME REMOVED FOR PRIVACY - 12345678K,C=ES Number of trusted certs = 11 Cert 0: wifiaccess.grupobbva.com Number of trust settings : 2 Trust Setting 0: Policy OID : EAP Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 1: Policy OID : Apple X509 Basic Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Cert 1: vpnaas.es.nextgen.igrupobbva Number of trust settings : 10 Trust Setting 0: Policy OID : SSL Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 1: Policy OID : SSL Allowed Error : Host name mismatch Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 2: Policy OID : SMIME Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 3: Policy OID : SMIME Allowed Error : S/MIME Email address mismatch Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 4: Policy OID : EAP Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 5: Policy OID : IPSec Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 6: Policy OID : Code Signing Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 7: Policy OID : Unknown OID length 9, value { 2A 86 48 86 F7 63 64 01 14 } Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 8: Policy OID : Apple X509 Basic Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 9: Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Cert 2: isepsncorpeditc2.igrupobbva Number of trust settings : 2 Trust Setting 0: Policy OID : EAP Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 1: Policy OID : Apple X509 Basic Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Cert 3: link.live.es.platform.bbva.com Number of trust settings : 3 Trust Setting 0: Policy OID : SSL Policy String : 185.24.6.15 Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 1: Policy OID : SSL Policy String : 185.24.6.15 Allowed Error : Host name mismatch Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 2: Policy OID : Apple X509 Basic Policy String : 185.24.6.15 Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Cert 4: armadillo.smlb.secaas-live-es.ext.es.iaas.igrupobbva Number of trust settings : 2 Trust Setting 0: Policy OID : SSL Policy String : atenea.live.global.ether.igrupobbva Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 1: Policy OID : SSL Policy String : atenea.live.global.ether.igrupobbva Allowed Error : Host name mismatch Result Type : kSecTrustSettingsResultTrustRoot Cert 5: Xcode Server Builder (05/11/2018, 09:57:44) Number of trust settings : 9 Trust Setting 0: Policy OID : SSL Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 1: Policy OID : SSL Allowed Error : Host name mismatch Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 2: Policy OID : SMIME Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 3: Policy OID : SMIME Allowed Error : S/MIME Email address mismatch Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 4: Policy OID : EAP Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 5: Policy OID : IPSec Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 6: Policy OID : Code Signing Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 7: Policy OID : Unknown OID length 9, value { 2A 86 48 86 F7 63 64 01 14 } Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 8: Policy OID : Apple X509 Basic Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Cert 6: NAME REMOVED FOR PRIVACY - 87654321K Number of trust settings : 9 Trust Setting 0: Policy OID : SSL Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 1: Policy OID : SSL Allowed Error : Host name mismatch Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 2: Policy OID : SMIME Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 3: Policy OID : SMIME Allowed Error : S/MIME Email address mismatch Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 4: Policy OID : EAP Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 5: Policy OID : IPSec Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 6: Policy OID : Code Signing Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 7: Policy OID : Unknown OID length 9, value { 2A 86 48 86 F7 63 64 01 14 } Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 8: Policy OID : Apple X509 Basic Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Cert 7: NAME REMOVED FOR PRIVACY - 12345678K Number of trust settings : 9 Trust Setting 0: Policy OID : SSL Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 1: Policy OID : SSL Allowed Error : Host name mismatch Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 2: Policy OID : SMIME Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 3: Policy OID : SMIME Allowed Error : S/MIME Email address mismatch Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 4: Policy OID : EAP Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 5: Policy OID : IPSec Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 6: Policy OID : Code Signing Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 7: Policy OID : Unknown OID length 9, value { 2A 86 48 86 F7 63 64 01 14 } Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 8: Policy OID : Apple X509 Basic Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Cert 8: BBVA Autoridad de Certificacion Digital Number of trust settings : 10 Trust Setting 0: Policy OID : SSL Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 1: Policy OID : SSL Allowed Error : Host name mismatch Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 2: Policy OID : SMIME Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 3: Policy OID : SMIME Allowed Error : S/MIME Email address mismatch Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 4: Policy OID : EAP Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 5: Policy OID : IPSec Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 6: Policy OID : Code Signing Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 7: Policy OID : Unknown OID length 9, value { 2A 86 48 86 F7 63 64 01 14 } Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 8: Policy OID : Apple X509 Basic Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 9: Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Cert 9: BBVA CA Raiz Number of trust settings : 10 Trust Setting 0: Policy OID : SSL Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 1: Policy OID : SSL Allowed Error : Host name mismatch Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 2: Policy OID : SMIME Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 3: Policy OID : SMIME Allowed Error : S/MIME Email address mismatch Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 4: Policy OID : EAP Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 5: Policy OID : IPSec Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 6: Policy OID : Code Signing Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 7: Policy OID : Unknown OID length 9, value { 2A 86 48 86 F7 63 64 01 14 } Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 8: Policy OID : Apple X509 Basic Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 9: Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Cert 10: Global Root CA Work Number of trust settings : 10 Trust Setting 0: Policy OID : SSL Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 1: Policy OID : SSL Allowed Error : Host name mismatch Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 2: Policy OID : SMIME Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 3: Policy OID : SMIME Allowed Error : S/MIME Email address mismatch Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 4: Policy OID : EAP Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 5: Policy OID : IPSec Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 6: Policy OID : Code Signing Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 7: Policy OID : Unknown OID length 9, value { 2A 86 48 86 F7 63 64 01 14 } Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 8: Policy OID : Apple X509 Basic Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 9: Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Number of trusted certs = 5 Cert 0: AutoFirma ROOT Number of trust settings : 10 Trust Setting 0: Policy OID : SSL Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 1: Policy OID : SSL Allowed Error : Host name mismatch Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 2: Policy OID : SMIME Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 3: Policy OID : SMIME Allowed Error : S/MIME Email address mismatch Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 4: Policy OID : EAP Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 5: Policy OID : IPSec Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 6: Policy OID : Code Signing Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 7: Policy OID : Unknown OID length 9, value { 2A 86 48 86 F7 63 64 01 14 } Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 8: Policy OID : Apple X509 Basic Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Trust Setting 9: Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustRoot Cert 1: 127.0.0.1 Number of trust settings : 9 Trust Setting 0: Policy OID : SSL Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 1: Policy OID : SSL Allowed Error : Host name mismatch Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 2: Policy OID : SMIME Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 3: Policy OID : SMIME Allowed Error : S/MIME Email address mismatch Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 4: Policy OID : EAP Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 5: Policy OID : IPSec Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 6: Policy OID : Code Signing Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 7: Policy OID : Unknown OID length 9, value { 2A 86 48 86 F7 63 64 01 14 } Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 8: Policy OID : Apple X509 Basic Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Cert 2: BBVA CA Servidores Number of trust settings : 10 Trust Setting 0: Policy OID : SSL Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 1: Policy OID : SSL Allowed Error : Host name mismatch Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 2: Policy OID : SMIME Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 3: Policy OID : SMIME Allowed Error : S/MIME Email address mismatch Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 4: Policy OID : EAP Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 5: Policy OID : IPSec Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 6: Policy OID : Code Signing Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 7: Policy OID : Unknown OID length 9, value { 2A 86 48 86 F7 63 64 01 14 } Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 8: Policy OID : Apple X509 Basic Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 9: Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Cert 3: BBVA Servidores Autoridad de Certificacion Digital Number of trust settings : 10 Trust Setting 0: Policy OID : SSL Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 1: Policy OID : SSL Allowed Error : Host name mismatch Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 2: Policy OID : SMIME Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 3: Policy OID : SMIME Allowed Error : S/MIME Email address mismatch Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 4: Policy OID : EAP Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 5: Policy OID : IPSec Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 6: Policy OID : Code Signing Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 7: Policy OID : Unknown OID length 9, value { 2A 86 48 86 F7 63 64 01 14 } Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 8: Policy OID : Apple X509 Basic Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Trust Setting 9: Allowed Error : CSSMERR_TP_CERT_EXPIRED Result Type : kSecTrustSettingsResultTrustAsRoot Cert 4: Global Root CA Number of trust settings : 0 |
This is definitely #24652, and judging from your output it will get fixed by the outstanding CLs, because "Global Root CA" is not one of the failing roots anymore. Closing as dup, but I might ping you from the other issue to make sure the final code passes for you. |
Same error with go 1.11.3 😠 |
git clone https://github.com/XXXX/TTT.git $GOPATH/src/XXXX/TTT |
What version of Go are you using (
go version
)?Does this issue reproduce with the latest release?
Yes
What operating system and processor architecture are you using (
go env
)?go env
What did you do?
go get -u scm.live.es.nextgen.igrupobbva/connectors/titan_core_protobuf
What did you expect to see?
The pkg installed
What did you see instead?
go: scm.live.es.nextgen.igrupobbva/connectors/titan_core_protobuf@v2.0.0+incompatible: unrecognized import path "scm.live.es.nextgen.igrupobbva/connectors/titan_core_protobuf" (https fetch: Get https://scm.live.es.nextgen.igrupobbva/connectors/titan_core_protobuf?go-get=1: x509: certificate signed by unknown authority) go: error loading module requirements
The server cert is signed by a private CA, but it is marked as trusted system-wide
More info:
curl -v https://scm.live.es.nextgen.igrupobbva/connectors/titan_core_protobuf
The URL can be reached only through VPN
Team mates using Linux don't have this issue.
go get -insecure
worksThe text was updated successfully, but these errors were encountered: