SSL wildcard certificate does not match - How to trust ?

For questions and discussion that is NOT (I repeat NOT) specific to a certain Operating System.
chownes
New Cone
New Cone
Posts: 5
Joined: 25 Aug 2010 11:37

SSL wildcard certificate does not match - How to trust ?

Postby chownes » 25 Aug 2010 11:49

Hello,

I am wondering how to trust a certificate manually in VLC.
My purpose is to open a stream over https. The common name of the certificate sent by the remote site is

Code: Select all

*.example.com
which does not match

Code: Select all

foo.bar.example.com
So I would like to tell VLC that this certificate can be trusted. This can be done easily in Firefox for instance (it offers to add a security exception). How do you do it in VLC ?

--

Rémi Denis-Courmont
Developer
Developer
Posts: 15323
Joined: 07 Jun 2004 16:01
VLC version: master
Operating System: Linux
Contact:

Re: SSL wildcard certificate does not match - How to trust ?

Postby Rémi Denis-Courmont » 27 Aug 2010 04:31

You can't. You need to add the root CA to the CA list.
Rémi Denis-Courmont
https://www.remlab.net/
Private messages soliciting support will be systematically discarded

chownes
New Cone
New Cone
Posts: 5
Joined: 25 Aug 2010 11:37

Re: SSL wildcard certificate does not match - How to trust ?

Postby chownes » 27 Aug 2010 15:13

The necessary arrangements with a Root CA file have been made (with the Stream Output preference and a file in PEM format).

The problem lies with the wildcard mechanism for the last certificate in the chain.
Last edited by chownes on 28 Aug 2010 18:21, edited 1 time in total.

Rémi Denis-Courmont
Developer
Developer
Posts: 15323
Joined: 07 Jun 2004 16:01
VLC version: master
Operating System: Linux
Contact:

Re: SSL wildcard certificate does not match - How to trust ?

Postby Rémi Denis-Courmont » 28 Aug 2010 03:14

Matching names is done inside libgnutls. VLC is not involved there.
Rémi Denis-Courmont
https://www.remlab.net/
Private messages soliciting support will be systematically discarded

chownes
New Cone
New Cone
Posts: 5
Joined: 25 Aug 2010 11:37

Re: SSL wildcard certificate does not match - How to trust ?

Postby chownes » 29 Aug 2010 23:18

I posted to the gnutls mailing list, here is a reply to my post:

http://article.gmane.org/gmane.network. ... neral/2111

Is there already a way to tell VLC not to check the name on the certificate, or is there a need to modify VLC ?

Rémi Denis-Courmont
Developer
Developer
Posts: 15323
Joined: 07 Jun 2004 16:01
VLC version: master
Operating System: Linux
Contact:

Re: SSL wildcard certificate does not match - How to trust ?

Postby Rémi Denis-Courmont » 30 Aug 2010 01:11

No and yes.
Rémi Denis-Courmont
https://www.remlab.net/
Private messages soliciting support will be systematically discarded


Return to “General VLC media player Troubleshooting”

Who is online

Users browsing this forum: No registered users and 71 guests