maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   MeeGo / Harmattan (https://talk.maemo.org/forumdisplay.php?f=45)
-   -   Restoring original CA certs without reflashing - possible? (https://talk.maemo.org/showthread.php?t=101315)

dredlok706 2022-03-09 15:31

Restoring original CA certs without reflashing - possible?
 
Hi there!
I messed up something with CA certs (aegis-certman-common-ca package). I installed latest it from Halftux:
https://talk.maemo.org/showpost.php?...9&postcount=94
I used aegis-certman-common-ca_1.0.8+0m9_all.deb file. It removed some certs, added some, ok
Homever, it broke dependencies. mp-harmattan-342 was ready to remove while used apt-get install -f!!! It said m8 version of aegis-certman-common-ca needed. So, I downloaded aegis-certman-common-ca_1.0.8+0m8_all.deb from Halftux and replaced by aegis-dpkg. It worked, but still most sites give certs errors, also certs are strange, one from 4737 year or something, just completely strange.
I tried to resurrect it. I installed original aegis-certman-common-ca from n9mirror. It hasn't helped :/ Strange, new certs are still alongside with old one.
Now my question in thread. Possible to completely restore old state? I don't have access to /etc/ssl/certs via terminal, so I can't copy content from other working N9 here.
Any other advice? Thanks in advance :)

ric9K 2022-03-09 17:35

Re: Restoring original CA certs without reflashing - possible?
 
Quote:

Originally Posted by dredlok706 (Post 1573751)
...I don't have access to /etc/ssl/certs via terminal...

Do you know why you don't have access?

dredlok706 2022-03-09 17:49

Re: Restoring original CA certs without reflashing - possible?
 
I can't e.g. copy any cert to /etc/ssl/certs.
Via devel-su, develsh, opensudo, opensh.
All give Permission denied

ric9K 2022-03-09 21:11

Re: Restoring original CA certs without reflashing - possible?
 
?
What device/os is it about? Maemo?

Use the search engine before asking, this will preserve people's time to do more useful things than repeating and it will preserve you from frustration if none answers.

E.g. "root acces"

dredlok706 2022-03-10 05:56

Re: Restoring original CA certs without reflashing - possible?
 
a) The topic is in MeeGo Harmattan section, so Nokia N9
b) Root access - I know what it is. Did you read my post - I wrote I tried to execute that command via devel-su, develsh, opensh and opensudo. All are different root shells. But it hasn't worked on any :/
c) I already searched on forum and Google but haven't found any advice.
I know I could reflash, but don't want to lose my configs etc. :)
What is strange, when I type in Terminal "ls /etc/ssl/certs" - I see many pem files.
When I connect N9 to PC in Ubiboot mode to export all partitions - in N9 rootfs/etc/ssl/certs I don't see anything :O

ric9K 2022-03-10 15:40

Re: Restoring original CA certs without reflashing - possible?
 
Oh, sorry, just skipped to see MeeGo / Harmattan.
Unknown to me.
So I close it :o

dredlok706 2022-03-10 18:28

Re: Restoring original CA certs without reflashing - possible?
 
I'm thinking about trying ariadne shell. Can that help?
Regards, WW

Halftux 2022-03-11 18:37

Re: Restoring original CA certs without reflashing - possible?
 
I am sorry that it is not working for you. The deb is also nowadays old and I guess some new certificates are missing.
I would suggest to follow the manual approach you could find links in this post I made:

https://talk.maemo.org/showpost.php?...7&postcount=89

Otherwise you need to create a deb package there you can specify to remove unwanted certs and only install which you need.

Or make a list with certificates you would like to delete and upload all certificates which you would like to install. I could make then a deb out of it.

dredlok706 2022-03-11 19:03

Re: Restoring original CA certs without reflashing - possible?
 
Ok, so:
https://talk.maemo.org/showpost.php?...67&postcount=4
I need to know sha1sums of all certs. I need to delete them via that method :up:
If I remove ALL certs (yours and original), will installing original aegis-certman-common-ca restore original CA?
Or, obtain sha1sums of YOUR certs and only delete them? I could do it comfortably via SSH. Then only original would be left on system, right?
Do I understand correctly? :P
Thank you a lot for your help, very appreciated :)
Regards, WW

badpixel 2022-04-12 12:11

Re: Restoring original CA certs without reflashing - possible?
 
Deb updated monthly would be awesome.

I really would like to use N9 or N950 as the only device I need to carry. But without working web browser it woudl be hard....


All times are GMT. The time now is 11:56.

vBulletin® Version 3.8.8