Bug 407095 - Openconnect fails with Unknown certificate hash: pin-sha256:*
Summary: Openconnect fails with Unknown certificate hash: pin-sha256:*
Status: RESOLVED WORKSFORME
Alias: None
Product: plasmashell
Classification: Plasma
Component: Networking in general (other bugs)
Version First Reported In: master
Platform: Other Linux
: NOR normal
Target Milestone: 1.0
Assignee: Jan Grulich
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-04-30 14:28 UTC by jellby
Modified: 2025-06-08 03:47 UTC (History)
1 user (show)

See Also:
Latest Commit:
Version Fixed/Implemented In:
Sentry Crash Report:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description jellby 2019-04-30 14:28:53 UTC
SUMMARY

I have an openconnect VPN connection that is currently failing with:

openconnect[6521]: Unknown certificate hash: pin-sha256:**************************************************.

This only happens for one particular user, a new user can connect correctly.

Furthermore, the reason for the failure only appears in the log file, there's no visual feedback, other than after entering username and password, the window vanishes and nothing happens.

STEPS TO REPRODUCE

I'm not 100% sure, but I suspect this happens because I first tried to use a newer openconnect version, that supports "pin-sha256", but when I now try using the right version I get the above error. It looks like the certificate hash was stored in the new format and it is now not recognized, but I cannot find where it is stored, or how to remove it!

SOFTWARE/OS VERSIONS
Linux/KDE Plasma: Kubuntu 18.04
(available in About System)
KDE Plasma Version: 5.12.7
KDE Frameworks Version: 5.44.0
Qt Version: 5.9.5
Comment 1 Ben Cooksley 2024-12-23 18:23:35 UTC
Bulk transfer as requested in T17796
Comment 2 Nate Graham 2025-05-09 17:29:23 UTC
Thank you for the bug report! I'm sorry we weren't able to get to it yet. Can you check and see if it's still an issue in Plasma 6.3.5 or later, and also presumably with newer system packages including newer versions of the packages for the networking stack?
Comment 3 Bug Janitor Service 2025-05-24 03:47:25 UTC
๐Ÿ›๐Ÿงน โš ๏ธ This bug has been in NEEDSINFO status with no change for at least 15 days. Please provide the requested information, then set the bug status to REPORTED. If there is no change for at least 30 days, it will be automatically closed as RESOLVED WORKSFORME.

For more information about our bug triaging procedures, please read https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging.

Thank you for helping us make KDE software even better for everyone!
Comment 4 Bug Janitor Service 2025-06-08 03:47:39 UTC
๐Ÿ›๐Ÿงน This bug has been in NEEDSINFO status with no change for at least 30 days. Closing as RESOLVED WORKSFORME.