Bug 435270 - SSL Error: Flatpak distribution cert errors
Summary: SSL Error: Flatpak distribution cert errors
Status: RESOLVED NOT A BUG
Alias: None
Product: Falkon
Classification: Applications
Component: general (other bugs)
Version First Reported In: 3.1.0
Platform: Flatpak Linux
: NOR normal
Target Milestone: ---
Assignee: David Rosca
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-04-02 15:11 UTC by hrwy
Modified: 2021-04-03 13:43 UTC (History)
8 users (show)

See Also:
Latest Commit:
Version Fixed/Implemented In:
Sentry Crash Report:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description hrwy 2021-04-02 15:11:52 UTC
SUMMARY
App shows certificate errors everywhere
github.com and duckduckgo.com etc

STEPS TO REPRODUCE
1. update with sudo apt update; sudo apt upgrade OR change date(dd.mm.yyyy) from 01.04.2021 to 02.04.2021
2. reboot
3. try to open anything with https://

OBSERVED RESULT
All https sites start to ask many certificate exclusions, every new interaction - new certificate exclusion. 
EXPECTED RESULT
Updated Flatpak formula, maybe cert, maybe curl. One of distributions has newer version of Falkon than on Flatpak (Build date: 2020-08-10 12:15:09
Git commit: 93a74e62973b332ad7cc9e026b14035c6d85e287 on Alpine 3.13 x86_64)

SOFTWARE/OS VERSIONS

Linux/KDE Plasma: 
(uname, lcb_release -a)
Distributor ID:	elementary
Description:	elementary OS 5.1.7 Hera
Release:	5.1.7
Codename:	hera
Linux alekseipc 5.4.0-70-generic #78~18.04.1-Ubuntu SMP Sat Mar 20 14:10:07 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux

(flatpak-about packaging & KDE)
flatpak info org.kde.falkon                                                      ...      ID: org.kde.falkon
         Ref: app/org.kde.falkon/x86_64/master
        Arch: x86_64
      Branch: master
     License: GPL-3.0+
      Origin: kdeapps
  Collection: 
Installation: system
   Installed: 6,9 MB
     Runtime: org.kde.Platform/x86_64/5.12
         Sdk: org.kde.Sdk/x86_64/5.12

      Commit: 214ff1b6389c197d1fe7ba3041179444532504b6045e72daa01f188544641aac
      Parent: 3152db7096001e7c89e7a37352ed5850db71d5f9c99baca18dffb1e02afd63f2
     Subject: Built on Wed Oct 16 21:43:24 UTC 2019
        Date: 2019-10-16 21:47:14 +0000

ADDITIONAL INFORMATION
2021-04-02 11:29:04 ubuntu-keyring:all
2021-04-02 11:29:09 appstream-data-pantheon:all
2021-04-02 11:29:12 appstream-data-pantheon-icons:all
2021-04-02 11:29:22 appstream-data-pantheon-icons-hidpi:all
2021-04-02 11:29:26 boot-sav:all
2021-04-02 11:29:42 boot-repair:all
2021-04-02 11:29:46 boot-sav-extra:all
2021-04-02 11:29:49 libcurl4-openssl-dev:amd64
2021-04-02 11:29:56 curl:amd64
2021-04-02 11:29:58 libcurl4:amd64
2021-04-02 11:30:01 libwebkit2gtk-4.0-37:amd64
2021-04-02 11:30:11 libjavascriptcoregtk-4.0-18:amd64
2021-04-02 11:30:19 gir1.2-webkit2-4.0:amd64
2021-04-02 11:30:20 gir1.2-javascriptcoregtk-4.0:amd64
2021-04-02 11:30:21 libcurl3-gnutls:amd64
2021-04-02 11:30:24 libopenexr22:amd64
2021-04-02 11:30:27 libwebkit2gtk-4.0-37-gtk2:all
2021-04-02 11:30:29 palemoon:amd64
Comment 1 hrwy 2021-04-02 15:28:31 UTC
https://bugs.kde.org/show_bug.cgi?id=393480 - not directly connected.
all sites become unreachable, only sites opened from session (if it saved it's cookie are reachable). Browsing is totally impossible.
Comment 2 hrwy 2021-04-02 16:04:44 UTC
https://github.com/jordansissel/fpm I will repackage Alpine's apk to deb and will stay on the last (maybe) working version of Falkon.
Comment 3 Alberto Salvia Novella 2021-04-02 16:24:48 UTC
Why have you added me? Do you require any feedback from me on this?
Comment 4 Juraj 2021-04-02 17:13:10 UTC
Since you added me here I will at least tell you my opinion.

It is flatpak, what did you expect?

According to my knowledge certificates are managed by your system and QtWebEngine is using them while Falkon has probably no say in this (someone please fix me if I am wrong here) and thus this whole mess is caused by wither you system being outdated or flatpak thing is somehow messed up.

I never touched flatpak and even Falkon flatpak build/package in not (never was and never will be) my doing.

There are too many errors in Falkon which were/are/will be caused by QtWebEngine updates.
Comment 5 Alberto Salvia Novella 2021-04-02 17:28:30 UTC
If you need my feedback, add me back.
Comment 6 hrwy 2021-04-03 00:36:28 UTC
Juraj, thanks for your quick answer.
I understand what it's more flatpak problem than any other component.

People is CC mailing list, please remove your e-mail if you don't want see updates here.

I will provide here more information and will find original flatpak maintainer-releaser (on gitlab) after some probes with Falkon after the profile back-up.
(Probes) Falkon-Flatpak is now installed as system-package and it is more vulnerable to the changes on host system, so first I'll try reinstall it as --user. Second probe is to modify permissions in terminal / or with Flatseal program to overcome certificates problem.

My last comment about packaging isn't right: there is the only one place there last Flatpak package placed: download.kde.org.

/ My last comment
Comment 7 hrwy 2021-04-03 13:43:08 UTC
It's an only Flatpak problem, because I found that other Flatpak-distribution "Freetube" didn't connect to servers and it was installed in contrast to Falkon into --user (~/.locale/share/flatpak). So I'm closing the issue.
Thank you.