Bug 455632 - Unable to establish stable internet connection cause could be issues related to permanent trojita certificate changes
Summary: Unable to establish stable internet connection cause could be issues related ...
Status: RESOLVED WORKSFORME
Alias: None
Product: trojita
Classification: Unmaintained
Component: Cryptography (show other bugs)
Version: unspecified
Platform: Ubuntu Linux
: NOR critical
Target Milestone: ---
Assignee: Trojita default assignee
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-06-20 07:06 UTC by dreyerbernd
Modified: 2022-07-21 04:36 UTC (History)
0 users

See Also:
Latest Commit:
Version Fixed In:
Sentry Crash Report:


Attachments
6FEC8E4AEF9E472ABDBEAB18FDED9B10.png (181.48 KB, image/png)
2022-06-20 09:13 UTC, dreyerbernd
Details
Unterschiedliches Zertifikat.jpg (58.99 KB, image/jpeg)
2022-06-20 09:13 UTC, dreyerbernd
Details
attachment-32497-0.html (3.70 KB, text/html)
2022-06-20 09:30 UTC, dreyerbernd
Details
attachment-26347-0.html (4.14 KB, text/html)
2022-06-20 13:22 UTC, dreyerbernd
Details
Probleme_mit_dem_darunterliegenden_Socket.jpg (21.71 KB, image/jpeg)
2022-06-20 15:54 UTC, dreyerbernd
Details
attachment-16168-0.html (2.64 KB, text/html)
2022-06-21 08:04 UTC, dreyerbernd
Details

Note You need to log in before you can comment on or make changes to this bug.
Description dreyerbernd 2022-06-20 07:06:36 UTC
Unable to establish stable internet connection cause could be issues related to permanent trojita certificate changes.
Comment 1 Jan Kundrát 2022-06-20 07:17:13 UTC
Please describe the issue in more detail. What do you see, what do you hope to see, and what have you tried doing to fix the problem.
Comment 2 dreyerbernd 2022-06-20 09:13:29 UTC
Created attachment 149944 [details]
6FEC8E4AEF9E472ABDBEAB18FDED9B10.png

Hello Jan,

this is a srceenshot from the message.

[cid:image001.png@01D88496.AE1DA990]

Please do not hesitate.

Mit freundlichen Grüßen

Bernd Dreyer
Kirchenstraße 8
84478 Waldkraiburg
Deutschland
dreyerbernd@hotmail.de<mailto:dreyerbernd@hotmail.de>
Festnetz: +49 8638 2036295
Mobiltel.: +49 177 5428627<Tel:+491775428627>

Von: Jan Kundrát<mailto:bugzilla_noreply@kde.org>
Gesendet: Montag, 20. Juni 2022 09:17
An: dreyerbernd@hotmail.de<mailto:dreyerbernd@hotmail.de>
Betreff: [trojita] [Bug 455632] Unable to establish stable internet connection cause could be issues related to permanent trojita certificate changes

https://bugs.kde.org/show_bug.cgi?id=455632

Jan Kundrát <jkt@kde.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|REPORTED                    |NEEDSINFO
         Resolution|---                         |WAITINGFORINFO

--- Comment #1 from Jan Kundrát <jkt@kde.org> ---
Please describe the issue in more detail. What do you see, what do you hope to
see, and what have you tried doing to fix the problem.

--
You are receiving this mail because:
You reported the bug.
Comment 3 dreyerbernd 2022-06-20 09:13:29 UTC
Created attachment 149945 [details]
Unterschiedliches Zertifikat.jpg
Comment 4 Jan Kundrát 2022-06-20 09:24:12 UTC
Trojita (by design) uses TLS public key pinning. Perhaps our error message is too scary (there are legitimate reasons for changing the private key "every now and then", not just a security breach on the server side. If you accept the certificate, how often do you get this dialog about a new, changed key?

If there are services which rotate keys very often, perhaps we might want to hide this behind a settings option?
Comment 5 dreyerbernd 2022-06-20 09:30:21 UTC
Created attachment 149947 [details]
attachment-32497-0.html

Every second, when I accept the change of the certificate.

Mit freundlichen Grüßen

Bernd Dreyer
Kirchenstraße 8
84478 Waldkraiburg
Deutschland
dreyerbernd@hotmail.de<mailto:dreyerbernd@hotmail.de>
Festnetz: +49 8638 2036295
Mobiltel.: +49 177 5428627<Tel:+491775428627>

Von: Jan Kundrát<mailto:bugzilla_noreply@kde.org>
Gesendet: Montag, 20. Juni 2022 11:24
An: dreyerbernd@hotmail.de<mailto:dreyerbernd@hotmail.de>
Betreff: [trojita] [Bug 455632] Unable to establish stable internet connection cause could be issues related to permanent trojita certificate changes

https://bugs.kde.org/show_bug.cgi?id=455632

--- Comment #4 from Jan Kundrát <jkt@kde.org> ---
Trojita (by design) uses TLS public key pinning. Perhaps our error message is
too scary (there are legitimate reasons for changing the private key "every now
and then", not just a security breach on the server side. If you accept the
certificate, how often do you get this dialog about a new, changed key?

If there are services which rotate keys very often, perhaps we might want to
hide this behind a settings option?

--
You are receiving this mail because:
You reported the bug.
Comment 6 Thomas Lübking 2022-06-20 13:14:24 UTC
Don't full-quote the discussion, you're also exposing your email and private address and phone number…
You might want to edit your posts accordingly.

On topic, this is likely backwards: Your connection is unstable and the reconnects trigger cert "updates".
Check whether the hashes actually change.

Then check the system journal for what causes the instability (concurrent network managing services, firmware crashes, aggressive power saving, bluetooth interference or otherwise lousy signal) and fix that. If this is a wifi connection, try the behavior on a wired one.
Comment 7 dreyerbernd 2022-06-20 13:22:00 UTC
Created attachment 149952 [details]
attachment-26347-0.html

Thank you very much,

message window does open only in conjunction with your software running.
Disruption of the internet connection was also noticed by automatic Ubuntu updates (ticket was already released).

Mit freundlichen Grüßen

Bernd Dreyer
Kirchenstraße 8
84478 Waldkraiburg
Deutschland
dreyerbernd@hotmail.de<mailto:dreyerbernd@hotmail.de>
Festnetz: +49 8638 2036295
Mobiltel.: +49 177 5428627<Tel:+491775428627>

Von: Thomas Lübking<mailto:bugzilla_noreply@kde.org>
Gesendet: Montag, 20. Juni 2022 15:14
An: dreyerbernd@hotmail.de<mailto:dreyerbernd@hotmail.de>
Betreff: [trojita] [Bug 455632] Unable to establish stable internet connection cause could be issues related to permanent trojita certificate changes

https://bugs.kde.org/show_bug.cgi?id=455632

--- Comment #6 from Thomas Lübking <thomas.luebking@gmail.com> ---
Don't full-quote the discussion, you're also exposing your email and private
address and phone number…
You might want to edit your posts accordingly.

On topic, this is likely backwards: Your connection is unstable and the
reconnects trigger cert "updates".
Check whether the hashes actually change.

Then check the system journal for what causes the instability (concurrent
network managing services, firmware crashes, aggressive power saving, bluetooth
interference or otherwise lousy signal) and fix that. If this is a wifi
connection, try the behavior on a wired one.

--
You are receiving this mail because:
You reported the bug.
Comment 8 Thomas Lübking 2022-06-20 13:56:07 UTC
"Jans" software…

There's no doubt about where that dialog comes from. Just that it's not gonna be the cause for the effect of an unstable network connection.
And there's a reasonable chance that the wonky network "triggers" this dialog.
Again: check whether the hashes actually change.

As for your disconnects, thanks to you posting your full contacts every time it wasn't hard to figure that you've an ath9k chip which are recently troubled by apparently a series of bugs or a bug that ubuntu carries on:
https://bbs.archlinux.org/viewtopic.php?id=275037
https://bugzilla.kernel.org/show_bug.cgi?id=215703
https://bugzilla.kernel.org/show_bug.cgi?id=215698
https://bugzilla.kernel.org/show_bug.cgi?id=215918

So plug in an rj45 and see how trojita behaves when you have a reliable network.

Also, *again*, stop full quoting mails.
You're aware that you're mailing to a bugtracker, are you?
Every post is recorded and te contents go in verbatim including all contacts.
Comment 9 dreyerbernd 2022-06-20 14:12:53 UTC
Thank you very much,

there is another box which occurs after the one from which you already have 
the screenshot. 
This box disappears always after one second, so that I am unable to make a 
screenshot. Which programmer does this?

Best regards

Am Montag, 20. Juni 2022 15:56:07 CEST schrieb Thomas Lübking:
> https://bugs.kde.org/show_bug.cgi?id=455632
>
> --- Comment #8 from Thomas Lübking <thomas.luebking@gmail.com> ---
> "Jans" software…
>
> There's no doubt about where that dialog comes from. Just that 
> it's not gonna
> be the cause for the effect of an unstable network connection.
> And there's a reasonable chance that the wonky network 
> "triggers" this dialog.
> Again: check whether the hashes actually change.
>
> As for your disconnects, thanks to you posting your full 
> contacts every time it
> wasn't hard to figure that you've an ath9k chip which are 
> recently troubled by
> apparently a series of bugs or a bug that ubuntu carries on:
> https://bbs.archlinux.org/viewtopic.php?id=275037
> https://bugzilla.kernel.org/show_bug.cgi?id=215703
> https://bugzilla.kernel.org/show_bug.cgi?id=215698
> https://bugzilla.kernel.org/show_bug.cgi?id=215918
>
> So plug in an rj45 and see how trojita behaves when you have a reliable
> network.
>
> Also, *again*, stop full quoting mails.
> You're aware that you're mailing to a bugtracker, are you?
> Every post is recorded and te contents go in verbatim including 
> all contacts.
>
Comment 10 dreyerbernd 2022-06-20 15:54:30 UTC
Created attachment 149957 [details]
Probleme_mit_dem_darunterliegenden_Socket.jpg

Good afternoon,

you find the second popup window attached to this message.

Best Regards

Bernd Dreyer

Am Montag, 20. Juni 2022 15:56:07 CEST schrieb Thomas Lübking:
> https://bugs.kde.org/show_bug.cgi?id=455632
>
> --- Comment #8 from Thomas Lübking <thomas.luebking@gmail.com> ---
> "Jans" software…
>
> There's no doubt about where that dialog comes from. Just that 
> it's not gonna
> be the cause for the effect of an unstable network connection.
> And there's a reasonable chance that the wonky network 
> "triggers" this dialog.
> Again: check whether the hashes actually change.
>
> As for your disconnects, thanks to you posting your full 
> contacts every time it
> wasn't hard to figure that you've an ath9k chip which are 
> recently troubled by
> apparently a series of bugs or a bug that ubuntu carries on:
> https://bbs.archlinux.org/viewtopic.php?id=275037
> https://bugzilla.kernel.org/show_bug.cgi?id=215703
> https://bugzilla.kernel.org/show_bug.cgi?id=215698
> https://bugzilla.kernel.org/show_bug.cgi?id=215918
>
> So plug in an rj45 and see how trojita behaves when you have a reliable
> network.
>
> Also, *again*, stop full quoting mails.
> You're aware that you're mailing to a bugtracker, are you?
> Every post is recorded and te contents go in verbatim including 
> all contacts.
>
Comment 11 Thomas Lübking 2022-06-20 20:36:27 UTC
That's trojita, same problem (likely) - network gone.
Alternatively outlook.office365 simply kicked you.

However, I'm out.

@Jan, if you've editing rights on the tracker, I'd appreciate if you could wipe his mindless full-top-quotings.
Comment 12 dreyerbernd 2022-06-21 08:04:36 UTC
Created attachment 149993 [details]
attachment-16168-0.html

Vodafone told me that there is an interferer in the network. The disruption can’t eliminated until the originator (and the adapter) is found and could accessed.


________________________________
Von: Jan Kundrát <bugzilla_noreply@kde.org>
Gesendet: Monday, June 20, 2022 11:24:12 AM
An: dreyerbernd@hotmail.de <dreyerbernd@hotmail.de>
Betreff: [trojita] [Bug 455632] Unable to establish stable internet connection cause could be issues related to permanent trojita certificate changes

https://bugs.kde.org/show_bug.cgi?id=455632

--- Comment #4 from Jan Kundrát <jkt@kde.org> ---
Trojita (by design) uses TLS public key pinning. Perhaps our error message is
too scary (there are legitimate reasons for changing the private key "every now
and then", not just a security breach on the server side. If you accept the
certificate, how often do you get this dialog about a new, changed key?

If there are services which rotate keys very often, perhaps we might want to
hide this behind a settings option?

--
You are receiving this mail because:
You reported the bug.
Comment 13 Bug Janitor Service 2022-07-06 04:36:56 UTC
Dear Bug Submitter,

This bug has been in NEEDSINFO status with no change for at least
15 days. Please provide the requested information as soon as
possible and set the bug status as REPORTED. Due to regular bug
tracker maintenance, if the bug is still in NEEDSINFO status with
no change in 30 days the bug will be closed as RESOLVED > WORKSFORME
due to lack of needed information.

For more information about our bug triaging procedures please read the
wiki located here:
https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging

If you have already provided the requested information, please
mark the bug as REPORTED so that the KDE team knows that the bug is
ready to be confirmed.

Thank you for helping us make KDE software even better for everyone!
Comment 14 Bug Janitor Service 2022-07-21 04:36:43 UTC
This bug has been in NEEDSINFO status with no change for at least
30 days. The bug is now closed as RESOLVED > WORKSFORME
due to lack of needed information.

For more information about our bug triaging procedures please read the
wiki located here:
https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging

Thank you for helping us make KDE software even better for everyone!