#1012810 cadaver: Doesn't recognise SSL cert (perhaps because it has many names)

Package:
cadaver
Source:
cadaver
Description:
command-line WebDAV client
Submitter:
Date:
2022-06-14 16:09:03 UTC
Severity:
normal
#1012810#5
Date:
2022-06-14 15:35:43 UTC
From:
To:
I'm trying to use cadaver on stable/amd64, the version I've got here
differs from the newest packages both by having a binary non-maintainer
upload for amd64 (giving the "+b1" on my version, i.e. I have that) and
a non-maintainer upload that only fixes building issues (as far as I
can see - giving the change for "-2.1" to "-2.2" - I don't have that).
In total I don't believe those differences matter for this issue.

When I try to use cadaver, I get this:
dav:!> open https://files.one.com
WARNING: Untrusted server certificate presented for `confluence.one.com':
Issued to: internal-it.one.com
Issued by: Let's Encrypt, US
Certificate is valid from Wed, 27 Apr 2022 15:35:02 GMT to Tue, 26 Jul 2022 15:35:01 GMT
Do you wish to accept the certificate? (y/n)


When I visit that site in a browser, it doesn't say anything about that
certificate, if I view it I can see it has 11 alternate names, of which
files.one.com is the second. We're witin the validity period that cadaver
sees and it actually shows the first alternate name in the "Untrusted
server certificate presented"-message, perhaps cadaver (or some library
it uses) doesn't properly support that many alternate names?

This might be the same issue as reported in
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=741366
but that bug report doesn't contain any info about the certificate
offered, so it's hard to tell.

.Henrik

#1012810#10
Date:
2022-06-14 15:55:06 UTC
From:
To:
submitter debian@3001.dk