From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id E3EBFEB64D8 for ; Wed, 21 Jun 2023 12:28:21 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:References: Message-ID:Subject:To:From:Date:Reply-To:Cc:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=DVkA0Lu6p4R6gjP7JMvQ6Xn4EtolVmi5xZyY7x9E+Cw=; b=2rnr2AakHMazz6 y2Ww7BFCodWhTY9Ms/AGs5x1N3no2tex/CUXFzvT91r9MkcFTcFR1w2SKZ7DYTXwi7ELaZFoGZSTJ M5VWuQ3e6fu4gkjWfN3THusWDXsVrPWTWQF3yH3BreKR+QP8byrAaBrw3JhEuTV5RqT8a3m894h50 QVW0BiIsyVElAxokW8oHgFbUd44W7DyxTqQ97D5093ghO6Rwhi2h3WTee2opDPvu5Iby7AjBoqtLy 14L5z2X5ex5SfdrJYsbtrlHU5GKx+CWWVb/L25uTzhPJI1i0HBn8qWR+NaUtaaCYDgPiWlyG+dvw1 4qBrWj0CdKaTkGYONrzA==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.96 #2 (Red Hat Linux)) id 1qBwwH-00EXd2-2b; Wed, 21 Jun 2023 12:27:57 +0000 Received: from pandora.armlinux.org.uk ([2001:4d48:ad52:32c8:5054:ff:fe00:142]) by bombadil.infradead.org with esmtps (Exim 4.96 #2 (Red Hat Linux)) id 1qBwwF-00EXbx-1a for linux-arm-kernel@lists.infradead.org; Wed, 21 Jun 2023 12:27:56 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=armlinux.org.uk; s=pandora-2019; h=Sender:In-Reply-To:Content-Type: MIME-Version:References:Message-ID:Subject:To:From:Date:Reply-To:Cc: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=EcCuT2xPRLmiUxkPgfhz+HtbHdFN0IXRkYTB5KyQmdQ=; b=uiS7CVsnzrQkMW73gegdrSpPzI Vg0inSoNEDWbZTDwaAUVAs1XaByYrm6AVaoXp5Twnszl6yUnmdajTEkBZW5rkH+vYzlu0d9Bf/fLw SqtQ5wiUnS289WvHhbikSIUYRUxjME1Eo5cGIF1J4X+03gMwMGInsK80ay4xqCl7k8yPs/5fOHtDO OYxLtxrarxRhT3gBlXXm/Pc+MiTgxSSflLz6LAs5gdOKhlPbAWbWH+fb3SCdRMTq3j+G9/WjHij29 8Ad5ucW1iy8TT1e/9ift/H75BW5mXPyj79Cgm9QVA6gDuG7ySb+JavZ37+fh3qWGV1VEn8u83O0Z+ YuiZ4lTw==; Received: from shell.armlinux.org.uk ([fd8f:7570:feb6:1:5054:ff:fe00:4ec]:34950) by pandora.armlinux.org.uk with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1qBwwD-0002PV-VZ for linux-arm-kernel@lists.infradead.org; Wed, 21 Jun 2023 13:27:54 +0100 Received: from linux by shell.armlinux.org.uk with local (Exim 4.94.2) (envelope-from ) id 1qBwwD-0007kO-3l for linux-arm-kernel@lists.infradead.org; Wed, 21 Jun 2023 13:27:53 +0100 Date: Wed, 21 Jun 2023 13:27:53 +0100 From: "Russell King (Oracle)" To: linux-arm-kernel@lists.infradead.org Subject: Re: PSV: Patch system offline due to system upgrade Message-ID: References: MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20230621_052755_529921_7FA94298 X-CRM114-Status: GOOD ( 17.31 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On Wed, Jun 21, 2023 at 12:53:20PM +0100, Russell King (Oracle) wrote: > All, > > Sorry, but the patch system will be offline for a while, thanks to > upgrading the mail server from Debian Buster to Debian Bookworm; the > perl scripts can no longer connect to the SQL server with the totally > unfathomable complaint: > > DBI connect('database=armlinux;host=sql.armlinux.org.uk;mysql_ssl=1;mysql_ssl_ca_file=/etc/local/pki/mysql-cacert.pem;mysql_ssl_verify_server_cert=1',...,...) failed: SSL connection error: Enforcing SSL encryption is not supported > > It _looks_ from what the error message seems to be saying that the > perl DBI folk have *disabled* SSL on database connections... seriously? > In this day and age where encryption is becoming the norm? > > If anyone has any clues, please mail me (privately.) The problem appears to be that Debian Bookworm regresses the supported TLS version for DBD::mysql (mariadb) from supporting TLS v1.2 and TLS v1.3 back to the known-to-be-vulnerable TLS v1.1 ! >From what I can tell, under Debian Buster, mariadb was linked against gnutls. Under Debian Bookworm, at least the "mysql" utility is *not* dynamically linked against any SSL library, and appears to refer internally to "yassl" which I can only assume is some home-grown and if it only supports up to TLS v1.1, insecure implementation of SSL! Way to go, Debian! That's quite a step backwards in this modern age. -- RMK's Patch system: https://www.armlinux.org.uk/developer/patches/ FTTP is here! 80Mbps down 10Mbps up. Decent connectivity at last! _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel