Thread 'schannel: disabled automatic use of client certificate'

Message boards : Questions and problems : schannel: disabled automatic use of client certificate
Message board moderation

To post messages, you must log in.

AuthorMessage
Lasantha Bandara

Send message
Joined: 28 Dec 24
Posts: 2
Sri Lanka
Message 115085 - Posted: 28 Dec 2024, 4:04:50 UTC

everything was working fine till last week. now only 7.16.20 can run. anything above that version gives error. windows pro 11.


12/27/2024 5:54:26 AM | Rosetta@home | Scheduler list fetch from https://boinc.bakerlab.org/rosetta/ failed: transient HTTP error
12/27/2024 5:54:27 AM | | [http] [ID#0] Info: Hostname boinc.bakerlab.org was found in DNS cache
12/27/2024 5:54:27 AM | | [http] [ID#0] Info: Trying 128.95.160.157:443...
12/27/2024 5:54:27 AM | | [http] [ID#0] Info: Connected to boinc.bakerlab.org (128.95.160.157) port 443
12/27/2024 5:54:27 AM | | [http] [ID#0] Info: schannel: disabled automatic use of client certificate
12/27/2024 5:54:27 AM | | [http] [ID#0] Info: ALPN: curl offers http/1.1
12/27/2024 5:54:27 AM | | [http] [ID#0] Info: schannel: next InitializeSecurityContext failed: CRYPT_E_REVOCATION_OFFLINE (0x80092013) - The revocation function was unable to check revocation because the revocation server was offline.
12/27/2024 5:54:27 AM | | [http] [ID#0] Info: Closing connection
12/27/2024 5:54:27 AM | | [http] [ID#0] Info: schannel: shutting down SSL/TLS connection with boinc.bakerlab.org port 443
12/27/2024 5:54:27 AM | | [http] HTTP error: SSL connect error
12/27/2024 5:54:29 AM | | [http] [ID#0] Info: Connection 7 seems to be dead
12/27/2024 5:54:29 AM | | [http] [ID#0] Info: Closing connection
12/27/2024 5:54:29 AM | | [http] [ID#0] Info: schannel: shutting down SSL/TLS connection with denis.usj.es port 443
12/27/2024 5:54:29 AM | | [http] [ID#0] Info: Host www.worldcommunitygrid.org:443 was resolved.

ID: 115085 · Report as offensive     Reply Quote
Dr Who Fan
Avatar

Send message
Joined: 10 May 07
Posts: 1468
United States
Message 115086 - Posted: 28 Dec 2024, 5:46:19 UTC - in response to Message 115085.  

Rosetta continues to have EXPIRED SSL/SECURITY CERTIFICATES on one or more servers for over a month now.

The temporary workaround is to edit the hosts file on your PC's.

See the many posts in the Message boards : Number crunching : Problems and Technical Issues with Rosetta@home link to instructions
ID: 115086 · Report as offensive     Reply Quote
Lasantha Bandara

Send message
Joined: 28 Dec 24
Posts: 2
Sri Lanka
Message 115088 - Posted: 28 Dec 2024, 14:30:42 UTC - in response to Message 115086.  

In reply to Dr Who Fan's message of 28 Dec 2024:
Rosetta continues to have EXPIRED SSL/SECURITY CERTIFICATES on one or more servers for over a month now.

The temporary workaround is to edit the hosts file on your PC's.

See the many posts in the Message boards : Number crunching : Problems and Technical Issues with Rosetta@home link to instructions


its even happen to GPUGRID .
It seems all project get this issue.when i report on respective groups all say it works fine.so its mine only Im trying to find out whats causing it, all have same error, client certificate.
ID: 115088 · Report as offensive     Reply Quote
ProfileVitalii Koshura
Volunteer developer
Help desk expert
Avatar

Send message
Joined: 29 Mar 17
Posts: 39
Germany
Message 115098 - Posted: 28 Dec 2024, 23:50:24 UTC - in response to Message 115088.  

In reply to Lasantha Bandara's message of 28 Dec 2024:
In reply to Dr Who Fan's message of 28 Dec 2024:
Rosetta continues to have EXPIRED SSL/SECURITY CERTIFICATES on one or more servers for over a month now.

The temporary workaround is to edit the hosts file on your PC's.

See the many posts in the Message boards : Number crunching : Problems and Technical Issues with Rosetta@home link to instructions


its even happen to GPUGRID .
It seems all project get this issue.when i report on respective groups all say it works fine.so its mine only Im trying to find out whats causing it, all have same error, client certificate.

Do you see the error when you try to go to the projects' websites?
Usually your browser should inform you that the site certificate is not valid.
Also, do you have your system up to date?
Do you use any non-default Endpoint Protection Software (Antivirus) that monitors your traffic?
I suggest also to scan your system for viruses with any antivirus of your choice (you don't need to buy any, almost all of them support some free version with simple scanning that should be enough for this purpose).
Also, if you use any kind of firewall (again, non-default) check its settings and logs.
BOINC maintainer.
For any insight, check my BOINC Development Blog.
ID: 115098 · Report as offensive     Reply Quote
ProfileDave
Help desk expert

Send message
Joined: 28 Jun 10
Posts: 2750
United Kingdom
Message 115099 - Posted: 29 Dec 2024, 9:47:07 UTC

everything was working fine till last week. now only 7.16.20 can run. anything above that version gives error. windows pro 11.

I don't remember if it was Windows or Linux that used to have its own ca_bundle.cert file with its list of certificates rather than relying on the system. Is it possible that your Windows installation is for some reason not updating the certificates? I did have a quick scan through the release notes but didn't spot the change.
ID: 115099 · Report as offensive     Reply Quote
Richard Haselgrove
Volunteer tester
Help desk expert

Send message
Joined: 5 Oct 06
Posts: 5138
United Kingdom
Message 115100 - Posted: 29 Dec 2024, 10:16:29 UTC - in response to Message 115099.  

In reply to Dave's message of 29 Dec 2024:
everything was working fine till last week. now only 7.16.20 can run. anything above that version gives error. windows pro 11.
I don't remember if it was Windows or Linux that used to have its own ca_bundle.cert file with its list of certificates rather than relying on the system. Is it possible that your Windows installation is for some reason not updating the certificates? I did have a quick scan through the release notes but didn't spot the change.
Windows.

The ca_bundle.crt file was supplied by BOINC, but sometimes not updated in time[*]. I can't remember whether there was an 'in use' update facility, or if it was only updated by the installer for a new version - I suspect the latter. The use of a separate file was made redundant by the switch to schannel, and won't be coming back: I suggest the questioner should concentrate on working out why that isn't working in this case.

[*] despite me writing it explicitly into the Release Manager's checklist during Kevin Reed's working party - nearly 10 years ago now.

The last version available in the BOINC download folder is datestamped October 2021 - I wouldn't trust that one, but it is a standard internet file and can be downloaded from other sources.
ID: 115100 · Report as offensive     Reply Quote

Message boards : Questions and problems : schannel: disabled automatic use of client certificate

Copyright © 2025 University of California.
Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation.