<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent changes to 350: SSL/TLS error prevented download of tile</title><link>https://sourceforge.net/p/mobac/bugs/350/</link><description>Recent changes to 350: SSL/TLS error prevented download of tile</description><atom:link href="https://sourceforge.net/p/mobac/bugs/350/feed.rss" rel="self"/><language>en</language><lastBuildDate>Wed, 10 Feb 2021 14:07:39 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/mobac/bugs/350/feed.rss" rel="self" type="application/rss+xml"/><item><title>#350 SSL/TLS error prevented download of tile</title><link>https://sourceforge.net/p/mobac/bugs/350/?limit=25#154c/d4f0</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;The grade of the server is not relevant. Look at the detail result especially on the cert chain. &lt;/p&gt;
&lt;p&gt;You are on Linux and you use SunJRE!? &lt;/p&gt;
&lt;p&gt;OpenJDK is IMHO at the moment the most preferred Java version to use.  SunJRE is dead because of license restrictions and Java 8 is getting a bit old.  &lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">r_x</dc:creator><pubDate>Wed, 10 Feb 2021 14:07:39 -0000</pubDate><guid>https://sourceforge.net232cfa5250dbb11e2a17175bdb3ec7519a0f47a4</guid></item><item><title>#350 SSL/TLS error prevented download of tile</title><link>https://sourceforge.net/p/mobac/bugs/350/?limit=25#154c</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;An interesting point is that using OpenJDK is avoiding the problem:&lt;/p&gt;
&lt;div class="codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="n"&gt;openjdk&lt;/span&gt; &lt;span class="k"&gt;version&lt;/span&gt; &lt;span class="ss"&gt;"11.0.10"&lt;/span&gt; &lt;span class="mi"&gt;2021&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;01&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;19&lt;/span&gt;
&lt;span class="n"&gt;OpenJDK&lt;/span&gt; &lt;span class="n"&gt;Runtime&lt;/span&gt; &lt;span class="n"&gt;Environment&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;build&lt;/span&gt; &lt;span class="mi"&gt;11&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="mi"&gt;9&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;Ubuntu&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="n"&gt;ubuntu1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mi"&gt;20&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mi"&gt;04&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;OpenJDK&lt;/span&gt; &lt;span class="mi"&gt;64&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="nb"&gt;Bit&lt;/span&gt; &lt;span class="n"&gt;Server&lt;/span&gt; &lt;span class="n"&gt;VM&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;build&lt;/span&gt; &lt;span class="mi"&gt;11&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="mi"&gt;9&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;Ubuntu&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="n"&gt;ubuntu1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mi"&gt;20&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mi"&gt;04&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;mixed&lt;/span&gt; &lt;span class="k"&gt;mode&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;sharing&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;

&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">rtfm</dc:creator><pubDate>Wed, 10 Feb 2021 14:00:40 -0000</pubDate><guid>https://sourceforge.net127b3c8ab785c24017c7faabd4750e0190040138</guid></item><item><title>#350 SSL/TLS error prevented download of tile</title><link>https://sourceforge.net/p/mobac/bugs/350/?limit=25#c009</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Checking the server with the URL you provided returns A grade for all 4 IP's.&lt;br/&gt;
So it is not the certificate chain itself.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">rtfm</dc:creator><pubDate>Wed, 10 Feb 2021 13:56:31 -0000</pubDate><guid>https://sourceforge.net7b3e466dc23cf7c89871f063f003c7cc85ff6847</guid></item><item><title>#350 SSL/TLS error prevented download of tile</title><link>https://sourceforge.net/p/mobac/bugs/350/?limit=25#ff01</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Some servers are configured wrong and even if the root CA certificate is trusted they forget to send the intermediate certificates. Firefox is so kind to provide an own large intermediate CA store to fix such problems. Java does not provide such a service to correct defect HTTPS servers. &lt;/p&gt;
&lt;p&gt;Most likely this is the problem.&lt;br/&gt;
You can test the server regarding SSL/TLS problems: &lt;a href="https://www.ssllabs.com/ssltest/" rel="nofollow"&gt;https://www.ssllabs.com/ssltest/&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">r_x</dc:creator><pubDate>Wed, 10 Feb 2021 13:18:01 -0000</pubDate><guid>https://sourceforge.netcce2260eb249f6a039258e1c4dce642e1963142f</guid></item><item><title>SSL/TLS error prevented download of tile</title><link>https://sourceforge.net/p/mobac/bugs/350/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;I get the following error by accessing the WMS server:&lt;/p&gt;
&lt;div class="codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nv"&gt;ERROR&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="nv"&gt;SSL&lt;/span&gt; &lt;span class="nv"&gt;error&lt;/span&gt;: &lt;span class="nv"&gt;PKIX&lt;/span&gt; &lt;span class="nv"&gt;path&lt;/span&gt; &lt;span class="nv"&gt;building&lt;/span&gt; &lt;span class="nv"&gt;failed&lt;/span&gt;: &lt;span class="nv"&gt;sun&lt;/span&gt;.&lt;span class="nv"&gt;security&lt;/span&gt;.&lt;span class="nv"&gt;provider&lt;/span&gt;.&lt;span class="nv"&gt;certpath&lt;/span&gt;.&lt;span class="nv"&gt;SunCertPathBuilderException&lt;/span&gt;: &lt;span class="nv"&gt;unable&lt;/span&gt; &lt;span class="nv"&gt;to&lt;/span&gt; &lt;span class="nv"&gt;find&lt;/span&gt; &lt;span class="nv"&gt;valid&lt;/span&gt; &lt;span class="nv"&gt;certification&lt;/span&gt; &lt;span class="nv"&gt;path&lt;/span&gt; &lt;span class="nv"&gt;to&lt;/span&gt; &lt;span class="nv"&gt;requested&lt;/span&gt; &lt;span class="nv"&gt;target&lt;/span&gt;
&lt;span class="nv"&gt;WARN&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="nv"&gt;SSL&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="nv"&gt;TLS&lt;/span&gt; &lt;span class="nv"&gt;error&lt;/span&gt; &lt;span class="nv"&gt;prevented&lt;/span&gt; &lt;span class="nv"&gt;download&lt;/span&gt; &lt;span class="nv"&gt;of&lt;/span&gt; &lt;span class="nv"&gt;tile&lt;/span&gt; &lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="mi"&gt;535&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="mi"&gt;362&lt;/span&gt;@&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nv"&gt;snip&lt;/span&gt;&lt;span class="o"&gt;/&amp;gt;&lt;/span&gt;: &lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nv"&gt;snip&lt;/span&gt;&lt;span class="o"&gt;/&amp;gt;&lt;/span&gt;: &lt;span class="nv"&gt;java&lt;/span&gt;.&lt;span class="nv"&gt;security&lt;/span&gt;.&lt;span class="nv"&gt;cert&lt;/span&gt;.&lt;span class="nv"&gt;CertificateException&lt;/span&gt;: &lt;span class="nv"&gt;Untrusted&lt;/span&gt; &lt;span class="nv"&gt;certificate&lt;/span&gt; &lt;span class="nv"&gt;encountered&lt;/span&gt;: &lt;span class="nv"&gt;publicKeyHash&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;&amp;lt;snip/&amp;gt;&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="c1"&gt;; certificate issued for &amp;lt;snip/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;I suspect a java keystore problem, but cannot find which keystore is involved.&lt;br/&gt;
The certificate chain is valid: I can fetch tiles with Firefox and check that the certificates are trusted.&lt;/p&gt;
&lt;p&gt;java version "1.8.0_281"&lt;br/&gt;
Java(TM) SE Runtime Environment (build 1.8.0_281-b09)&lt;br/&gt;
Java HotSpot(TM) 64-Bit Server VM (build 25.281-b09, mixed mode)&lt;/p&gt;
&lt;p&gt;Running Linux Mint 20.1&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">rtfm</dc:creator><pubDate>Wed, 10 Feb 2021 13:14:18 -0000</pubDate><guid>https://sourceforge.netb7f0a026efda268dc84d3b939df1efd7dae4588d</guid></item></channel></rss>