hg ignores corporate root CA installed in /usr/share/ca-certificates

Bug #999216 reported by Robin Green
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mercurial (Ubuntu)
New
Undecided
Unassigned

Bug Description

I have installed a corporate root CA using the instructions here:
http://askubuntu.com/a/94861/5729

While this has allowed wget and curl to verify the certificate of an internal website, hg still says "abort [...] certificate verify failed". But it should not say that, because it is configured (by default) to look at the certificates in ca-certificates.

A notable difference between this root certificate and all the others (which are all shipped with Ubuntu), is that the others are all in text format, whereas this new root cert is in binary format.

ProblemType: Bug
DistroRelease: Ubuntu 12.04
Package: mercurial 2.0.2-1ubuntu1
ProcVersionSignature: Ubuntu 3.2.0-24.38-generic-pae 3.2.16
Uname: Linux 3.2.0-24-generic-pae i686
NonfreeKernelModules: nvidia wl
ApportVersion: 2.0.1-0ubuntu7
Architecture: i386
Date: Mon May 14 17:34:42 2012
EcryptfsInUse: Yes
InstallationMedia: Ubuntu 11.04 "Natty Narwhal" - Release i386 (20110427.1)
ProcEnviron:
 LANGUAGE=en_GB:en
 TERM=xterm
 PATH=(custom, user)
 LANG=en_GB.UTF-8
 SHELL=/bin/bash
SourcePackage: mercurial
UpgradeStatus: Upgraded to precise on 2012-04-27 (17 days ago)

Revision history for this message
Robin Green (greenrd) wrote :
Revision history for this message
Robin Green (greenrd) wrote :

OK, I see that binary cert formats are officially not supported by hg. But I installed a text version of the root CA and it still didn't work.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.