On Fri, Oct 08, 2010 at 10:57:58AM -0700, Jesse Keating wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > On 10/8/10 10:52 AM, Farkas Levente wrote: > > rhel-6 beta2's > > nss-3.12.6-3.el6.x86_64 > > anyway yesterday morning i was not able to build, but afternoot after a > > new cert ie: fedora-packager-setup i was able to build again. then today > > i can't build again... > > > > Are you generating the cert on multiple hosts? You can only ever have > one cert, you have to copy it manually to all the hosts that you work from. > This would seem to fit the symptoms of being able to build yesterday but not today -- the crl that invalidates an old key when a new one is created would take time to be generated and then propogated to the servers so creating multiple new certs would have all of them working for a period of time. > Also, I seem to recall RHEL6's nss having issues with our cert, somebody > more familiar with the problem will have to verify though. > Dennis informed me this morning that the koji stuff uses pyOpenSSL so it shouldn't be affected by nss. Uploading to the lookaside cache uses curl which uses nss in RHEL6 and all current Fedoras. One way to test whether the nss or openssl library is at fault would be to see if you can upload to lookaside even though building doesn't work or vice-versa. If neither one works, it's more likely that there's something wrong with the certificate itself. -Toshio
Attachment:
pgpqbtHucq6rv.pgp
Description: PGP signature
-- devel mailing list devel@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/devel