Scheduler request failed: Peer certificate cannot be authenticated with given CA certificates

log in

Advanced search

Message boards : Number crunching : Scheduler request failed: Peer certificate cannot be authenticated with given CA certificates

Author Message
Dr Who Fan
     
Avatar
Send message
Joined: 29 Jul 11
Posts: 317
Credit: 1,164,609
RAC: 365
Total hours: 1,608,855
Message 8359 - Posted: 30 Sep 2021, 14:56:34 UTC

Keep getting the SAME ERROR messages across all my PC's:

WUProp@Home 9/30/2021 09:51:30 Scheduler request failed: Peer certificate cannot be authenticated with given CA certificates
WUProp@Home 9/30/2021 09:51:29 [http] HTTP error: Peer certificate cannot be authenticated with given CA certificates
WUProp@Home 9/30/2021 09:51:29 Sending scheduler request: Requested by project.
WUProp@Home 9/30/2021 09:49:11 Scheduler request failed: Peer certificate cannot be authenticated with given CA certificates
WUProp@Home 9/30/2021 09:49:10 [http] HTTP error: Peer certificate cannot be authenticated with given CA certificates
WUProp@Home 9/30/2021 09:49:10 [http] [ID#1] Info: SSL certificate problem: certificate has expired

____________

Profile den777
       
Send message
Joined: 21 Jun 13
Posts: 26
Credit: 817,922
RAC: 80
Total hours: 1,074,604
Message 8360 - Posted: 30 Sep 2021, 17:38:59 UTC
Last modified: 30 Sep 2021, 17:42:44 UTC

Other projects are affected too, but only on Windows, while Linux boxes are running fine.
Looks like ca-bundle.crt shipped with windows boinc client is outdated. I fixed this problem by copying /etc/ssl/certs/ca-ceritificates.crt from Linux to C:\Program Files\BOINC\ca-bundle.crt

Btw, this is working ca-bundle.crt (taken from Ubuntu 21.04) https://drive.google.com/file/d/1-zirSeFwap21lRABRLD6k_nlOHlXRLFe/view
(use it only if you trust me, ofc ;))

nanoprobe
   
Avatar
Send message
Joined: 20 Feb 13
Posts: 34
Credit: 653,713
RAC: 0
Total hours: 3,329,673
Message 8361 - Posted: 30 Sep 2021, 18:24:19 UTC
Last modified: 30 Sep 2021, 18:25:13 UTC

Replaced the file on windows with one from the link you posted. Problem solved. Read somewhere yesterday about this upcoming issue. Can't find it now.
Thanks
____________

Warped
 
Send message
Joined: 16 Sep 17
Posts: 1
Credit: 96,339
RAC: 0
Total hours: 133,827
Message 8362 - Posted: 30 Sep 2021, 19:49:30 UTC

This may be of interest:
https://www.theregister.com/2020/06/10/iot_trouble_root_certificates_expire/

matsu_pl
 
Send message
Joined: 28 Dec 18
Posts: 1
Credit: 336,889
RAC: 0
Total hours: 485,060
Message 8363 - Posted: 30 Sep 2021, 20:27:56 UTC - in response to Message 8360.

It's possible to fix the issue, without downloading any unknown files from the net.
Edit the file c:\Program Files\BOINC\ca-bundle.crt with administrative privileges, and remove the DST Root CA X3 expired certificate.

DST Root CA X3
==============
-----BEGIN CERTIFICATE-----
MIIDSjCCAjKgAwIBAgIQRK+wgNajJ7qJMDmGLvhAazANBgkqhkiG9w0BAQUFADA/MSQwIgYDVQQK
ExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMTDkRTVCBSb290IENBIFgzMB4X
DTAwMDkzMDIxMTIxOVoXDTIxMDkzMDE0MDExNVowPzEkMCIGA1UEChMbRGlnaXRhbCBTaWduYXR1
cmUgVHJ1c3QgQ28uMRcwFQYDVQQDEw5EU1QgUm9vdCBDQSBYMzCCASIwDQYJKoZIhvcNAQEBBQAD
ggEPADCCAQoCggEBAN+v6ZdQCINXtMxiZfaQguzH0yxrMMpb7NnDfcdAwRgUi+DoM3ZJKuM/IUmT
rE4Orz5Iy2Xu/NMhD2XSKtkyj4zl93ewEnu1lcCJo6m67XMuegwGMoOifooUMM0RoOEqOLl5CjH9
UL2AZd+3UWODyOKIYepLYYHsUmu5ouJLGiifSKOeDNoJjj4XLh7dIN9bxiqKqy69cK3FCxolkHRy
xXtqqzTWMIn/5WgTe1QLyNau7Fqckh49ZLOMxt+/yUFw7BZy1SbsOFU5Q9D8/RhcQPGX69Wam40d
utolucbY38EVAjqr2m7xPi71XAicPNaDaeQQmxkqtilX4+U9m5/wAl0CAwEAAaNCMEAwDwYDVR0T
AQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwHQYDVR0OBBYEFMSnsaR7LHH62+FLkHX/xBVghYkQ
MA0GCSqGSIb3DQEBBQUAA4IBAQCjGiybFwBcqR7uKGY3Or+Dxz9LwwmglSBd49lZRNI+DT69ikug
dB/OEIKcdBodfpga3csTS7MgROSR6cz8faXbauX+5v3gTt23ADq1cEmv8uXrAvHRAosZy5Q6XkjE
GB5YGV8eAlrwDPGxrancWYaLbumR9YbK+rlmM6pZW87ipxZzR8srzJmwN0jP41ZL9c8PDHIyh8bw
RLtTcm1D9SZImlJnt1ir/md2cXjbDaJWFBM5JDGFoqgCWjBH4d1QB7wCCZAA62RjYJsWvIjJEubS
fZGL+T0yjWW06XyxV3bqxbYoOb8VZRzI9neWagqNdwvYkQsEjgfbKbYK7p2CNTUQ
-----END CERTIFICATE-----

Profile STE\/E
           
Avatar
Send message
Joined: 28 Mar 10
Posts: 643
Credit: 3,878,883
RAC: 466
Total hours: 20,185,117
Message 8364 - Posted: 30 Sep 2021, 21:45:01 UTC - in response to Message 8360.

Other projects are affected too, but only on Windows, while Linux boxes are running fine.
Looks like ca-bundle.crt shipped with windows boinc client is outdated. I fixed this problem by copying /etc/ssl/certs/ca-ceritificates.crt from Linux to C:\Program Files\BOINC\ca-bundle.crt

Btw, this is working ca-bundle.crt (taken from Ubuntu 21.04) https://drive.google.com/file/d/1-zirSeFwap21lRABRLD6k_nlOHlXRLFe/view
(use it only if you trust me, ofc ;))


Thanks, fixed my problem on my Win 7 Pro & Win 10 Pro ...

Dr Who Fan
     
Avatar
Send message
Joined: 29 Jul 11
Posts: 317
Credit: 1,164,609
RAC: 365
Total hours: 1,608,855
Message 8365 - Posted: 30 Sep 2021, 22:09:27 UTC - in response to Message 8360.

... I fixed this problem by copying /etc/ssl/certs/ca-ceritificates.crt from Linux to C:\Program Files\BOINC\ca-bundle.crt

Btw, this is working ca-bundle.crt (taken from Ubuntu 21.04) https://drive.google.com/file/d/1-zirSeFwap21lRABRLD6k_nlOHlXRLFe/view
(use it only if you trust me, ofc ;))

Works for me across all my Windows versions.
____________

mmonnin
       
Send message
Joined: 22 Aug 16
Posts: 421
Credit: 1,947,129
RAC: 703
Total hours: 9,237,964
Message 8367 - Posted: 1 Oct 2021, 3:11:01 UTC

Works for me as well, thanks.

numbermaniac
 
Send message
Joined: 4 Sep 15
Posts: 7
Credit: 231,290
RAC: 217
Total hours: 168,430
Message 8368 - Posted: 1 Oct 2021, 5:22:05 UTC

I'm on Android and having this same error, which means I'm unable to report my completed task - is there any way to fix it there?

Dr Who Fan
     
Avatar
Send message
Joined: 29 Jul 11
Posts: 317
Credit: 1,164,609
RAC: 365
Total hours: 1,608,855
Message 8369 - Posted: 1 Oct 2021, 7:18:54 UTC - in response to Message 8368.

I'm on Android and having this same error, which means I'm unable to report my completed task - is there any way to fix it there?

You are using an outdated version (Android BOINC version 7.4.53) according to your computer list.

MANUALLY DOWNLOAD using your phones web browser and UPDATE THE LATEST BOINC VERSION 7.18.1. You will not find the latest version in the Google Play store.
Download Link: Android client version 7.18.1 released.

Once downloaded, suspend and EXIT BOINC.
Open folder where you saved the boinc_7.18.1.apk file and double tap/click to run the installer.
Once installed, Open BOINC and resume running. You can then delete the downloaded apk to save space if needed.
____________

OCNfranz
 
Send message
Joined: 4 Feb 21
Posts: 1
Credit: 130,702
RAC: 47
Total hours: 510,338
Message 8370 - Posted: 1 Oct 2021, 12:24:46 UTC - in response to Message 8363.

It's possible to fix the issue, without downloading any unknown files from the net.
Edit the file c:\Program Files\BOINC\ca-bundle.crt with administrative privileges, and remove the DST Root CA X3 expired certificate.


Thanks matsu_pl this worked for me

Profile [SG-FC] dingdong
     
Send message
Joined: 14 Apr 10
Posts: 16
Credit: 2,037,919
RAC: 520
Total hours: 4,878,199
Message 8371 - Posted: 1 Oct 2021, 16:08:52 UTC

I installed the Version 7.18.1 on all androids this morning. But now most wuprop results are marked as not guilty. What is to do?

Profile Michael Goetz
     
Avatar
Send message
Joined: 18 Apr 13
Posts: 166
Credit: 1,022,396
RAC: 158
Total hours: 1,612,548
Message 8372 - Posted: 1 Oct 2021, 16:40:17 UTC - in response to Message 8371.

I installed the Version 7.18.1 on all androids this morning. But now most wuprop results are marked as not guilty. What is to do?


Try disabling remote access in the prefs.
____________
Want to find one of the largest known primes? Try PrimeGrid. Or help cure disease at WCG.

Dr Who Fan
     
Avatar
Send message
Joined: 29 Jul 11
Posts: 317
Credit: 1,164,609
RAC: 365
Total hours: 1,608,855
Message 8373 - Posted: 1 Oct 2021, 16:46:33 UTC - in response to Message 8371.

I installed the Version 7.18.1 on all androids this morning. But now most wuprop results are marked as not guilty. What is to do?

08:42:10 (20447): Erreur reception active_result
08:43:10 (20447): can't connect to Unix domain socket

DISABLE RPC (REMOTE MONITORING) ON THE AFFECTED ANDROID DEVICES.
____________

Profile [SG-FC] dingdong
     
Send message
Joined: 14 Apr 10
Posts: 16
Credit: 2,037,919
RAC: 520
Total hours: 4,878,199
Message 8374 - Posted: 1 Oct 2021, 17:03:13 UTC

Ok, thx. Will see in a few hours.

mmonnin
       
Send message
Joined: 22 Aug 16
Posts: 421
Credit: 1,947,129
RAC: 703
Total hours: 9,237,964
Message 8377 - Posted: 1 Oct 2021, 22:07:02 UTC

I also have this on 1 of my 5 RPIs running Raspian. 4 are identical RPI3s that I setup at the same time, same everything. v7.6.33

Profile [SG-FC] dingdong
     
Send message
Joined: 14 Apr 10
Posts: 16
Credit: 2,037,919
RAC: 520
Total hours: 4,878,199
Message 8385 - Posted: 2 Oct 2021, 4:29:00 UTC - in response to Message 8374.

Ok, thx. Will see in a few hours.


All wus of all devices are running fine now and are guilty. Thank you!

Profile Conan
       
Avatar
Send message
Joined: 28 Mar 10
Posts: 570
Credit: 1,178,401
RAC: 167
Total hours: 3,280,346
Message 8388 - Posted: 2 Oct 2021, 8:09:43 UTC

This is an Expired Certificate issue that does not belong to this or any other projects,

It is a certificate that has expired called IdentTrust DST Root CA X3 that has run from the year 2000 to September 30 2021 and has now expired. Let's Encrypt is the company supplying the certificate.

It deals with HTTPS access to the Web and will stop access if you are using it.
It can't apparently just be extended, and affects most devices prior to 2017. Windows XP Service pack 2 is affected but service pack is not (to a degree), lots of Apple devices and old phones will stop working and can't access the web.

There is a replacement Certificate called ISRG Root X1 and you can get it in a more recent CA Certificate bundle.
Some people have copied the version running in a recent Linux (which does not seem to be affected, probably because Firefox is the only browser that does not rely on the computers certificates to access the net) and then copied that into their Windows machines which seem to have fixed the problem. Or as Den777 posted below by downloading the CA Certificate (what I did) from his posted site.

I updated my CA Certificate bundle and found that only Latin Squares (ODLK1) and ODLK were the only two projects that stopped working.
Even with the updated certificate I had to Remove and Add back each project to get them to work again.

All working again now.

More information is available on the net see Let's Encrypt expiration

Conan
____________

Profile Bill F
   
Avatar
Send message
Joined: 21 Sep 16
Posts: 132
Credit: 534,581
RAC: 232
Total hours: 958,415
Message 8475 - Posted: 24 Oct 2021, 3:07:19 UTC

For any 64 Bit Windows users that did not correct their own crt file BOINC Berkeley has released an updated BOINC Version dated 17 Oct 2021. This version contains the corrected file.

7.16.20 can be found here

https://boinc.berkeley.edu/download.php

Bill F
____________
In October 1969 I took an oath to support and defend the Constitution of the United States against all enemies, foreign and domestic;
There was no expiration date.



Post to thread

Message boards : Number crunching : Scheduler request failed: Peer certificate cannot be authenticated with given CA certificates


Home | My Account | Message Boards | Results


Copyright © 2024 Sebastien