• Enabling SSL for NNRPD (was: Looking for peering and help)

    From Ray Banana@rayban@raybanana.net to news.admin.peering,news.software.nntp on Thu Mar 27 19:05:52 2025
    From Newsgroup: news.software.nntp

    [crosspost and followup-to to news.software.nntp]

    * Gabx wrote:
    I have commented out everything that concernes tls but i still get:

    20 [16:51:14] gabriel1@xnibiru25: ~ $ nc news.tcpreset.net 119
    400 Error initializing TLS

    Mar 27 15:52:34 news nnrpd[581321]: unable to get certificate from '/etc/news/cert.pem'
    Mar 27 15:52:34 news nnrpd[581321]: error initializing TLS: [CA_file: ] [CA_path: /etc/news] [cert_file: /etc/news/cert.pem] [key_file: /etc/news/key.pem]

    As you see:

    root@news:/etc/news/ssl# grep cert.pem -R /etc/news/
    /etc/news/inn.conf:#tlscertfile: /etc/news/ssl/cert.pe

    tls directive is commented out.

    When nnrpd is started by innd, it should only use SSL when a client explicitly requests encryption via STARTTLS, so I wonder how your nnrpd is actually started?

    What is the output from the following command:

    netstat -tulpen | grep :119

    Just because you mention Letsencrypt in your parallel posting in n.s.nntp:

    What does ls -l /etc/news/*.pem display`?

    And finally: What is your operating system (distibution)? Did you install
    INN from the package supplied by your distribution?
    --
    -f-a|U-e-u-+ rCo -a-a-|-+-+|U
    https://www.eternal-september.org
    --- Synchronet 3.21a-Linux NewsLink 1.2
  • From Gabx@dogfromhell666@mail2tor.com to news.software.nntp on Fri Mar 28 15:15:02 2025
    From Newsgroup: news.software.nntp

    Ray Banana wrote:

    And finally: What is your operating system (distibution)? Did you install
    INN from the package supplied by your distribution?


    I run ubuntu22.04 and INN2 2.6.4 installed by apt.

    Regards

    Gabx
    --
    https://yamn.virebent.art/contatti.html
    --- Synchronet 3.21a-Linux NewsLink 1.2
  • From Marco Moock@mm@dorfdsl.de to news.software.nntp on Fri Mar 28 16:35:45 2025
    From Newsgroup: news.software.nntp

    On 28.03.2025 15:15 Uhr Gabx wrote:

    I run ubuntu22.04 and INN2 2.6.4 installed by apt.

    Is there a reason to choose an old OS version?
    --
    kind regards
    Marco

    Send spam to 1743171302muell@stinkedores.dorfdsl.de

    --- Synchronet 3.21a-Linux NewsLink 1.2
  • From Ray Banana@rayban@raybanana.net to news.software.nntp on Fri Mar 28 17:18:49 2025
    From Newsgroup: news.software.nntp

    Thus spake Gabx <dogfromhell666@mail2tor.com>

    Ray Banana wrote:
    And finally: What is your operating system (distibution)? Did you install
    INN from the package supplied by your distribution?
    I run ubuntu22.04 and INN2 2.6.4 installed by apt.

    Thanks for the clarification. I found the answer to my first question in another reply.

    BTW:

    ,-----------------------------------------------------------------------
    | Path: news.tcpreset.net!.POSTED.news.eternal-september.org!not-for-mail
    | From: Ray Banana <rayban@raybanana.net>
    | Newsgroups: local.test
    | Subject: Test local
    | Date: Fri, 28 Mar 2025 16:08:47 -0000 (UTC)
    | Organization: An antother poorly-installed InterNetNews site

    and you even customized your inn.conf ;-)

    | Message-ID: <slrnvudicf.339rh.rayban@raybanana.net>
    | Mime-Version: 1.0
    | Content-Type: text/plain; charset=UTF-8
    | Content-Transfer-Encoding: 8bit
    | Injection-Date: Fri, 28 Mar 2025 16:08:47 -0000 (UTC)
    \________________________________________________________________________
    --
    -f-a|U-e-u-+ rCo -a-a-|-+-+|U
    https://www.eternal-september.org
    --- Synchronet 3.21a-Linux NewsLink 1.2