Zřejmě máte TLS_FORWARD kde nakonfigurované jméno služby neodpovídá jménu certifikátu který ta služba pošle. Tam aktualizace ca-certificates nemůže pomoct, protože nesedí jméno. Takže... prostě nastavte správné jméno, za předpokladu že mu stále věříte, apod.
Kde/ako (v ktorom konfigu) mám správne nastaviť to meno ?
Ja mám k /etc/knot-resolver/kresd.conf nasledujuce nastavenie TLS
policy.add(policy.all(policy.TLS_FORWARD({
{'9.9.9.9', hostname='dns.quad9.net', ca_file='/etc/ssl/certs/ca-certificates.crt'},
{'149.112.112.112', hostname='dns.quad9.net', ca_file='/etc/ssl/certs/ca-certificates.crt'},
{'194.36.144.87', hostname='ns29.de.dns.opennic.glue', ca_file='/etc/ssl/certs/ca-certificates.crt'}
})))
Tiez som si všimol ze sa Knot obsac sam od seba restartne, , vypis z /var/log/syslog
Aug 1 09:34:37 rpi400 kresd[2312]: [tls_cl] failed to verify peer certificate: The certificate is NOT trusted. The name in the certificate does not match the expected.
Aug 1 09:37:22 rpi400 kresd[2312]: double free or corruption (!prev)
Aug 1 09:37:23 rpi400 systemd[1]: kresd@1.service: Main process exited, code=dumped, status=6/ABRT
Aug 1 09:37:23 rpi400 systemd[1]: kresd@1.service: Failed with result 'core-dump'.
Aug 1 09:37:23 rpi400 systemd[1]: kresd@1.service: Scheduled restart job, restart counter is at 2.
Aug 1 09:37:23 rpi400 systemd[1]: Stopped Knot Resolver daemon.
Aug 1 09:37:23 rpi400 systemd[1]: Starting Knot Resolver daemon...
Aug 1 09:37:23 rpi400 systemd[1]: Started Knot Resolver daemon.
Aug 1 09:38:20 rpi400 kresd[5900]: [tls_cl] failed to verify peer certificate: The certificate is NOT trusted. The name in the certificate does not match the expected.
Aug 1 09:38:44 rpi400 kresd[5900]: message repeated 3 times: [ [tls_cl] failed to verify peer certificate: The certificate is NOT trusted. The name in the certificate doe