Jump to content

Plugin Install SSL Issue


Recommended Posts

Digital_Warrior
Posted

Fresh install on Centos 9 Stream. Emby Version 4.7.1.0

I am unable to install any plugins or check for updates. The log shows this error

InnerException: System.Security.Authentication.AuthenticationException: The remote certificate is invalid because of errors in the certificate chain: NotSignatureValid

I am able to download using wget https://embydata.com/admin/service/packageFiles/Emby.PortMapper.dll_1.1.4.exe  with out any issue.

 

embyserver.txt

Q-Droid
Posted (edited)

This might be the result of Centos 9 hardening and not necessarily .Net.  Would changing the systemwide crypto policy to LEGACY be a workaround?

https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening

Linked from here: https://serverfault.com/questions/1095898/how-can-i-use-a-legacy-ssh-rsa-key-on-centos-9-stream

Edit:

Well, after more reading and even if this ends up being the workaround there are big differences between rel 8 and 9. The same policy is stricter in 9 so IF this were to be a solution it would have to be more explicit in how the policy is defined.

https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening

 

Edited by Q-Droid
  • Thanks 1
Q-Droid
Posted

This was kinda bugging me so I decided to test it with a fresh CentOS Stream 9 VM. The default crypto policy is definitely too strict and causing this problem. The workaround is as simple as changing the policy and rebooting.

$ update-crypto-policies --set LEGACY

$ reboot

I tried using the DEFAULT policy first and got the same error as the OP for plug-in installation. Changing policy to LEGACY allowed plug-in installation and then changing policy back to DEFAULT would trigger the errors again for subsequent plug-in installs.

 

 

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...