![]() |
#1 | |
Junior Member
![]() Posts: 3
Karma: 10
Join Date: Aug 2023
Device: None
|
SSL issues with metadata download
I've looked through the forum and have found other similar questions about this topic. But seeing as I'm in an awkward place here, I'm going to re-ask with the details pertinent to my specific problem.
I'm running Calibre portable 6.24 When I try to download metadata, the query fails. Logs show the following: Quote:
I'm working from behind a firewall/content filter that parses SSL, similar to what some AV software does. I have no way to turn this off or add an exception, as this is not managed by me. The firewall re-signs the traffic using its own CA certificate, which I have. Is there a way to set Calibre to use that CA to accept the resigned SSL queries? |
|
![]() |
![]() |
![]() |
#2 |
Bibliophagist
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 46,220
Karma: 168983734
Join Date: Jul 2010
Location: Vancouver
Device: Kobo Sage, Libra Colour, Lenovo M8 FHD, Paperwhite 4, Tolino epos
|
There might be a way to get calibre to accept unsafe certificates but it would be better to have the certificate using a longer key. Basically, the certificate is using less than 128 bits which is the absolute minimum with OpenSSL security level 2. Ask your IT people to ensure that you are meeting current minimum security standards. Corporately, we use Palo Alto and 4096 bit RSA keys for our SSL decryption internal certificates. OTOH, we don't bother to try to use SSL decryption on Google who are using certificate pinning to make SSL decryption less than useful. There are several other techniques used as well. Our exception list ran to over 4 pages at one point. Sadly, our SSL decryption is pretty much the definition of a MITM attack.
|
![]() |
![]() |
Advert | |
|
![]() |
#3 |
Junior Member
![]() Posts: 3
Karma: 10
Join Date: Aug 2023
Device: None
|
Thanks David, but here's the issue:
The CA certificate is NOT weak, It's 2048 bit RSA. I can attach a copy of it here if it'll help anyone. You're right in that the filter essentially does an MTM attack. But since I actually want the service it does, I have no problem with it. I saw somewhere else on the forum that it's possible to get Calibre to use its own CA store, but I couldn't figure out how to do it and if it works also on the portable version. |
![]() |
![]() |
![]() |
#4 | |
Bibliophagist
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 46,220
Karma: 168983734
Join Date: Jul 2010
Location: Vancouver
Device: Kobo Sage, Libra Colour, Lenovo M8 FHD, Paperwhite 4, Tolino epos
|
Quote:
It's also possible that you are missing an intermediate certificate but since your corporate CA is being used, you should have been sent the certificate chain. <deleted a mass of over information> since I think I just bored everybody within 100 metres into a coma. |
|
![]() |
![]() |
![]() |
#5 |
creator of calibre
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 45,355
Karma: 27182818
Join Date: Oct 2006
Location: Mumbai, India
Device: Various
|
calibre uses python which uses OpenSSL. OpenSSL supports env vars to specify certificates. Whether those work on windows I have no idea. IIRC by default SSL uses the windows OS certificate store.
|
![]() |
![]() |
Advert | |
|
![]() |
#6 |
Junior Member
![]() Posts: 3
Karma: 10
Join Date: Aug 2023
Device: None
|
Thanks for the responses.
I'm comparing my certificate to others, and it looks no different than, say Symantec's root certificate. This certificate is also installed in my Windows certificate store, so Chrome and such have no issues with the resigned certificates. I find that only third-party software that expects a specific certificate (like Google Drive) has issues with this setup. Firefox uses its own store and I have the certificate installed there as well with no issues. I'm attaching my firewall's CA certificate, as well as the certificate I extracted from Mobileread, in case that gives anyone ideas on how to proceed. (They've both been RARed so they can be attached here...) _.mobileread.com.rar Symen (72295).rar |
![]() |
![]() |
![]() |
#7 |
creator of calibre
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 45,355
Karma: 27182818
Join Date: Oct 2006
Location: Mumbai, India
Device: Various
|
THis has nothing to do with the CA certificate. The error means the ceritficate for the site your are visiting is too weak, which means your MITM is returning fake certificates that are too weak.
|
![]() |
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Download Metadata - issues getting correct hits | Vanguard3000 | Calibre | 2 | 03-15-2023 01:20 PM |
Download metadata and covers issues | tomsem | Calibre | 5 | 11-29-2022 08:29 PM |
Issues with Metadata download and editing of comments. | MrBear | Calibre | 8 | 11-13-2021 10:36 PM |
"Download Metadata" issues | VirgoGirl | Calibre | 6 | 10-25-2013 04:53 AM |
Book metadata download handling issues | kloon | Library Management | 4 | 10-24-2012 02:30 PM |