Skip to Main Content

Infrastructure Software

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

The certificate /usr/share/rhn/ULN-CA-CERT is expired

user12273809Mar 19 2016 — edited Mar 23 2016

Hi guys,

We have about 60 virtual machines running Oracle Linux Server 6 and 7 on a predominately Linux environment. This past Wednesday, we started getting this error when doing anything with YUM:

The certificate /usr/share/rhn/ULN-CA-CERT is expired. Please ensure you have the correct certificate and your system time is correct.

We have at least a few machines that this isn't happening on, and I can find absolutely zero difference between the working machines and the non-working ones (the files match exactly, as I've gone through and did an md5sum on them and the md5 sum matches between working and non-working). There seems to be absolutely no reason for this to happen. The certificate file is the same across all of them:

Certificate:

    Data:

        Version: 1 (0x0)

        Serial Number:

            02:ad:66:7e:4e:45:fe:5e:57:6f:3c:98:19:5e:dd:c0

        Signature Algorithm: md2WithRSAEncryption

        Issuer: C=US, O=RSA Data Security, Inc., OU=Secure Server Certification Authority

        Validity

            Not Before: Nov  9 00:00:00 1994 GMT

            Not After : Jan  7 23:59:59 2010 GMT

        Subject: C=US, O=RSA Data Security, Inc., OU=Secure Server Certification Authority

        Subject Public Key Info:

            Public Key Algorithm: rsaEncryption

            RSA Public Key: (1000 bit)

                Modulus (1000 bit):

                    00:92:ce:7a:c1:ae:83:3e:5a:aa:89:83:57:ac:25:

                    01:76:0c:ad:ae:8e:2c:37:ce:eb:35:78:64:54:03:

                    e5:84:40:51:c9:bf:8f:08:e2:8a:82:08:d2:16:86:

                    37:55:e9:b1:21:02:ad:76:68:81:9a:05:a2:4b:c9:

                    4b:25:66:22:56:6c:88:07:8f:f7:81:59:6d:84:07:

                    65:70:13:71:76:3e:9b:77:4c:e3:50:89:56:98:48:

                    b9:1d:a7:29:1a:13:2e:4a:11:59:9c:1e:15:d5:49:

                    54:2c:73:3a:69:82:b1:97:39:9c:6d:70:67:48:e5:

                    dd:2d:d6:c8:1e:7b

                Exponent: 65537 (0x10001)

    Signature Algorithm: md2WithRSAEncryption

        65:dd:7e:e1:b2:ec:b0:e2:3a:e0:ec:71:46:9a:19:11:b8:d3:

        c7:a0:b4:03:40:26:02:3e:09:9c:e1:12:b3:d1:5a:f6:37:a5:

        b7:61:03:b6:5b:16:69:3b:c6:44:08:0c:88:53:0c:6b:97:49:

        c7:3e:35:dc:6c:b9:bb:aa:df:5c:bb:3a:2f:93:60:b6:a9:4b:

        4d:f2:20:f7:cd:5f:7f:64:7b:8e:dc:00:5c:d7:fa:77:ca:39:

        16:59:6f:0e:ea:d3:b5:83:7f:4d:4d:42:56:76:b4:c9:5f:04:

        f8:38:f8:eb:d2:5f:75:5f:cd:7b:fc:e5:8e:80:7c:fc:50

-----BEGIN CERTIFICATE-----

MIICNDCCAaECEAKtZn5ORf5eV288mBle3cAwDQYJKoZIhvcNAQECBQAwXzELMAkG

A1UEBhMCVVMxIDAeBgNVBAoTF1JTQSBEYXRhIFNlY3VyaXR5LCBJbmMuMS4wLAYD

VQQLEyVTZWN1cmUgU2VydmVyIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MB4XDTk0

MTEwOTAwMDAwMFoXDTEwMDEwNzIzNTk1OVowXzELMAkGA1UEBhMCVVMxIDAeBgNV

BAoTF1JTQSBEYXRhIFNlY3VyaXR5LCBJbmMuMS4wLAYDVQQLEyVTZWN1cmUgU2Vy

dmVyIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIGbMA0GCSqGSIb3DQEBAQUAA4GJ

ADCBhQJ+AJLOesGugz5aqomDV6wlAXYMra6OLDfO6zV4ZFQD5YRAUcm/jwjiioII

0haGN1XpsSECrXZogZoFokvJSyVmIlZsiAeP94FZbYQHZXATcXY+m3dM41CJVphI

uR2nKRoTLkoRWZweFdVJVCxzOmmCsZc5nG1wZ0jl3S3WyB57AgMBAAEwDQYJKoZI

hvcNAQECBQADfgBl3X7hsuyw4jrg7HFGmhkRuNPHoLQDQCYCPgmc4RKz0Vr2N6W3

YQO2WxZpO8ZECAyIUwxrl0nHPjXcbLm7qt9cuzovk2C2qUtN8iD3zV9/ZHuO3ABc

1/p3yjkWWW8O6tO1g39NTUJWdrTJXwT4OPjr0l91X817/OWOgHz8UA==

-----END CERTIFICATE-----

Certificate:

    Data:

        Version: 1 (0x0)

        Serial Number:

            70:ba:e4:1d:10:d9:29:34:b6:38:ca:7b:03:cc:ba:bf

        Signature Algorithm: md2WithRSAEncryption

        Issuer: C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority

        Validity

            Not Before: Jan 29 00:00:00 1996 GMT

            Not After : Aug  1 23:59:59 2028 GMT

        Subject: C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority

        Subject Public Key Info:

            Public Key Algorithm: rsaEncryption

            RSA Public Key: (1024 bit)

                Modulus (1024 bit):

                    00:c9:5c:59:9e:f2:1b:8a:01:14:b4:10:df:04:40:

                    db:e3:57:af:6a:45:40:8f:84:0c:0b:d1:33:d9:d9:

                    11:cf:ee:02:58:1f:25:f7:2a:a8:44:05:aa:ec:03:

                    1f:78:7f:9e:93:b9:9a:00:aa:23:7d:d6:ac:85:a2:

                    63:45:c7:72:27:cc:f4:4c:c6:75:71:d2:39:ef:4f:

                    42:f0:75:df:0a:90:c6:8e:20:6f:98:0f:f8:ac:23:

                    5f:70:29:36:a4:c9:86:e7:b1:9a:20:cb:53:a5:85:

                    e7:3d:be:7d:9a:fe:24:45:33:dc:76:15:ed:0f:a2:

                    71:64:4c:65:2e:81:68:45:a7

                Exponent: 65537 (0x10001)

    Signature Algorithm: md2WithRSAEncryption

        bb:4c:12:2b:cf:2c:26:00:4f:14:13:dd:a6:fb:fc:0a:11:84:

        8c:f3:28:1c:67:92:2f:7c:b6:c5:fa:df:f0:e8:95:bc:1d:8f:

        6c:2c:a8:51:cc:73:d8:a4:c0:53:f0:4e:d6:26:c0:76:01:57:

        81:92:5e:21:f1:d1:b1:ff:e7:d0:21:58:cd:69:17:e3:44:1c:

        9c:19:44:39:89:5c:dc:9c:00:0f:56:8d:02:99:ed:a2:90:45:

        4c:e4:bb:10:a4:3d:f0:32:03:0e:f1:ce:f8:e8:c9:51:8c:e6:

        62:9f:e6:9f:c0:7d:b7:72:9c:c9:36:3a:6b:9f:4e:a8:ff:64:

        0d:64

-----BEGIN CERTIFICATE-----

MIICPDCCAaUCEHC65B0Q2Sk0tjjKewPMur8wDQYJKoZIhvcNAQECBQAwXzELMAkG

A1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMTcwNQYDVQQLEy5DbGFz

cyAzIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MB4XDTk2

MDEyOTAwMDAwMFoXDTI4MDgwMTIzNTk1OVowXzELMAkGA1UEBhMCVVMxFzAVBgNV

BAoTDlZlcmlTaWduLCBJbmMuMTcwNQYDVQQLEy5DbGFzcyAzIFB1YmxpYyBQcmlt

YXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIGfMA0GCSqGSIb3DQEBAQUAA4GN

ADCBiQKBgQDJXFme8huKARS0EN8EQNvjV69qRUCPhAwL0TPZ2RHP7gJYHyX3KqhE

BarsAx94f56TuZoAqiN91qyFomNFx3InzPRMxnVx0jnvT0Lwdd8KkMaOIG+YD/is

I19wKTakyYbnsZogy1Olhec9vn2a/iRFM9x2Fe0PonFkTGUugWhFpwIDAQABMA0G

CSqGSIb3DQEBAgUAA4GBALtMEivPLCYATxQT3ab7/AoRhIzzKBxnki98tsX63/Do

lbwdj2wsqFHMc9ikwFPwTtYmwHYBV4GSXiHx0bH/59AhWM1pF+NEHJwZRDmJXNyc

AA9WjQKZ7aKQRUzkuxCkPfAyAw7xzvjoyVGM5mKf5p/AfbdynMk2OmufTqj/ZA1k

-----END CERTIFICATE----y,

Essentially, YUM is worthless - you cannot even do a "yum --help" - everything results in that error.

System time is set via ntp, so time and date are correct. Again, there are no differences (that I can find) between the working and nonworking machines. It just seems that the nonworking machines have decided not to function. It's completely odd, and of course there doesn't appear to be anyone else on the net who's run into this issue in the past 5 or 6 years, so I'm at a loss. Any ideas?

Attached is the output of running strace and yum makecache on one of the nonworking machines...

Thanks,

Randall

Comments
Locked Post
New comments cannot be posted to this locked post.
Post Details
Locked on Apr 20 2016
Added on Mar 19 2016
13 comments
6,190 views