SSH-Error - no updates possible


Message boards : Problems and bug reports : SSH-Error - no updates possible

Message board moderation

To post messages, you must log in.
AuthorMessage
Profile danwat1234

Send message
Joined: 28 May 25
Posts: 8
Credit: 170,652,213
RAC: 1,049,885
Message 9198 - Posted: 28 Sep 2025, 17:24:09 UTC - in response to Message 9197.  

Last modified: 28 Sep 2025, 18:03:01 UTC
Tested with 1 machine w BOINC 7.22.2 new cert file windows 10, was successful at uploading but some boxes still have error.
OK. So remoted into a windows 10 21h1 machine (ivybridge#4) with BOINC 7.16.20 , new crt file, would not upload. Updated BOINC to 7.22.2, did upload, even with OLD .crt it came with. Replaced with new .crt, still successful. Update to 7.22.2 is solution but why.
ID: 9198 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Profile danwat1234

Send message
Joined: 28 May 25
Posts: 8
Credit: 170,652,213
RAC: 1,049,885
Message 9199 - Posted: 28 Sep 2025, 18:42:36 UTC

Last modified: 28 Sep 2025, 18:43:24 UTC
Looks like BOINC 7.20 and newer uses Windows Trusted Root Certification Authorities store instead of local crt, YET it came with a crt. Newest crt on Github ( https://github.com/BOINC/boinc/blob/master/curl/ca-bundle.crt) and i assume same on BOINC page ( https://boinc.berkeley.edu/ca_bundle.php) yup same MD5 (06b9102fcb5931f1ecc87e898a4f89da) have issue with Asteroids.
Explains 7.20+ uses WTRCAS; https://boinc.berkeley.edu/forum_thread.php?id=14963

I think easiest 4 me is to abort my work and suspend project on farm until if need arises 4 more compute (u guys got it covered) rather than using WTRCAS of old Windows 10. all other projects are working fine. Linux issues, carry on! sorry 4 hijacking.
ID: 9199 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
karbonade
Avatar

Send message
Joined: 13 Jan 15
Posts: 5
Credit: 3,049,339
RAC: 3,421
Message 9200 - Posted: 28 Sep 2025, 19:23:24 UTC - in response to Message 9128.  

Last modified: 28 Sep 2025, 19:24:47 UTC
The server admin has to fix the secondary certificate issue on his side. Nothing can be done but wait it out.


Hi Keith, Is the server manager aware of this problem as far as you know?
ID: 9200 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
al.golm

Send message
Joined: 5 Dec 14
Posts: 6
Credit: 2,011,864
RAC: 5,425
Message 9201 - Posted: 28 Sep 2025, 20:10:05 UTC - in response to Message 9200.  
Look at https://asteroidsathome.net/boinc/forum_thread.php?id=1154&postid=9154
I have sent a PM asking if they are aware.
ID: 9201 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Profile Keith Myers
Avatar

Send message
Joined: 16 Nov 22
Posts: 185
Credit: 195,095,561
RAC: 42,309
Message 9203 - Posted: 29 Sep 2025, 0:04:49 UTC - in response to Message 9200.  
Asteroids app developer has tried to contact the server admin but has never received any response or acknowledgement of said contact. So no response from admin yet. So we continue to be stuck with no way to contact project, report tasks or request more without using the workaround. And no external stats site can show any stats either still of completed work or updated stats.

A proud member of the OFA (Old Farts Association)
ID: 9203 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
l008com

Send message
Joined: 8 Aug 13
Posts: 12
Credit: 4,212,210
RAC: 16,616
Message 9206 - Posted: 29 Sep 2025, 8:34:29 UTC
Trying to get a work-around working on my old Macos cruncher. I installed the cert but BOINC still can't connect.

Did I install the right cert?
I did the top one in this list: https://repo.harica.gr/rep_dyn.php

https://repo.harica.gr/certs/EACP-Root.pem
^
I'm still getting "transient HTTP error"
And "SSL peer certificate or SSH remote key was not OK"

I did add the cert correctly (as you do in macos) and then went back in and explicitly told keychain access to always trust the cert. In the keychain app, it went from red 'error' to blue 'ok'
ID: 9206 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Paul

Send message
Joined: 17 Nov 15
Posts: 20
Credit: 153,798
RAC: 4
Message 9207 - Posted: 29 Sep 2025, 8:53:42 UTC - in response to Message 9206.  
From earlier post in this thread you need the intermediate cert.
https://www.uni-muenster.de/CA/harica-rsa-server-2025.crt
Paul.
ID: 9207 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
rob

Send message
Joined: 28 Mar 13
Posts: 3
Credit: 5,001,852
RAC: 0
Message 9208 - Posted: 29 Sep 2025, 9:21:22 UTC - in response to Message 9203.  
Well, in the last hour or so something MAY have changed - I was able to upload and report fifteen task, which are now sitting awaiting validation.
ID: 9208 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
karbonade
Avatar

Send message
Joined: 13 Jan 15
Posts: 5
Credit: 3,049,339
RAC: 3,421
Message 9225 - Posted: 30 Sep 2025, 17:35:37 UTC

Last modified: 30 Sep 2025, 17:36:42 UTC
Yes, here to.
Since about 1 1/2 hour it seem to work. There where several WU's downloaded on my two Ubuntu's and they are running now. Very hopefully!
:-)
Good work!
ID: 9225 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Profile Conan
Avatar

Send message
Joined: 19 Jun 12
Posts: 36
Credit: 7,966,750
RAC: 21,702
Message 9226 - Posted: 1 Oct 2025, 1:33:16 UTC
No change here, still can't contact servers,

Transient HTTP error and certificate problems on 4 of my Linux machines.

One does work as it has a different Boinc Client version

it all worked up till the 17th of September then stopped.

Conan
ID: 9226 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Brummig
Avatar

Send message
Joined: 30 Jan 18
Posts: 17
Credit: 1,484,524
RAC: 252
Message 9227 - Posted: 1 Oct 2025, 10:52:25 UTC - in response to Message 9226.  

Last modified: 1 Oct 2025, 10:59:20 UTC
No change here, still can't contact servers,

Transient HTTP error and certificate problems on 4 of my Linux machines.

One does work as it has a different Boinc Client version

it all worked up till the 17th of September then stopped.

Conan

Same here.
I think this explains the problem:
https://asteroidsathome.net/boinc/forum_thread.php?id=1148&postid=9222
but I'm running the latest version in the repo, which is 7.16.
ID: 9227 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Ian&Steve C.
Volunteer developer
Volunteer tester
Avatar

Send message
Joined: 23 Apr 21
Posts: 125
Credit: 139,062,466
RAC: 256,633
Message 9228 - Posted: 1 Oct 2025, 11:57:07 UTC
add the gianfranco PPA and install a newer BOINC client.

even with some updated certs, you still have things like SSL versions that are compiled into the BOINC client and cant be added a la carte like the certs can be.

ID: 9228 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Profile Conan
Avatar

Send message
Joined: 19 Jun 12
Posts: 36
Credit: 7,966,750
RAC: 21,702
Message 9229 - Posted: 1 Oct 2025, 13:25:15 UTC
Why should we update BOINC when the old certificate (as of the 17th September 2025) worked fine with the BOINC versions I already have.

Can't that certificate be added back in? Then all would be fine as it was before

It is not going to be easy for me to upgrade the Berkeley installed versions I have.

I like the way it is installed (with the Berkeley installer), I don't like the distribution installed versions as they stick stuff everywhere and I lose direct control over the way things are installed and looked after.

Conan
ID: 9229 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Ian&Steve C.
Volunteer developer
Volunteer tester
Avatar

Send message
Joined: 23 Apr 21
Posts: 125
Credit: 139,062,466
RAC: 256,633
Message 9230 - Posted: 1 Oct 2025, 14:45:12 UTC - in response to Message 9229.  

Last modified: 1 Oct 2025, 14:54:23 UTC
I dont think it's going to be possible to explain all the intricacies of the certificates and how they work to satisfactorily answer your question.

the old cert expired it cant be used anymore.
using the new cert may need a newer version of SSL
SSL is compiled into BOINC, not a separate package.

you may need to bite the bullet and upgrade at this point. as other projects update their certificates you may start to see other projects requiring the same kind of updates eventually. Einstein just posted something about this yesterday.

you could always pull the code from their github, compile the client yourself and just replace the boinc client executable. leaving everything else in-place.

ID: 9230 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Brummig
Avatar

Send message
Joined: 30 Jan 18
Posts: 17
Credit: 1,484,524
RAC: 252
Message 9232 - Posted: 1 Oct 2025, 20:19:17 UTC

Last modified: 1 Oct 2025, 20:34:57 UTC
Problem solved for my old BOINC clients by following these instructions:
https://boinc.berkeley.edu/ca_bundle.php

I found the BOINC directory (/var/lib/boinc) contained a symlinked .crt file:
lrwxrwxrwx 1 boinc boinc 34 Jun 18  2019 ca-bundle.crt -> /etc/ssl/certs/ca-certificates.crt

I renamed it ca-bundle.crt.old before downloading the new bundle with wget:
sudo mv ca-bundle.crt ca-bundle.crt.old
sudo wget https://boinc.berkeley.edu/ca-bundle.crt
sudo chown boinc:boinc ca-bundle.crt

Then I restarted BOINC (by rebooting :)).
ID: 9232 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
StarCastle

Send message
Joined: 21 Jan 14
Posts: 12
Credit: 4,876,891
RAC: 1,057
Message 9234 - Posted: 1 Oct 2025, 21:31:07 UTC - in response to Message 9232.  
I can confirm that this worked on my systems as well.

Thanks!
ID: 9234 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Profile Conan
Avatar

Send message
Joined: 19 Jun 12
Posts: 36
Credit: 7,966,750
RAC: 21,702
Message 9237 - Posted: 2 Oct 2025, 1:51:30 UTC
Thanks Ian&Steve C. I will probably have to bite the bullet one day, just not today, I have been given a reprieve.

Thank you Brummig that link works a treat and I can now talk to Asteroids again

All 4 computers have now contacted the project.

Thanks to all

Conan
ID: 9237 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
l008com

Send message
Joined: 8 Aug 13
Posts: 12
Credit: 4,212,210
RAC: 16,616
Message 9363 - Posted: 9 Jan 2026, 9:51:04 UTC
I upgraded two lesser used computers to boinc 8.2.8 from I think 8.2.5 a week or two ago and they haven't been able to access the server since.

I just tried adding the certificate manually but that doesn't seem to work. These systems aren't that old either. Formerly I was only having trouble on older machines. These two are on Monterey and Ventura.

If I tried anything besides adding the cert to the system, I didn't write it down I guess because. Any tips to get this working again? I have a bunch of completed work thats already expired :(
ID: 9363 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
l008com

Send message
Joined: 8 Aug 13
Posts: 12
Credit: 4,212,210
RAC: 16,616
Message 9368 - Posted: 13 Jan 2026, 7:58:23 UTC
Downgrading back to 8.2.5 fixed the problem for me.
ID: 9368 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
ahorek's team
Volunteer developer
Volunteer tester

Send message
Joined: 1 Jan 13
Posts: 170
Credit: 15,656,490
RAC: 19,228
Message 9369 - Posted: 13 Jan 2026, 11:29:16 UTC
BOINC should use system certificates since version 7.20.0
https://github.com/BOINC/boinc/commit/85b9494d96161cd0800efb6c254b3a4573df860b

If reverting from 8.2.8 to 8.2.5 resolves the problem and the website is accessible from a web browser, then the issue is likely within BOINC (macOS version) and should be addressed there.

There was a recent change in BOINC 8.2.6 that may have caused the issue https://github.com/BOINC/boinc/commit/420ba06465e16510a5f8a320718d70601f8ed308
ID: 9369 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote

Message boards : Problems and bug reports : SSH-Error - no updates possible