Bonjour Jean-Michel,
> This is solved and it was tricky. The CRLs are on an NFS shared area
> and they are updated from one single machine.
>
> What happened is that I changed the server responsible for performing
> the updates and it resulted in a change in the hashes names for the
> symlinks. Thus, I had a double set of symlinks : the old ones and the
> new ones. It seems that the old symlinks were used by the test jobs.
>
> Deleting all old symlinks solves the issue.
I am not convinced that this actually explains the matter.
Note that it is normal for every CA to appear with _two_ hashes and
therefore _two_ CRL files, viz. one for OpenSSL >= 1.0 and one for
OpenSSL < 1.0. For example:
-----------------------------------------------------------------------------
lrwxrwxrwx. 1 root root 17 Jul 2 20:01 585d9326.0 -> CNRS2-Grid-FR.pem
lrwxrwxrwx. 1 root root 24 Jul 2 20:01 585d9326.namespaces ->
CNRS2-Grid-FR.namespaces
-rw-r--r--. 1 root root 5828 Sep 23 12:43 585d9326.r0
lrwxrwxrwx. 1 root root 28 Jul 2 20:01 585d9326.signing_policy ->
CNRS2-Grid-FR.signing_policy
-rw-r--r--. 1 root root 49 Jun 23 17:56 CNRS2-Grid-FR.crl_url
-rw-r--r--. 1 root root 359 Jun 23 17:56 CNRS2-Grid-FR.info
-rw-r--r--. 1 root root 423 Jun 23 17:56 CNRS2-Grid-FR.namespaces
-rw-r--r--. 1 root root 1363 Jun 23 17:56 CNRS2-Grid-FR.pem
-rw-r--r--. 1 root root 207 Jun 23 17:56 CNRS2-Grid-FR.signing_policy
lrwxrwxrwx. 1 root root 17 Jul 2 20:01 d11f973e.0 -> CNRS2-Grid-FR.pem
lrwxrwxrwx. 1 root root 24 Jul 2 20:01 d11f973e.namespaces ->
CNRS2-Grid-FR.namespaces
-rw-r--r--. 1 root root 5828 Sep 23 12:43 d11f973e.r0
lrwxrwxrwx. 1 root root 28 Jul 2 20:01 d11f973e.signing_policy ->
CNRS2-Grid-FR.signing_policy
-----------------------------------------------------------------------------
These days we mostly rely on OpenSSL >= 1.0, i.e. only half of them are used.
|