Idk what happened here, or if it is SweeNet or just ZNC

For some reason *status in SweeNet dumped the certificate on the 4th of february.


07:11 PM <*status> Disconnected from IRC. Reconnecting...
07:12 PM <*status> Connected!
07:17 PM <*status> Disconnected from IRC. Reconnecting...
07:19 PM <*status> |Certificate:
07:19 PM <*status> Disconnected from IRC (Invalid SSL certificate: unable to get local issuer certificate, unable to verify the first certificate). Reconnecting...
07:19 PM <*status> |        Version: 3 (0x2)
07:19 PM <*status> |    Data:
07:19 PM <*status> |            04:ca:c2:73:18:2b:ac:06:1f:01:f3:14:7e:ac:a0:ce:69:d9
07:19 PM <*status> |        Serial Number:
07:19 PM <*status> |            Not Before: Jan 31 06:55:04 2025 GMT
07:19 PM <*status> |        Validity
07:19 PM <*status> |        Issuer: C=US, O=Let's Encrypt, CN=E5
07:19 PM <*status> |        Signature Algorithm: ecdsa-with-SHA384
07:19 PM <*status> |            Public Key Algorithm: id-ecPublicKey
07:19 PM <*status> |        Subject Public Key Info:
07:19 PM <*status> |        Subject: CN=*.ircat.xyz
07:19 PM <*status> |            Not After : May  1 06:55:03 2025 GMT
07:19 PM <*status> |                    fd:b0:05:8f:01
07:19 PM <*status> |                    98:32:6b:1a:ee:49:a3:5c:c5:72:4e:3e:59:9f:3a:
07:19 PM <*status> |                    c8:52:3a:b6:68:ff:4f:b3:1c:5b:1b:69:65:05:bf:
07:19 PM <*status> |                    e7:7e:3c:df:37:5e:b8:87:6f:90:85:3e:3b:09:11:
07:19 PM <*status> |                    04:76:b7:11:eb:6c:ed:e8:9a:af:72:ef:02:ca:0d:
07:19 PM <*status> |                pub:
07:19 PM <*status> |                Public-Key: (256 bit)
07:19 PM <*status> |        X509v3 extensions:
07:19 PM <*status> |                NIST CURVE: P-256
07:19 PM <*status> |                ASN1 OID: prime256v1
07:19 PM <*status> |            X509v3 Subject Key Identifier: 
07:19 PM <*status> |                CA:FALSE
07:19 PM <*status> |            X509v3 Basic Constraints: critical
07:19 PM <*status> |                TLS Web Server Authentication, TLS Web Client Authentication
07:19 PM <*status> |            X509v3 Extended Key Usage: 
07:19 PM <*status> |                Digital Signature
07:19 PM <*status> |            X509v3 Key Usage: critical
07:19 PM <*status> |            X509v3 Authority Key Identifier: 
07:19 PM <*status> |                AE:83:89:1A:E4:01:DD:5C:54:02:FF:BE:18:2F:4B:92:0D:01:86:E7
07:19 PM <*status> |                Policy: 2.23.140.1.2.1
07:19 PM <*status> |            X509v3 Certificate Policies: 
07:19 PM <*status> |                DNS:*.ircat.xyz
07:19 PM <*status> |            X509v3 Subject Alternative Name: 
07:19 PM <*status> |                CA Issuers - URI:http://e5.i.lencr.org/
07:19 PM <*status> |                OCSP - URI:http://e5.o.lencr.org
07:19 PM <*status> |            Authority Information Access: 
07:19 PM <*status> |                9F:2B:5F:CF:3C:21:4F:9D:04:B7:ED:2B:2C:C4:C6:70:8B:D2:D7:0D
07:19 PM <*status> |                    Timestamp : Jan 31 07:53:34.692 2025 GMT
07:19 PM <*status> |                                87:5C:14:A0:4E:95:9E:B9:03:2F:D9:0E:8C:2E:79:B8
07:19 PM <*status> |                    Log ID    : 7D:59:1E:12:E1:78:2A:7B:1C:61:67:7C:5E:FD:F8:D0:
07:19 PM <*status> |                    Version   : v1 (0x0)
07:19 PM <*status> |                Signed Certificate Timestamp:
07:19 PM <*status> |            CT Precertificate SCTs: 
07:19 PM <*status> |                Signed Certificate Timestamp:
07:19 PM <*status> |                                EB:31:5A:C1:B7:58
07:19 PM <*status> |                                26:63:C0:65:F9:02:B2:D9:5A:4B:1C:CD:83:15:E5:B3:
07:19 PM <*status> |                                68:47:C9:57:02:20:7F:87:B3:B2:12:6F:B2:19:DA:EB:
07:19 PM <*status> |                                5B:A7:CF:A2:11:EA:7B:B3:87:41:D6:99:40:65:CF:58:
07:19 PM <*status> |                                30:44:02:20:2D:FF:BC:A7:25:E2:15:67:87:C3:EB:99:
07:19 PM <*status> |                    Signature : ecdsa-with-SHA256
07:19 PM <*status> |                    Extensions: none
07:19 PM <*status> |                                30:44:02:20:79:20:D7:6D:07:D0:4F:70:95:10:66:55:
07:19 PM <*status> |                    Signature : ecdsa-with-SHA256
07:19 PM <*status> |                    Extensions: none
07:19 PM <*status> |                    Timestamp : Jan 31 07:53:34.882 2025 GMT
07:19 PM <*status> |                                16:B7:23:49:CE:58:57:6A:DF:AE:DA:A7:C2:AB:E0:22
07:19 PM <*status> |                    Log ID    : 13:4A:DF:1A:B5:98:42:09:78:0C:6F:EF:4C:7A:91:A4:
07:19 PM <*status> |                    Version   : v1 (0x0)
07:19 PM <*status> |        30:65:02:30:6c:c5:08:42:5b:ae:02:27:e5:90:a2:3f:7e:96:
07:19 PM <*status> |    Signature Value:
07:19 PM <*status> |    Signature Algorithm: ecdsa-with-SHA384
07:19 PM <*status> |                                00:6C:31:9A:A1:A6
07:19 PM <*status> |                                5D:15:80:21:CE:2A:FD:03:80:B0:A1:8E:24:CE:5A:F9:
07:19 PM <*status> |                                E3:BF:1A:EC:02:20:1C:04:2E:17:2E:23:EE:E3:24:6A:
07:19 PM <*status> |                                8D:1A:50:04:00:20:1B:4A:53:C3:3E:A9:B2:B4:A9:2F:
07:19 PM <*status> |        5c:43:60:4a:4a:1b:df:75:d6:89:29:9b:2e
07:19 PM <*status> |        84:93:7f:f2:b3:c0:86:cb:6a:df:dc:8f:b5:67:9a:5d:63:90:
07:19 PM <*status> |        00:e5:87:ea:53:c6:c3:bf:ad:6d:b6:93:e0:d6:a9:73:7c:be:
07:19 PM <*status> |        a0:92:7e:82:06:0e:5f:bd:1b:db:7d:91:58:85:a6:8b:02:31:
07:19 PM <*status> |        f6:6f:b4:65:eb:05:3b:e4:a7:90:09:90:bf:29:af:9f:35:29:
07:19 PM <*status> If you trust this certificate, do /znc AddTrustedServerFingerprint 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34
07:19 PM <*status> SHA-256: 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34
07:19 PM <*status> SHA1: 21:2f:0f:67:89:4d:be:c2:99:55:0b:d2:45:03:14:d1:10:0e:ab:fd
07:19 PM <*status> Disconnected from IRC. Reconnecting...
07:22 PM <*status> |Certificate:
07:22 PM <*status> Disconnected from IRC (Invalid SSL certificate: unable to get local issuer certificate, unable to verify the first certificate). Reconnecting...
07:22 PM <*status> |        Serial Number:
07:22 PM <*status> |        Version: 3 (0x2)
07:22 PM <*status> |    Data:
07:22 PM <*status> |            04:ca:c2:73:18:2b:ac:06:1f:01:f3:14:7e:ac:a0:ce:69:d9
07:22 PM <*status> |            Not After : May  1 06:55:03 2025 GMT
07:22 PM <*status> |            Not Before: Jan 31 06:55:04 2025 GMT
07:22 PM <*status> |        Validity
07:22 PM <*status> |        Issuer: C=US, O=Let's Encrypt, CN=E5
07:22 PM <*status> |        Signature Algorithm: ecdsa-with-SHA384
07:22 PM <*status> |                Public-Key: (256 bit)
07:22 PM <*status> |            Public Key Algorithm: id-ecPublicKey
07:22 PM <*status> |        Subject Public Key Info:
07:22 PM <*status> |        Subject: CN=*.ircat.xyz
07:22 PM <*status> |                    04:76:b7:11:eb:6c:ed:e8:9a:af:72:ef:02:ca:0d:
07:22 PM <*status> |                pub:
07:22 PM <*status> |                NIST CURVE: P-256
07:22 PM <*status> |                ASN1 OID: prime256v1
07:22 PM <*status> |                    fd:b0:05:8f:01
07:22 PM <*status> |                    98:32:6b:1a:ee:49:a3:5c:c5:72:4e:3e:59:9f:3a:
07:22 PM <*status> |                    c8:52:3a:b6:68:ff:4f:b3:1c:5b:1b:69:65:05:bf:
07:22 PM <*status> |                    e7:7e:3c:df:37:5e:b8:87:6f:90:85:3e:3b:09:11:
07:22 PM <*status> |                Digital Signature
07:22 PM <*status> |            X509v3 Key Usage: critical
07:22 PM <*status> |        X509v3 extensions:
07:22 PM <*status> |            X509v3 Subject Key Identifier: 
07:22 PM <*status> |                CA:FALSE
07:22 PM <*status> |            X509v3 Basic Constraints: critical
07:22 PM <*status> |                TLS Web Server Authentication, TLS Web Client Authentication
07:22 PM <*status> |            X509v3 Extended Key Usage: 
07:22 PM <*status> |                CA Issuers - URI:http://e5.i.lencr.org/
07:22 PM <*status> |                OCSP - URI:http://e5.o.lencr.org
07:22 PM <*status> |            Authority Information Access: 
07:22 PM <*status> |                9F:2B:5F:CF:3C:21:4F:9D:04:B7:ED:2B:2C:C4:C6:70:8B:D2:D7:0D
07:22 PM <*status> |            X509v3 Authority Key Identifier: 
07:22 PM <*status> |                AE:83:89:1A:E4:01:DD:5C:54:02:FF:BE:18:2F:4B:92:0D:01:86:E7
07:22 PM <*status> |            CT Precertificate SCTs: 
07:22 PM <*status> |                Policy: 2.23.140.1.2.1
07:22 PM <*status> |            X509v3 Certificate Policies: 
07:22 PM <*status> |                DNS:*.ircat.xyz
07:22 PM <*status> |            X509v3 Subject Alternative Name: 
07:22 PM <*status> |                    Timestamp : Jan 31 07:53:34.692 2025 GMT
07:22 PM <*status> |                                87:5C:14:A0:4E:95:9E:B9:03:2F:D9:0E:8C:2E:79:B8
07:22 PM <*status> |                    Log ID    : 7D:59:1E:12:E1:78:2A:7B:1C:61:67:7C:5E:FD:F8:D0:
07:22 PM <*status> |                    Version   : v1 (0x0)
07:22 PM <*status> |                Signed Certificate Timestamp:
07:22 PM <*status> |                                68:47:C9:57:02:20:7F:87:B3:B2:12:6F:B2:19:DA:EB:
07:22 PM <*status> |                                5B:A7:CF:A2:11:EA:7B:B3:87:41:D6:99:40:65:CF:58:
07:22 PM <*status> |                                30:44:02:20:2D:FF:BC:A7:25:E2:15:67:87:C3:EB:99:
07:22 PM <*status> |                    Signature : ecdsa-with-SHA256
07:22 PM <*status> |                    Extensions: none
07:22 PM <*status> |                    Log ID    : 13:4A:DF:1A:B5:98:42:09:78:0C:6F:EF:4C:7A:91:A4:
07:22 PM <*status> |                    Version   : v1 (0x0)
07:22 PM <*status> |                Signed Certificate Timestamp:
07:22 PM <*status> |                                EB:31:5A:C1:B7:58
07:22 PM <*status> |                                26:63:C0:65:F9:02:B2:D9:5A:4B:1C:CD:83:15:E5:B3:
07:22 PM <*status> |                                30:44:02:20:79:20:D7:6D:07:D0:4F:70:95:10:66:55:
07:22 PM <*status> |                    Signature : ecdsa-with-SHA256
07:22 PM <*status> |                    Extensions: none
07:22 PM <*status> |                    Timestamp : Jan 31 07:53:34.882 2025 GMT
07:22 PM <*status> |                                16:B7:23:49:CE:58:57:6A:DF:AE:DA:A7:C2:AB:E0:22
07:22 PM <*status> |                                5D:15:80:21:CE:2A:FD:03:80:B0:A1:8E:24:CE:5A:F9:
07:22 PM <*status> |                                E3:BF:1A:EC:02:20:1C:04:2E:17:2E:23:EE:E3:24:6A:
07:22 PM <*status> |                                8D:1A:50:04:00:20:1B:4A:53:C3:3E:A9:B2:B4:A9:2F:
07:22 PM <*status> |        f6:6f:b4:65:eb:05:3b:e4:a7:90:09:90:bf:29:af:9f:35:29:
07:22 PM <*status> |        30:65:02:30:6c:c5:08:42:5b:ae:02:27:e5:90:a2:3f:7e:96:
07:22 PM <*status> |    Signature Value:
07:22 PM <*status> |    Signature Algorithm: ecdsa-with-SHA384
07:22 PM <*status> |                                00:6C:31:9A:A1:A6
07:22 PM <*status> SHA1: 21:2f:0f:67:89:4d:be:c2:99:55:0b:d2:45:03:14:d1:10:0e:ab:fd
07:22 PM <*status> |        5c:43:60:4a:4a:1b:df:75:d6:89:29:9b:2e
07:22 PM <*status> |        84:93:7f:f2:b3:c0:86:cb:6a:df:dc:8f:b5:67:9a:5d:63:90:
07:22 PM <*status> |        00:e5:87:ea:53:c6:c3:bf:ad:6d:b6:93:e0:d6:a9:73:7c:be:
07:22 PM <*status> |        a0:92:7e:82:06:0e:5f:bd:1b:db:7d:91:58:85:a6:8b:02:31:
07:22 PM <*status> If you trust this certificate, do /znc AddTrustedServerFingerprint 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34
07:22 PM <*status> SHA-256: 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34
07:22 PM <*status> Disconnected from IRC. Reconnecting...
07:25 PM <*status> Disconnected from IRC (Invalid SSL certificate: unable to get local issuer certificate, unable to verify the first certificate). Reconnecting...
07:25 PM <*status> |        Version: 3 (0x2)
07:25 PM <*status> |    Data:
07:25 PM <*status> |Certificate:
07:25 PM <*status> |            Not After : May  1 06:55:03 2025 GMT
07:25 PM <*status> |            Not Before: Jan 31 06:55:04 2025 GMT
07:25 PM <*status> |        Validity
07:25 PM <*status> |        Issuer: C=US, O=Let's Encrypt, CN=E5
07:25 PM <*status> |        Signature Algorithm: ecdsa-with-SHA384
07:25 PM <*status> |            04:ca:c2:73:18:2b:ac:06:1f:01:f3:14:7e:ac:a0:ce:69:d9
07:25 PM <*status> |        Serial Number:
07:25 PM <*status> |                    c8:52:3a:b6:68:ff:4f:b3:1c:5b:1b:69:65:05:bf:
07:25 PM <*status> |                    e7:7e:3c:df:37:5e:b8:87:6f:90:85:3e:3b:09:11:
07:25 PM <*status> |                    04:76:b7:11:eb:6c:ed:e8:9a:af:72:ef:02:ca:0d:
07:25 PM <*status> |                pub:
07:25 PM <*status> |                Public-Key: (256 bit)
07:25 PM <*status> |            Public Key Algorithm: id-ecPublicKey
07:25 PM <*status> |        Subject Public Key Info:
07:25 PM <*status> |        Subject: CN=*.ircat.xyz
07:25 PM <*status> |                ASN1 OID: prime256v1
07:25 PM <*status> |                    fd:b0:05:8f:01
07:25 PM <*status> |                    98:32:6b:1a:ee:49:a3:5c:c5:72:4e:3e:59:9f:3a:
07:25 PM <*status> |            X509v3 Extended Key Usage: 
07:25 PM <*status> |                Digital Signature
07:25 PM <*status> |            X509v3 Key Usage: critical
07:25 PM <*status> |        X509v3 extensions:
07:25 PM <*status> |                NIST CURVE: P-256
07:25 PM <*status> |                CA:FALSE
07:25 PM <*status> |            X509v3 Basic Constraints: critical
07:25 PM <*status> |                TLS Web Server Authentication, TLS Web Client Authentication
07:25 PM <*status> |                CA Issuers - URI:http://e5.i.lencr.org/
07:25 PM <*status> |                OCSP - URI:http://e5.o.lencr.org
07:25 PM <*status> |            Authority Information Access: 
07:25 PM <*status> |                9F:2B:5F:CF:3C:21:4F:9D:04:B7:ED:2B:2C:C4:C6:70:8B:D2:D7:0D
07:25 PM <*status> |            X509v3 Authority Key Identifier: 
07:25 PM <*status> |                AE:83:89:1A:E4:01:DD:5C:54:02:FF:BE:18:2F:4B:92:0D:01:86:E7
07:25 PM <*status> |            X509v3 Subject Key Identifier: 
07:25 PM <*status> |                Policy: 2.23.140.1.2.1
07:25 PM <*status> |            X509v3 Certificate Policies: 
07:25 PM <*status> |                DNS:*.ircat.xyz
07:25 PM <*status> |            X509v3 Subject Alternative Name: 
07:25 PM <*status> |                    Timestamp : Jan 31 07:53:34.692 2025 GMT
07:25 PM <*status> |                                87:5C:14:A0:4E:95:9E:B9:03:2F:D9:0E:8C:2E:79:B8
07:25 PM <*status> |                    Log ID    : 7D:59:1E:12:E1:78:2A:7B:1C:61:67:7C:5E:FD:F8:D0:
07:25 PM <*status> |                    Version   : v1 (0x0)
07:25 PM <*status> |                Signed Certificate Timestamp:
07:25 PM <*status> |            CT Precertificate SCTs: 
07:25 PM <*status> |                Signed Certificate Timestamp:
07:25 PM <*status> |                                EB:31:5A:C1:B7:58
07:25 PM <*status> |                                26:63:C0:65:F9:02:B2:D9:5A:4B:1C:CD:83:15:E5:B3:
07:25 PM <*status> |                                68:47:C9:57:02:20:7F:87:B3:B2:12:6F:B2:19:DA:EB:
07:25 PM <*status> |                                5B:A7:CF:A2:11:EA:7B:B3:87:41:D6:99:40:65:CF:58:
07:25 PM <*status> |                                30:44:02:20:2D:FF:BC:A7:25:E2:15:67:87:C3:EB:99:
07:25 PM <*status> |                    Signature : ecdsa-with-SHA256
07:25 PM <*status> |                    Extensions: none
07:25 PM <*status> |                                30:44:02:20:79:20:D7:6D:07:D0:4F:70:95:10:66:55:
07:25 PM <*status> |                    Signature : ecdsa-with-SHA256
07:25 PM <*status> |                    Extensions: none
07:25 PM <*status> |                    Timestamp : Jan 31 07:53:34.882 2025 GMT
07:25 PM <*status> |                                16:B7:23:49:CE:58:57:6A:DF:AE:DA:A7:C2:AB:E0:22
07:25 PM <*status> |                    Log ID    : 13:4A:DF:1A:B5:98:42:09:78:0C:6F:EF:4C:7A:91:A4:
07:25 PM <*status> |                    Version   : v1 (0x0)
07:25 PM <*status> |    Signature Value:
07:25 PM <*status> |    Signature Algorithm: ecdsa-with-SHA384
07:25 PM <*status> |                                00:6C:31:9A:A1:A6
07:25 PM <*status> |                                5D:15:80:21:CE:2A:FD:03:80:B0:A1:8E:24:CE:5A:F9:
07:25 PM <*status> |                                E3:BF:1A:EC:02:20:1C:04:2E:17:2E:23:EE:E3:24:6A:
07:25 PM <*status> |                                8D:1A:50:04:00:20:1B:4A:53:C3:3E:A9:B2:B4:A9:2F:
07:25 PM <*status> |        5c:43:60:4a:4a:1b:df:75:d6:89:29:9b:2e
07:25 PM <*status> |        84:93:7f:f2:b3:c0:86:cb:6a:df:dc:8f:b5:67:9a:5d:63:90:
07:25 PM <*status> |        00:e5:87:ea:53:c6:c3:bf:ad:6d:b6:93:e0:d6:a9:73:7c:be:
07:25 PM <*status> |        a0:92:7e:82:06:0e:5f:bd:1b:db:7d:91:58:85:a6:8b:02:31:
07:25 PM <*status> |        f6:6f:b4:65:eb:05:3b:e4:a7:90:09:90:bf:29:af:9f:35:29:
07:25 PM <*status> |        30:65:02:30:6c:c5:08:42:5b:ae:02:27:e5:90:a2:3f:7e:96:
07:25 PM <*status> SHA-256: 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34
07:25 PM <*status> SHA1: 21:2f:0f:67:89:4d:be:c2:99:55:0b:d2:45:03:14:d1:10:0e:ab:fd
07:25 PM <*status> If you trust this certificate, do /znc AddTrustedServerFingerprint 33:fa:4c:74:3c:ee:f5:78:79:26:ee:08:1c:ee:bd:87:56:81:5b:9e:a4:89:4b:93:68:8d:eb:c4:1c:a5:80:34
07:25 PM <*status> Disconnected from IRC. Reconnecting...
07:28 PM <*status> Connected!
07:52 PM <*status> Disconnected from IRC. Reconnecting...
07:54 PM <*status> Connected!

I cannot understand why. and it’s only in SweeNet that it happened.

Hi @Depresst0

This error was when I was migrating the built in ssl module to PyOpenSSL, (I have reverted that change recently)

I accidentally made OpenSSL load the certificate chain as a certificate file instead of chain

This problem was not reported here since it required only a small patch.

Ref: Commit 6577098a60