New f/w build 53396, but inaccessible using easyddup script

Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware
Author Message
ArjenR49
DD-WRT Guru


Joined: 05 Oct 2008
Posts: 646
Location: Helsinki, Finland / nr. Alkmaar, Netherlands

PostPosted: Mon Aug 21, 2023 13:36    Post subject: New f/w build 53396, but inaccessible using easyddup script Reply with quote
Error message:
root@XR500:/opt/easyddup# easyddup.sh
curlerror=60
Something went wrong getting the online build list for year 2023.
...

Other ways of downloading probably work again after the certificate expired yesterday.

I have no clue as to who can/could/should do what to make easyddup/curl work with the new certificate.
My remote router, which is in use, but otherwise left alone for over a month now, shows the same error.
Sponsor
IONK
DD-WRT Guru


Joined: 19 Aug 2011
Posts: 893

PostPosted: Mon Aug 21, 2023 14:18    Post subject: Re: New f/w build 53396, but inaccessible using easyddup scr Reply with quote
ArjenR49 wrote:
I have no clue as to who can/could/should do what to make easyddup/curl work with the new certificate.
the people in charge are already informed https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=334994
Options:
a) wait till new cert is up,
b) manually upgrade the firmware now using the traditional ways.

_________________
▫ RSS feed for DD-WRT releases (2023): https://politepol.com/fd/bdQnjdZgyaln
easyddup - A simple upgrade/downgrade utility by yoyoma2 --- as featured in 📌 List of reference threads, how-tos, and otherwise (Moderator's Pick 🌟)
ArjenR49
DD-WRT Guru


Joined: 05 Oct 2008
Posts: 646
Location: Helsinki, Finland / nr. Alkmaar, Netherlands

PostPosted: Mon Aug 21, 2023 15:03    Post subject: Reply with quote
The traditional access through a web page was also broken yesterday, but not anymore. Something was already done. Which made me think that perhaps I need to do something, top. Other than just wait.
Thanks.
IONK
DD-WRT Guru


Joined: 19 Aug 2011
Posts: 893

PostPosted: Mon Aug 21, 2023 15:09    Post subject: Reply with quote
ArjenR49 wrote:
The traditional access through a web page was also broken yesterday, but not anymore. Something was already done. Which made me think that perhaps I need to do something, top. Other than just wait.
Thanks.
sorry I forgot that most web browsers would not allow you to proceed with https if the cert expired. Workarounds are http or ftp.
_________________
▫ RSS feed for DD-WRT releases (2023): https://politepol.com/fd/bdQnjdZgyaln
easyddup - A simple upgrade/downgrade utility by yoyoma2 --- as featured in 📌 List of reference threads, how-tos, and otherwise (Moderator's Pick 🌟)
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1636

PostPosted: Mon Aug 21, 2023 15:41    Post subject: Reply with quote
Doesn't appear as if anything was done here. Trying to access with https fails, but http works:

http://ftp.dd-wrt.com/dd-wrtv2/downloads/betas/

http://download1.dd-wrt.com/dd-wrtv2/downloads/betas/

So much for all the bitching about having secure download options.

#4700 Use a more secure protocol for downloading DD-WRT images

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
ArjenR49
DD-WRT Guru


Joined: 05 Oct 2008
Posts: 646
Location: Helsinki, Finland / nr. Alkmaar, Netherlands

PostPosted: Mon Aug 21, 2023 20:09    Post subject: Reply with quote
The traditional access through a web page was also broken yesterday, but not anymore. Something was already done. Which made me think that perhaps I need to do something, top. Other than just wait.
Thanks.
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1636

PostPosted: Mon Aug 21, 2023 21:30    Post subject: Reply with quote
At the time of my previous post, using https:// did *NOT* allow the usual bypass which now does work (proceed to sitename (unsafe) in chrome), as I've just tested just now. Maybe your experience was different, maybe it was a cache problem on my end, maybe the "workaround" to proceed to http is what was fixed. Arguing about the semantics and details never solves anything.
_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
ramblin
DD-WRT User


Joined: 03 Nov 2015
Posts: 313
Location: Florida, USA

PostPosted: Tue Aug 22, 2023 19:42    Post subject: Reply with quote
dale_gribble39 wrote:
At the time of my previous post, using https:// did *NOT* allow the usual bypass which now does work (proceed to sitename (unsafe) in chrome), as I've just tested just now.


I updated yesterday and Debian11/Firefox and Win10/Edge both thru up the unsafe/certificate flags, but both allowed me to continue and download.

_________________
......All GOOD here... Just Handshakes and Time Stamps !......
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 13883
Location: Texas, USA

PostPosted: Tue Aug 22, 2023 20:07    Post subject: Reply with quote
Not all browsers react the same. For example, SRWare Iron (JUST NOW):

Quote:
Your connection is not private
Attackers might be trying to steal your information from download1.dd-wrt.com (for example, passwords, messages, or credit cards). Learn more
NET::ERR_CERT_DATE_INVALID
download1.dd-wrt.com normally uses encryption to protect your information. When Chromium tried to connect to download1.dd-wrt.com this time, the website sent back unusual and incorrect credentials. This may happen when an attacker is trying to pretend to be download1.dd-wrt.com, or a Wi-Fi sign-in screen has interrupted the connection. Your information is still secure because Chromium stopped the connection before any data was exchanged.

You cannot visit download1.dd-wrt.com right now because the website uses HSTS. Network errors and attacks are usually temporary, so this page will probably work later.

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
yoyoma2
DD-WRT User


Joined: 24 Sep 2016
Posts: 358

PostPosted: Wed Aug 23, 2023 5:11    Post subject: Reply with quote
The url easyddup uses first is the following and at the time of posting it still has a certificate error causing easyddup to fail.

https://download1.dd-wrt.com/dd-wrtv2/downloads/betas/2023/

There is a secondary url that the gui uses that easyddup will fall back to for certain specific errors but apparently not for certificate errors. I could release a new version that works around this certificate error but hopefully the server will be fixed and stop generating certificate errors.
yoyoma2
DD-WRT User


Joined: 24 Sep 2016
Posts: 358

PostPosted: Wed Aug 23, 2023 17:10    Post subject: Reply with quote
ArjenR49 wrote:
The traditional access through a web page was also broken yesterday, but not anymore. Something was already done.

Yes something incomplete must have been done but the primary url (posted above) used by easyddup is still failing.

I posted a new version in the sticky easyddup thread in "Contributions Upload" to work around this issue using a new setting in easyddup.ini so take a look. Posting in that thread or a PM has a better chance of getting my attention than starting a new thread.
ArjenR49
DD-WRT Guru


Joined: 05 Oct 2008
Posts: 646
Location: Helsinki, Finland / nr. Alkmaar, Netherlands

PostPosted: Fri Aug 25, 2023 11:52    Post subject: Reply with quote
This latest update of easyddup to 0.9.3 is very welcome since the certificate problem seems to persist.
While we're waiting for the certificate to be renewed, the new option is, of course, just another way of circumventing the security certificate having expired.

See the thread under Contributions Upload.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum