<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>16077</bug_id>
          
          <creation_ts>2025-11-26 12:47:00 +0000</creation_ts>
          <short_desc>opkg in SDK fails to validate server certificates</short_desc>
          <delta_ts>2025-12-22 10:32:19 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>oe-core other</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium+</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>5.0.15</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Moritz Haase">Moritz.Haase</reporter>
          <assigned_to name="Moritz Haase">Moritz.Haase</assigned_to>
          <cc>randy.macleod</cc>
    
    <cc>steve</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Don&apos;t know</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>103378</commentid>
    <comment_count>0</comment_count>
    <who name="Moritz Haase">Moritz.Haase</who>
    <bug_when>2025-11-26 12:47:00 +0000</bug_when>
    <thetext>Change https://git.openembedded.org/openembedded-core/commit/?id=4909a46e93ba774c960c3d3c277e2a669af3fea6 (or more specifically, it&apos;s backport to Scarthgap) has broken opkg in the SDK for us: It now fails to download
packages via HTTPS (from a server with a &quot;proper&quot; certificate from a public CA),
reporting:

&gt; SSL certificate problem: self-signed certificate in certificate chain

It looks like the env variables set by [0] and others like &apos;SSL_CERT_(DIR|FILE)&apos;
(see [1]) are only taken into account by curl on the command line (see [2]), but
not by libcurl, which opkg uses. Removing the default CA bundle option from the
build now means that libcurl doesn&apos;t have any CA certificates to verify against
unless explicitly configured (previously it was using &apos;ca-certificates.crt&apos;
shipped by the SDK). Since opkg doesn&apos;t have any env var handling built-in,
it ends up without a CA bundle and fails to verify certificates.

Based on a discussion on the mailing list, the workaround suggested in [3] seems to be the best course of action to fix this and still respect host settings. It&apos;d mean that there is a sensible default of using the host system&apos;s bundle for verification for all programs using libcurl (unless they implement their own override mechanisms).

[0]: https://git.openembedded.org/openembedded-core/tree/meta/recipes-support/curl/curl/environment.d-curl.sh
[1]: https://git.openembedded.org/openembedded-core/tree/meta/recipes-connectivity/openssl/files/environment.d-openssl.sh
[2]: https://github.com/curl/curl/blob/de7b3e89218467159a7af72d58cea8425946e97d/src/tool_operate.c#L2586-L2623
[3]: https://lists.openembedded.org/g/openembedded-core/topic/115993530#msg226756</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103379</commentid>
    <comment_count>1</comment_count>
    <who name="Moritz Haase">Moritz.Haase</who>
    <bug_when>2025-11-26 12:47:39 +0000</bug_when>
    <thetext>I&apos;m currently preparing a patch with the aforementioned fix for submission to the mailing list.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103429</commentid>
    <comment_count>2</comment_count>
    <who name="Moritz Haase">Moritz.Haase</who>
    <bug_when>2025-11-28 06:25:11 +0000</bug_when>
    <thetext>Patch has been submitted to the mailing list for &apos;master&apos;: https://patchwork.yoctoproject.org/project/oe-core/patch/20251127103129.2564918-1-Moritz.Haase@bmw.de/</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103459</commentid>
    <comment_count>3</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2025-12-02 19:43:15 +0000</bug_when>
    <thetext>Merged so resolving:
   https://git.openembedded.org/openembedded-core/commit/?id=545e43a7a45be02fda8fc3af69faa20e889f58c4

❯ git branch -a --contains 545e43a7a45be02fda8fc3af69faa20e889f58c4
* master
  remotes/origin/HEAD -&gt; origin/master
  remotes/origin/master
  remotes/origin/master-next

Thanks Moritz!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103464</commentid>
    <comment_count>4</comment_count>
    <who name="Moritz Haase">Moritz.Haase</who>
    <bug_when>2025-12-03 06:35:20 +0000</bug_when>
    <thetext>@Randy: Looks like there has been a minor mix-up and the ticket will need to be re-opened. My commit that got merged and that you linked to (&quot;curl: Ensure &apos;CURL_CA_BUNDLE&apos; from host env is indeed respected&quot;) is related, but not the actual fix. That&apos;d be &quot;curl: Use host CA bundle by default for native(sdk) builds&quot; (linked in my previous comment), which hasn&apos;t been accepted yet.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103482</commentid>
    <comment_count>5</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2025-12-04 00:54:52 +0000</bug_when>
    <thetext>Moritz,
Oops, my bad.
Thanks for correcting the situation.
I&apos;ll leave resolution of this bug to you but I&apos;ve moved it to &quot;IN PROGRESS DESIGN&quot; since it is in that state.
../Randy</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103634</commentid>
    <comment_count>6</comment_count>
    <who name="Moritz Haase">Moritz.Haase</who>
    <bug_when>2025-12-22 10:32:19 +0000</bug_when>
    <thetext>Actual fix has now been merged:

https://git.openembedded.org/openembedded-core/commit/?id=3f819f57aa1960af36ac0448106d1dce7f38c050

❯ git branch -a --contains 3f819f57aa1960af36ac0448106d1dce7f38c050
* master
  remotes/origin/HEAD -&gt; origin/master
  remotes/origin/master
  remotes/origin/master-next</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>