Linux Operating System (MOSC)

MOSC Banner

Setting crypto policy FUTURE on OL8 breaks dnf connectivity with yum.oracle.com

edited May 30, 2022 12:45AM in Linux Operating System (MOSC) 5 commentsAnswered ✓

After setting a FUTURE crypto policy and rebooting, dnf fails with the base repository:

# dnf update
Oracle Linux 8 BaseOS Latest (x86_64)      0.0 B/s |  0 B   00:00   
Errors during downloading metadata for repository 'ol8_baseos_latest':
  - Curl error (60): Peer certificate cannot be authenticated with given CA certificates for https://yum.oracle.com/repo/OracleLinux/OL8/baseos/latest/x86_64/repodata/repomd.xml [SSL certificate problem: CA certificate key too weak]

After dropping down to default...

# update-crypto-policies --set DEFAULT
Setting system policy to DEFAULT
Note: System-wide crypto policies are applied on application start-up.
It is recommended to restart the system for the change of policies
to fully take place.
# reboot -f
Rebooting.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center