From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Tue, 28 Apr 2026 09:40:33 +0200 X-Sieve: CMU Sieve 2.4 Received: from mail-yx1-f57.google.com (mail-yx1-f57.google.com [74.125.224.57]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 63S7eV1b007931 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Tue, 28 Apr 2026 09:40:32 +0200 Received: by mail-yx1-f57.google.com with SMTP id 956f58d0204a3-649df163c11sf16162585d50.1 for ; Tue, 28 Apr 2026 00:40:32 -0700 (PDT) ARC-Seal: i=3; a=rsa-sha256; t=1777362026; cv=pass; d=google.com; s=arc-20240605; b=R9Vjtt/D3wzg4DpaQS6DzJlrzv/0U56JenJjx3MrQfNOyt1HYIhT4z/0M3id4CQ2Zv z91/MTwtE0foVCmk9MukCMjikLZXjfX8tccGPV9bRnN8Tx5MSTNLSKxKsskEZoXa0zOx 0m6cdxBI5Ov43znm621HrKRGELRrOFd5E57/6MNlgFp5sR25LILJ0evesePSGa6jUx2d MLoTBXQOEU7NKnxdg6SHKoe/kvg3/nD/6Zo1/NZlg3WAnWpBWjrcesfAF6MfBjlEV5WI kqPYw2O6mgvaUzsiUt+tAwi+qlHGmVZC4Og97MnM2TKVKGu7t+7MmXrb9Egc+FWDzmhC jYow== ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:mime-version :content-transfer-encoding:in-reply-to:autocrypt:content-language :from:references:to:subject:user-agent:date:message-id :dkim-signature; bh=SV+dLSwQop7RnvsN1Nb57bVg2GK+m4QGLz0aS3Pwrpg=; fh=qI7h4FSrGmQOcbtRgO7FUk9gV6LKACUiDWAlRhTN4rQ=; b=JQ5KPqicbsMjEg6hTWCXm7+/QWrBZAqxW+p1+R1K2DoU/1qBvqQC6iugXz6Qd+1jmP 2oDCOzTn7qUW/uxCDFQPJjfXNQxySFZwQLKs4SuPMWDmu6AKXe9rVIMHux1a7tmukMGj OtrRFvgIWYaF3rnq7UkpD3pAY7ciNC3TGgdnGNN+e1UPO86e3B8EtG1X+1n3r/VL2rar 2Nxuwt4g65b9A+GzBKtW7sr1Kg1tHKVA0L/Z7jjPz8JVS3K4o/j1EErSEAOQaTTRW9XI nSF46nKIrMxpeiFEwjlBmShek8XxsxQoHIOeEjCM1BvvdryrmOSC2K8AhZFWn3a5Llml NzQw==; darn=ilbers.de ARC-Authentication-Results: i=3; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=penhlwJb; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of jan.kiszka@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) smtp.mailfrom=jan.kiszka@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20251104; t=1777362026; x=1777966826; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-transfer-encoding:in-reply-to:autocrypt:content-language :from:references:to:subject:user-agent:date:message-id:from:to:cc :subject:date:message-id:reply-to; bh=SV+dLSwQop7RnvsN1Nb57bVg2GK+m4QGLz0aS3Pwrpg=; b=D6JHU3khjpy5q0tOOGYEyoAQ6QLnHd1G+YhYervl7WqEYo/ZFt3uMWe+xiGHH12Yky 2L4gJLvX3Oo5hdWVbvev4mIzha0e1Fk8P+49ENxDPEZdNb+0sQ6b1IbG0FAz2UQ6Hmlk oJ8kLyLwVJldDDdlGk1vaqQZSh2BY+XpBq1Z7ydkW8Iy4ChVKDNhQPquefY34A9DcD0s AeEZLBcKI2MjsOFImUve2eJp3sqVKHASosPLzOmFjkDLNT/a2jGf/CVCMRQT9mOkNOtJ sD//oqH0O8t22N9kRQwhTKTgygP60tb7mnlXj9meoO5ozDQeqc6aFN/yMI0zG96UDO0Z SEKw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1777362026; x=1777966826; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-transfer-encoding:in-reply-to:autocrypt:content-language :from:references:to:subject:user-agent:date:message-id:x-beenthere :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=SV+dLSwQop7RnvsN1Nb57bVg2GK+m4QGLz0aS3Pwrpg=; b=svUVgsLkG9EDDQ9IV8+2m8krJjqZsSuQbT6C54F2ZK47rDTmHo8lY+KRwSMSQ1SwOS CzprM0SyGHcHaTxGcB5N/lbeLe0Ua3PbpeBhcAHGAJQVHNn31Ei46Y/1ys4tNVb4vde7 1JFShUBkVY/KwRTV2TWGQnIuh/6CahC5Po4DrkheA4nftD/Ae5lp08iUCWvolk6xtNfy W5rBq/fMc3ew5WGVG2P81XWn14IKTztZm5vGXIsFqQYwcfFwMq8BozehYCuP+tXSsxg1 PqE+Hvd0JWlyUaZZjOi3QM1C3gkOIfdXWn+806z/iph75DSxp8MdRODsaQqQ5UxDRnnY 3Zcg== X-Forwarded-Encrypted: i=3; AFNElJ8qvBSlkgXPFu8XWgFpIehYUkvQiwqUk1yj7Ht3PFzWsPHI0izwGGwe1M8qtJoTAkehHu5U@ilbers.de X-Gm-Message-State: AOJu0YzGDAptQMhudZTMeSajSbs/MkeapuP0jOm+mbkKKjdz8VadGTcn +27vmmoeAnUPky/ztU1Wm01+r7gcdh0BIc196by2dOaCDlwB5TULMCI9 X-Received: by 2002:a05:690e:2418:b0:651:b899:c5e8 with SMTP id 956f58d0204a3-65beee4426dmr1187013d50.36.1777362025731; Tue, 28 Apr 2026 00:40:25 -0700 (PDT) X-BeenThere: isar-users@googlegroups.com; h="AUV6zMP69UaC0YWbjYJd5WoMGzO162IuOwMFyk87OhlgowyqrQ==" Received: by 2002:a53:d243:0:b0:646:78d8:d2c2 with SMTP id 956f58d0204a3-652f775082als7810369d50.0.-pod-prod-03-us; Tue, 28 Apr 2026 00:40:24 -0700 (PDT) X-Forwarded-Encrypted: i=3; AFNElJ8SJmN4WjEAJZ6SS2xvOOC07nlhXq/xwKCR5WKWYWUXsI7InQPYZCSQ8e+d/Du+JQFOTmG+2LTCAMOC@googlegroups.com X-Received: by 2002:a05:690e:2408:b0:654:6a61:fb36 with SMTP id 956f58d0204a3-65beeeca5e0mr1191945d50.58.1777362024601; Tue, 28 Apr 2026 00:40:24 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1777362024; cv=pass; d=google.com; s=arc-20240605; b=eThnDIEyXnyvQJ8blpzMe3qwPpkEbSHg+TxNHlpVk2IFAN6dx0Cyx4NkQV1v56n9EN siZZLezenYqivszFe7QKag9330fX85wQcgxjPc9KaGmxYlBNlr8KFEuFPpn5KyDeuvxk kDDFlqaVE521wXjir7K164Q+B9M2E30mdlDomo7ovx9AqlOoFpI/TrqMdRXFw/kS3gYR uUWMdO/9d4d2N3Glha8bBN7aAdL8fIILyOGIaA7x5iRBq8ltjT8xM6LxjKRWDS5jYmbZ j0OyChUcenlH/nkvciFeCx24YSLJN0DRM87Yk4RLAA5GMQ1yZ0+lsS50vghtnjz7+mE1 +bMQ== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=mime-version:content-transfer-encoding:in-reply-to:autocrypt :content-language:from:references:to:subject:user-agent:date :message-id:dkim-signature; bh=BkZf8s5kH4jIwnyLM54w/ij4b13iDod51XEuAvBYmbY=; fh=iV2u/hCwU78Zp4KETryd2gBTMuoXluC6670G+1prfbM=; b=SPs7UKfbqSwvwWCpPEUGQd5apCrK7m7Z7ZmoYOokQBkT0U0w+G0Zi0oW5ZdgoNV+i4 0kjC3eYtDkG4ez6zTQVwGCaylFT6Qr4cWQNqDB68dppPzFLUojmLjIUxwHne1nVOeQHR A026QMMJxuKzti/pocYlZp3Oamv1XsIcr7tLBBeRLDVXC9Wu8nDtdcb8qDg/rUQqcEas rjxtn4M+CddqdH4kkr+kuYzDpIADXY5M84kBupnjdlQwu1oeex5Rx05D1gIdIVboxKul MTWCm8yjVGxcg4HludHwe6rBRZJ37SzsIPOexikuVHpQjOFhAQrUq8fifNoZxElJav8h KQ5w==; dara=google.com ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=penhlwJb; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of jan.kiszka@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) smtp.mailfrom=jan.kiszka@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com Received: from GVXPR05CU001.outbound.protection.outlook.com (mail-swedencentralazlp170130007.outbound.protection.outlook.com. [2a01:111:f403:c202::7]) by gmr-mx.google.com with ESMTPS id 956f58d0204a3-65bee00c562si57392d50.0.2026.04.28.00.40.24 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Apr 2026 00:40:24 -0700 (PDT) Received-SPF: pass (google.com: domain of jan.kiszka@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) client-ip=2a01:111:f403:c202::7; ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=TJfsuazYWM+3C53rlBcMyRDZHsYwbWAOShHjnhVuLQFvPD9JMQRgM3ymluZZchO5C4S3gXzxeZJX6lxgP58C4oT+YUhwxR9Mno/ORdnBXKa0E1YCHgTfYeLb9K8Kf5/sz6dSpltaHyb7VRgMZVTxMpjlf/xvDTKXiDao4kxrEKuf76rFJ+neKnYBBO0ZdWRJcuwu+l9s0HSmPxF6N3mSIcg6T/WIs8IdeYVBtN07v4nVAE21vkb0IIgSPENVhooPBElpGrVztW3fWZ5I2/ahPIE3vM30truvuqIkmgvZlTXsKH7FRLFeNgvfBbaoGT5pcDZXuBEqwedrMbgnRnq9qA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=BkZf8s5kH4jIwnyLM54w/ij4b13iDod51XEuAvBYmbY=; b=Hb58pi0/x+40r5c/oLjmucXFXcQh+cu6hoGQ9Th5Hc1YgzOQYNGfO1uIvssRykoci837P+WxozKaEgczQHJkj/+BKcnqt1SfxTwTZcCVxKQPTA3jieEe6BF3fXIaJQ8efLzF41xlYuBJvjWVgUhMHXybBEaPRnQ6IByBymPdDC1y66k6R5jC51hGSlAWjQ/NRVjtzSYfXMLKIILLjGuxkYeW8rO/eGQde3d1MiJKFm5pEXmmXpn4cW0JpN7LEGrgZ9jcgTiarSkWcR0l53xNLaIVXKNQkGhr9FNhXJ+7pa2hIkSGstdZ3aXeb0EX6fx3XfVGGh4PbR0CBqiQkj5/ZA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none Received: from AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:588::19) by PA2PR10MB9173.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:41b::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9846.26; Tue, 28 Apr 2026 07:40:21 +0000 Received: from AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM ([fe80::be9f:e8ca:ee9:83e1]) by AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM ([fe80::be9f:e8ca:ee9:83e1%3]) with mapi id 15.20.9846.025; Tue, 28 Apr 2026 07:40:20 +0000 Message-ID: <2b9c7c31-2ff0-41c3-8e66-8f9a86199252@siemens.com> Date: Tue, 28 Apr 2026 09:40:19 +0200 User-Agent: Mozilla Thunderbird Subject: Re: HTTPs connection during bootstrap To: Ulrich Teichert , isar-users References: <3a6bc2de-5694-4a72-90fd-6fcb5a62587en@googlegroups.com> From: "'Jan Kiszka' via isar-users" Content-Language: en-US Autocrypt: addr=jan.kiszka@siemens.com; keydata= xsFNBGZY+hkBEACkdtFD81AUVtTVX+UEiUFs7ZQPQsdFpzVmr6R3D059f+lzr4Mlg6KKAcNZ uNUqthIkgLGWzKugodvkcCK8Wbyw+1vxcl4Lw56WezLsOTfu7oi7Z0vp1XkrLcM0tofTbClW xMA964mgUlBT2m/J/ybZd945D0wU57k/smGzDAxkpJgHBrYE/iJWcu46jkGZaLjK4xcMoBWB I6hW9Njxx3Ek0fpLO3876bszc8KjcHOulKreK+ezyJ01Hvbx85s68XWN6N2ulLGtk7E/sXlb 79hylHy5QuU9mZdsRjjRGJb0H9Buzfuz0XrcwOTMJq7e7fbN0QakjivAXsmXim+s5dlKlZjr L3ILWte4ah7cGgqc06nFb5jOhnGnZwnKJlpuod3pc/BFaFGtVHvyoRgxJ9tmDZnjzMfu8YrA +MVv6muwbHnEAeh/f8e9O+oeouqTBzgcaWTq81IyS56/UD6U5GHet9Pz1MB15nnzVcyZXIoC roIhgCUkcl+5m2Z9G56bkiUcFq0IcACzjcRPWvwA09ZbRHXAK/ao/+vPAIMnU6OTx3ejsbHn oh6VpHD3tucIt+xA4/l3LlkZMt5FZjFdkZUuAVU6kBAwElNBCYcrrLYZBRkSGPGDGYZmXAW/ VkNUVTJkRg6MGIeqZmpeoaV2xaIGHBSTDX8+b0c0hT/Bgzjv8QARAQABzSNKYW4gS2lzemth IDxqYW4ua2lzemthQHNpZW1lbnMuY29tPsLBlAQTAQoAPhYhBABMZH11cs99cr20+2mdhQqf QXvYBQJmWPvXAhsDBQkFo5qABQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJEGmdhQqfQXvY zPAP/jGiVJ2VgPcRWt2P8FbByfrJJAPCsos+SZpncRi7tl9yTEpS+t57h7myEKPdB3L+kxzg K3dt1UhYp4FeIHA3jpJYaFvD7kNZJZ1cU55QXrJI3xu/xfB6VhCs+VAUlt7XhOsOmTQqCpH7 pRcZ5juxZCOxXG2fTQTQo0gfF5+PQwQYUp0NdTbVox5PTx5RK3KfPqmAJsBKdwEaIkuY9FbM 9lGg8XBNzD2R/13cCd4hRrZDtyegrtocpBAruVqOZhsMb/h7Wd0TGoJ/zJr3w3WnDM08c+RA 5LHMbiA29MXq1KxlnsYDfWB8ts3HIJ3ROBvagA20mbOm26ddeFjLdGcBTrzbHbzCReEtN++s gZneKsYiueFDTxXjUOJgp8JDdVPM+++axSMo2js8TwVefTfCYt0oWMEqlQqSqgQwIuzpRO6I ik7HAFq8fssy2cY8Imofbj77uKz0BNZC/1nGG1OI9cU2jHrqsn1i95KaS6fPu4EN6XP/Gi/O 0DxND+HEyzVqhUJkvXUhTsOzgzWAvW9BlkKRiVizKM6PLsVm/XmeapGs4ir/U8OzKI+SM3R8 VMW8eovWgXNUQ9F2vS1dHO8eRn2UqDKBZSo+qCRWLRtsqNzmU4N0zuGqZSaDCvkMwF6kIRkD ZkDjjYQtoftPGchLBTUzeUa2gfOr1T4xSQUHhPL8zsFNBGZY+hkBEADb5quW4M0eaWPIjqY6 aC/vHCmpELmS/HMa5zlA0dWlxCPEjkchN8W4PB+NMOXFEJuKLLFs6+s5/KlNok/kGKg4fITf Vcd+BQd/YRks3qFifckU+kxoXpTc2bksTtLuiPkcyFmjBph/BGms35mvOA0OaEO6fQbauiHa QnYrgUQM+YD4uFoQOLnWTPmBjccoPuiJDafzLxwj4r+JH4fA/4zzDa5OFbfVq3ieYGqiBrtj tBFv5epVvGK1zoQ+Rc+h5+dCWPwC2i3cXTUVf0woepF8mUXFcNhY+Eh8vvh1lxfD35z2CJeY txMcA44Lp06kArpWDjGJddd+OTmUkFWeYtAdaCpj/GItuJcQZkaaTeiHqPPrbvXM361rtvaw XFUzUlvoW1Sb7/SeE/BtWoxkeZOgsqouXPTjlFLapvLu5g9MPNimjkYqukASq/+e8MMKP+EE v3BAFVFGvNE3UlNRh+ppBqBUZiqkzg4q2hfeTjnivgChzXlvfTx9M6BJmuDnYAho4BA6vRh4 Dr7LYTLIwGjguIuuQcP2ENN+l32nidy154zCEp5/Rv4K8SYdVegrQ7rWiULgDz9VQWo2zAjo TgFKg3AE3ujDy4V2VndtkMRYpwwuilCDQ+Bpb5ixfbFyZ4oVGs6F3jhtWN5Uu43FhHSCqUv8 FCzl44AyGulVYU7hTQARAQABwsF8BBgBCgAmFiEEAExkfXVyz31yvbT7aZ2FCp9Be9gFAmZY +hkCGwwFCQWjmoAACgkQaZ2FCp9Be9hN3g/8CdNqlOfBZGCFNZ8Kf4tpRpeN3TGmekGRpohU bBMvHYiWW8SvmCgEuBokS+Lx3pyPJQCYZDXLCq47gsLdnhVcQ2ZKNCrr9yhrj6kHxe1Sqv1S MhxD8dBqW6CFe/mbiK9wEMDIqys7L0Xy/lgCFxZswlBW3eU2Zacdo0fDzLiJm9I0C9iPZzkJ gITjoqsiIi/5c3eCY2s2OENL9VPXiH1GPQfHZ23ouiMf+ojVZ7kycLjz+nFr5A14w/B7uHjz uL6tnA+AtGCredDne66LSK3HD0vC7569sZ/j8kGKjlUtC+zm0j03iPI6gi8YeCn9b4F8sLpB lBdlqo9BB+uqoM6F8zMfIfDsqjB0r/q7WeJaI8NKfFwNOGPuo93N+WUyBi2yYCXMOgBUifm0 T6Hbf3SHQpbA56wcKPWJqAC2iFaxNDowcJij9LtEqOlToCMtDBekDwchRvqrWN1mDXLg+av8 qH4kDzsqKX8zzTzfAWFxrkXA/kFpR3JsMzNmvextkN2kOLCCHkym0zz5Y3vxaYtbXG2wTrqJ 8WpkWIE8STUhQa9AkezgucXN7r6uSrzW8IQXxBInZwFIyBgM0f/fzyNqzThFT15QMrYUqhhW ZffO4PeNJOUYfXdH13A6rbU0y6xE7Okuoa01EqNi9yqyLA8gPgg/DhOpGtK8KokCsdYsTbk= In-Reply-To: <3a6bc2de-5694-4a72-90fd-6fcb5a62587en@googlegroups.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: FR4P281CA0251.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:f5::12) To AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:588::19) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AS4PR10MB6181:EE_|PA2PR10MB9173:EE_ X-MS-Office365-Filtering-Correlation-Id: fbe3f087-82b2-41c8-cbda-08dea4f96686 X-MS-Exchange-AtpMessageProperties: SA X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|56012099003|18002099003|22082099003|55112099003|13003099007; X-Microsoft-Antispam-Message-Info: lr2oAY1CRGg7V/wxUM4hcT/OkQusfCeHXkVhfJCAFpW2VtWpLr5dd07g2MCBP0M4js9W2VNWKwaLSgw5eE6aqaIH8Nf+pgH8FD7byF5Z6MfOZFwOSOgmmGIQ79IHXU8jBaHiK11zVfugVXkt/Qd+SRRwdpTkWNkgREqJ2QBw51SAXtGTOFm9QCKaGd6hYLQWjmmGC2dRMCtO9EsL7c/FiCEqAUNncaWor3xcQZkFVIPAosG6I8Up9eWJTbyaizwLxkvIOj9+uuzRAEaAuTZVf55zIIdIU55mhFUYrFyNjJRdWdNc3k+dP8UJctaYVovnipS7yYQ34oX58A5gYYlR6wurYVTBKdKbu2tZyGnT2qKkigI3pGxY0G9zkAxWFyQETqxmF1lU7XVQy1gT0mQjJpEgrZCT1wU8YrL69nJGDhUD8aE1jQ0o8/lmiUKJv/sL69lSWsLoL7UWiG8gg28ah4FIb+guFwcMjslyrnRyCGycDpxb28l7X14ZiU2k+wkvqYkEcf6NHIwB0KsUw4+8vTJiFrRMlKmS78kD9gcYZADnwFR6HRIM1bxxkiKMHol7zfs67n5D8BwKW7lqBFpJoAxZzVA4NMThwv4ig2SvnncQBTlS8yKLTolJzIuGvpLAn+VjobS/bRF/Y5vfJNAgbqUAEjdxxyFWonhz1YWBLh922oKzB/Z0CplY9Mx3RKdk X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(56012099003)(18002099003)(22082099003)(55112099003)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?B?VHpNWHNkS0FzeXBzL0M4MGFLVnRLVXZDSlZ3bWpGcFZkeDljYUpqTDlLanZm?= =?utf-8?B?VnFTN3hITHNTOFBOMmFvV3BZcDZsTGsxQ1NyTFFIRkk1dVJsVWhYb0lhdHhH?= =?utf-8?B?ZmMwcFAwaEc1b3R4UzNVUjJEdjIxNE54eVhPQW5ia1FaRnB3czhtVDM2R1dN?= =?utf-8?B?QTBHcnNnNXl5RUV5dVpIUVJzUGhOemZ5VDNkMXlYTDMwL3JTRjJxVjc2Z214?= =?utf-8?B?dFFUbmxIRm5YdDM3ZThBZklESEJWT1JWZVR3MXNWYXdvV1pMTi9ZVUdYRXZO?= =?utf-8?B?Slc5eXdCaC9mN01sM1Y3WDVzQVFPQ1o4QWdhaTVIS05VR3NNWXNaMStjR2pM?= =?utf-8?B?VzR6TlMvRG9TaTREd2NBTy96b3JmeUQ5eldRT2Vla3NNWVFoc2hYaERrbnlQ?= =?utf-8?B?UWlQVVNRUUticDdYeWROTHl5YkFjMGxwQmtMY0hiNFNlUjVicEdianFxLzhF?= =?utf-8?B?SG9lTnA4dlVSblUweU1UcldsMnNjclR1WFhJMWRNZTlYcmJEaUN1WGZONW5O?= =?utf-8?B?amVPV3VXaDVScDZEQVFjeGs4b0RuYzB0RVZlQ0Z0cENyL2x3YnJFUXlhYzJM?= =?utf-8?B?MElNYXpSNDFTV2xqdG84REpYTTRwVSsrVzJoNnNndnBvUkZDVVRRS1Npam1x?= =?utf-8?B?TEhWMEpvelJxaExyWndES3crWVdmc1NnWlpsYU43Q25NMldDRHM2WkJNT3VT?= =?utf-8?B?WE9wWHJzTCtHY01Qc0I0aHhvUW80bFdKS2ZsNk83SVVXU3BqeTloOG9DY3pM?= =?utf-8?B?QWN3OEV4Ykg0ZW5FSEk2Z2lWODRHWmpiY1ZNZGhvUFBlZzE2ME9UeWpHSHBr?= =?utf-8?B?eWZDWW00ZDFBd3U4UDZDNU9tdTRMSUg4WmxDeXpGWDRyQ3JXT1RUWTU4N3A3?= =?utf-8?B?RnI1VHh0YlhMOGFIUFlCVEV4OVl4ZE1GMm55SEJ0U0hRdWNPeU9vUFBmUDUz?= =?utf-8?B?aDkxVFZreWVEUXpISzZ4Q2pKTmxDMjJxeFJnU2FtaVdjYVhVYmdyUTc5dXFv?= =?utf-8?B?SE1pMVdUTzlBTy81bjFPWXZ6YlFWQ0hmcmczM2lHN3djc1VuTFBqbmFVb24v?= =?utf-8?B?WlIrUVowS3gyQjZrTk1iVUVKVGxPNTJycVJrckxYd0ZYK1lUYmxqVGV0NDNk?= =?utf-8?B?UVdkd1lNbjNVRDNneUVYY1RLd2U5TGRnbW9ZTEJsS3JpeE1Bd3RTcWNHUWE5?= =?utf-8?B?ekJlS3hWZmRMaXJaNXJMWmxLcnJkcytMcUtoYWJCWWZQdVRtb3pnQ1FUNnRt?= =?utf-8?B?ckt5SVJZS3dBbmdxZlA2VTZIbmNwRnVVcHJXL0xXblVuampRRlNacTFpeWU5?= =?utf-8?B?KzJZTEhyU2pvSlkwOUw1UmVQRVI4eVltOGZFUzlRd0g3RjZ3MHd4MlFWeFFE?= =?utf-8?B?ampiRmNwZU1kTGJFaVBxZlptOUVBRXU0VStsZ25MVzVCWkJDcys3Y2FZekR2?= =?utf-8?B?RDFHWnZETjBTVXZ6QXJKSm9TQ3ZuOW51RTBFWGZZMlVHZkl1Mzcvemlwb0tQ?= =?utf-8?B?cnc2UUxTTjFHT0hpSFRSUWdYdEdHS0xCWktnejk2emtHdU4remo1TTJrRlNQ?= =?utf-8?B?Tzhha29KUkJNditmQnJReTFBYWkxMHc3bmpEc3RqMnFSUGZuSk5BU1R3WkxU?= =?utf-8?B?VWtBbFBwT0hkcmlPVnBkbDJRSkdwUXpkQ3ZBQTVseVhhL2ZMb1VtYVBiZDk3?= =?utf-8?B?Y3ZvYzZ1QnVEK0dFRExKZ1hrTENTMWdiUVV5L3Zja2VyZFU0bzFFOE12ejVr?= =?utf-8?B?M00yejFtRXpZZk44QzFVTUNJL08wWXppN1ZLK0tGRFNsWXpoZmJZTGY0KzB4?= =?utf-8?B?cUlyTjZqcWI4VndvWXNiL0k2KzNnSXZQZnpXYk5Ca3J2aVpFcjM1VmhUU25P?= =?utf-8?B?VVlMU3RkbWRSK0U5SUk2cVljSG5ZdGFaMTlXRXVtWGdUNTY3bWxBWk9QeEZI?= =?utf-8?B?ZGd1bUVFR3JIVk1kUlFzb0hiZjIvSjBUSDdoOTVWT1c1QnBTODlnTDBSNUg4?= =?utf-8?B?d1lWZ1RKSE9xWk1XR0dCVGpGQ2d1WXFOQ1BKNkVXUHVxUGRkSHQvYXRCZUpV?= =?utf-8?B?SytaUW9CNkhCclp6UEI0cklvRkpnOTVEeWFuWm5Ca1NqVEwyeGdLVE9wS1FB?= =?utf-8?B?ckZCUWJnOStaQmZJbUFaT3dnZElaME5hM1Ribm5jdUQ0andMRmtxd2VYWTla?= =?utf-8?B?YWN4SDZMN1h0Kzh2Wm5iZVBDck1NWHJsekpQeHFwRXdCb0k3dWhwZncvZFRL?= =?utf-8?B?WEZJRHVGOTBvV0xZcGdWSktaSW1MUk9zaEJQdXF0SXRHSHBLdXdhdkFTbk1o?= =?utf-8?B?SnBKWVpqdnFJOFFRdjkvUXVyOGZVZVpTWXp2U2U3SjNFM0ZEeExiZz09?= X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: fbe3f087-82b2-41c8-cbda-08dea4f96686 X-MS-Exchange-CrossTenant-AuthSource: AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 28 Apr 2026 07:40:20.8217 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: tjEQmOugAuB4QlOhuarpHOVv+hozP8oHvYC/9ccLERiC3DyB4VHL4ppLpSbpS8sQPYGMgz4BruqAyE7bJWtIaA== X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA2PR10MB9173 X-Original-Sender: jan.kiszka@siemens.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=penhlwJb; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of jan.kiszka@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) smtp.mailfrom=jan.kiszka@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com X-Original-From: Jan Kiszka Reply-To: Jan Kiszka Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Status: No, score=-4.9 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H2,RCVD_IN_RP_CERTIFIED, RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-TUID: iKy4Qatqllx3 On 28.04.26 08:58, Ulrich Teichert wrote: > Hi, >=20 > after some teething problems, I've been able to build a bootable qemu > ARM64 image > with some of our packages for a proof of concept - thanks again to Anton. >=20 > Still open is getting a successful connection to an external apt- > repository over HTTPs, > during bootstrapping which is secured by self signed certificates. > Currently, I have to use > a reverse proxy (caddy - nice and simple setup) to circumvent the issue, > and I would like to > get rid of it. >=20 > The error I'm getting at the moment when not using the reverse proxy is: >=20 > ERROR: mc:qemuarm64-trixie:isar-mmdebstrap-target-1.0-r0 do_bootstrap: > ExecutionError('/home/isar/isar-image/build/tmp/work/debian-trixie- > arm64/isar-mmdebstrap-target/1.0-r0/temp/run.do_bootstrap.18929', 25, > None, None) > ERROR: Logfile of failure stored in: /home/isar/isar-image/build/tmp/ > work/debian-trixie-arm64/isar-mmdebstrap-target/1.0-r0/temp/ > log.do_bootstrap.18929 > Log data follows: > | DEBUG: Executing python function sstate_task_prefunc > | DEBUG: Python function sstate_task_prefunc finished > | DEBUG: Executing shell function do_bootstrap > | removed '/home/isar/isar-image/build/tmp/work/debian-trixie-arm64/ > isar-mmdebstrap-target/1.0-r0/sources.list.d/bootstrap.list' > | '/home/isar/isar-image/build/tmp/work/debian-trixie-arm64/isar- > mmdebstrap-target/1.0-r0/apt-sources' -> '/home/isar/isar-image/build/ > tmp/work/debian-trixie-arm64/isar-mmdebstrap-target/1.0-r0/ > sources.list.d/bootstrap.list' > | I: arm64 cannot be executed natively, but transparently using qemu- > user binfmt emulation > | I: finding correct signed-by value... > | I: automatically chosen format: tar > | I: using /home/isar/isar-image/build/tmp/work/debian-trixie-arm64/ > isar-mmdebstrap-target/1.0-r0/tempdir/mmdebstrap.3tADUZToch as tempdir > | W: Download is performed unsandboxed as root as file /home/isar/isar- > image/build/tmp/work/debian-trixie-arm64/isar-mmdebstrap-target/1.0-r0/ > tempdir/mmdebstrap.3tADUZToch/var/lib/apt/lists/partial couldn't be > accessed by user _apt > | I: running --setup-hook in shell: sh -c 'mkdir -p "$1/var/cache/apt/ > archives/"' exec /home/isar/isar-image/build/tmp/work/debian-trixie- > arm64/isar-mmdebstrap-target/1.0-r0/tempdir/mmdebstrap.3tADUZToch > | I: running --setup-hook in shell: sh -c 'flock -s /home/isar/isar- > image/build/downloads/deb/debian-trixie.lock cp -n --no-preserve=3Downer = \ > | =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 "/home/isar/isar-image/build/tmp/work/debian- > trixie-arm64/isar-mmdebstrap-target/1.0-r0/dl_dir/var/cache/apt/ > archives/"*.deb \ > | =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 "$1/var/cache/apt/archives/" || true' exec / > home/isar/isar-image/build/tmp/work/debian-trixie-arm64/isar-mmdebstrap- > target/1.0-r0/tempdir/mmdebstrap.3tADUZToch > | I: running special hook: upload "/home/isar/isar-image/build/tmp/work/ > debian-trixie-arm64/isar-mmdebstrap-target/1.0-r0/apt-preferences" /etc/ > apt/preferences.d/bootstrap > | I: running special hook: upload "/home/isar/isar-image/build/tmp/work/ > debian-trixie-arm64/isar-mmdebstrap-target/1.0-r0/apt-sources-init" / > etc/apt/sources-list > | I: running special hook: upload "/home/isar/isar-image/build/tmp/work/ > debian-trixie-arm64/isar-mmdebstrap-target/1.0-r0/locale" /etc/locale > | I: running --setup-hook in shell: sh -c 'mkdir -p "$1/etc/apt/ > trusted.gpg.d"' exec /home/isar/isar-image/build/tmp/work/debian-trixie- > arm64/isar-mmdebstrap-target/1.0-r0/tempdir/mmdebstrap.3tADUZToch > | I: running special hook: sync-in "/home/isar/isar-image/build/tmp/ > work/debian-trixie-arm64/isar-mmdebstrap-target/1.0-r0/trusted.gpg.d" / > etc/apt/trusted.gpg.d > | I: running --setup-hook in shell: sh -c 'install -v -m755 "/home/isar/ > isar-image/build/tmp/work/debian-trixie-arm64/isar-mmdebstrap- > target/1.0-r0/chroot-setup.sh" "$1/chroot-setup.sh"' exec /home/isar/ > isar-image/build/tmp/work/debian-trixie-arm64/isar-mmdebstrap- > target/1.0-r0/tempdir/mmdebstrap.3tADUZToch > | '/home/isar/isar-image/build/tmp/work/debian-trixie-arm64/isar- > mmdebstrap-target/1.0-r0/chroot-setup.sh' -> '/home/isar/isar-image/ > build/tmp/work/debian-trixie-arm64/isar-mmdebstrap-target/1.0-r0/ > tempdir/mmdebstrap.3tADUZToch/chroot-setup.sh' > | I: running apt-get update... > | Ign:1 https://XXXXXXXX.kumkeo.local/trixie/latest trixie InRelease > | Get:2 http://deb.debian.org/debian trixie InRelease [140 kB] > | Get:3 http://deb.debian.org/debian-security trixie-security InRelease > [43.4 kB] > | Get:4 http://deb.debian.org/debian trixie-updates InRelease [47.3 kB] > | Get:5 http://deb.debian.org/debian trixie/non-free Sources [75.9 kB] > | Get:6 http://deb.debian.org/debian trixie/contrib Sources [52.3 kB] > | Get:7 http://deb.debian.org/debian trixie/main Sources [10.5 MB] > | Get:8 http://deb.debian.org/debian trixie/non-free-firmware Sources > [6552 B] > | Get:9 http://deb.debian.org/debian trixie/non-free-firmware arm64 > Packages [6484 B] > | Get:10 http://deb.debian.org/debian trixie/contrib arm64 Packages > [48.4 kB] > | Get:11 http://deb.debian.org/debian trixie/non-free arm64 Packages > [74.4 kB] > | Get:12 http://deb.debian.org/debian trixie/main arm64 Packages [9607 kB= ] > | Ign:1 https://XXXXXXXX.kumkeo.local/trixie/latest trixie InRelease > | Get:13 http://deb.debian.org/debian-security trixie-security/non-free- > firmware Sources [696 B] > | Get:14 http://deb.debian.org/debian-security trixie-security/main > Sources [132 kB] > | Get:15 http://deb.debian.org/debian-security trixie-security/main > arm64 Packages [127 kB] > | Get:16 http://deb.debian.org/debian trixie-updates/main Sources [2788 B= ] > | Get:17 http://deb.debian.org/debian trixie-updates/main arm64 Packages > [5404 B] > | Ign:1 https://XXXXXXXXX.kumkeo.local/trixie/latest trixie InRelease > | Err:1 https://XXXXXXXXX.kumkeo.local/trixie/latest trixie InRelease > | =C2=A0 SSL connection failed: error:0A000086:SSL routines::certificate > verify failed / Success [IP: A.B.C.D 443] > | Fetched 20.9 MB in 7s (2899 kB/s) > | Reading package lists... > | E: Failed to fetch https://XXXXX.kumkeo.local/trixie/latest/dists/ > trixie/InRelease =C2=A0SSL connection failed: error:0A000086:SSL > routines::certificate verify failed / Success [IP: A.B.C.D 443] > | E: Some index files failed to download. They have been ignored, or old > ones used instead. > | E: apt-get update --error-on=3Dany -oAPT::Status-Fd=3D<$fd> -oDpkg::Use= - > Pty=3Dfalse failed: process exited with 100 and error in console output > | W: hooklistener errored out: E: received eof on socket > | > | I: main() received signal PIPE: waiting for setup... > | I: removing tempdir /home/isar/isar-image/build/tmp/work/debian- > trixie-arm64/isar-mmdebstrap-target/1.0-r0/tempdir/mmdebstrap.3tADUZToch.= .. > | E: mmdebstrap failed to run > ERROR: Task (mc:qemuarm64-trixie:/home/isar/isar-image/isar/meta/ > recipes-core/isar-mmdebstrap/isar-mmdebstrap-target.bb:do_bootstrap) > failed with exit code '1' > NOTE: Tasks Summary: Attempted 136 tasks of which 135 didn't need to be > rerun and 1 failed. > =C2=A0 > Summary: 1 task failed: > =C2=A0 mc:qemuarm64-trixie:/home/isar/isar-image/isar/meta/recipes-core/i= sar- > mmdebstrap/isar-mmdebstrap-target.bb:do_bootstrap > Summary: There was 1 ERROR message, returning a non-zero exit code. >=20 > (internal hostname replaced by XXXXX, IP by A.B.C.D) >=20 > What would be the best way to inject the missing certificates into the > bootstrapping > process? Bootstrapping is done within the environment of your host or kas-isar in case you use the build container. So, one way is to enrich the appropriate environment with that special certificate prior to starting the build. Another one is to explore the extension of do_apt_config_prepare of the bootstrap class with setting for https://manpages.debian.org/trixie/apt/apt-transport-https.1.en.html. There is no convenient way of configuring this via Isar variables because that case is too uncommon. Normally, one signs the repo itself, and can thus disable/ignore transport security. Jan --=20 Siemens AG, Foundational Technologies Linux Expert Center --=20 You received this message because you are subscribed to the Google Groups "= isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/= 2b9c7c31-2ff0-41c3-8e66-8f9a86199252%40siemens.com.