Certificate verification failed

upgrade-nonroot

Certificate verification failed: The certificate is NOT trusted. The revocation or OCSP data are old and have been superseded. Could not handshake: Error in the certificate verification. [IP: xxx.x.x.x xxxx]
Reading package lists… Done
E: Failed to fetch tor + https deb kicksecure com dists bookworm InRelease Certificate verification failed: The certificate is NOT trusted. The revocation or OCSP data are old and have been superseded. Could not handshake: Error in the certificate verification. [IP: xxx.x.x.x xxxx]
E: Some index files failed to download. They have been ignored, or old ones used instead.
zsh: exit 100 upgrade-nonroot [user ~]%

sudo apt-get install --reinstall ca-certificates
Reading package lists… Done
Building dependency tree… Done
Reading state information… Done
0 upgraded, 0 newly installed, 1 reinstalled, 0 to remove and 0 not upgraded.
Need to get 153 kB of archives.
After this operation, 0 B of additional disk space will be used.
Get:1 tor + https deb debian org/debian bookworm/main amd64 ca-certificates all 20230311 [153 kB]
Fetched 153 kB in 8s (20.0 kB/s)
Preconfiguring packages …
(Reading database … 112385 files and directories currently installed.)
Preparing to unpack …/ca-certificates_20230311_all.deb …
Unpacking ca-certificates (20230311) over (20230311) …
Setting up ca-certificates (20230311) …
Updating certificates in /etc/ssl/certs…
0 added, 0 removed; done.
Processing triggers for man-db (2.11.2-2) …
Processing triggers for security-misc (3:36.7-1) …
INFO: triggered security-misc: ‘security-misc’ security-misc DPKG_MAINTSCRIPT_NAME: ‘postinst’ $@: ‘triggered /usr’ 2: ‘/usr’

  • set -e
  • command -v vboxmanage
  • test -f /etc/sysctl.d/30-lkrg-virtualbox.conf
  • exit 0
    /usr/libexec/security-misc/mmap-rnd-bits: INFO: Successfully written ASLR map config file:
    /etc/sysctl.d/30_security-misc_aslr-mmap.conf
    Running SUID Disabler and Permission Hardener… See also:
    https w.k re com/wiki/SUID_Disabler_and_Permission_Hardener
    /var/lib/dpkg/info/security-misc.postinst: INFO: running: permission-hardener enable

INFO: To compare the current and previous permission modes:
Install ‘meld’ (or preferred diff tool) for comparison of file mode changes:
sudo apt install --no-install-recommends meld

Use ‘meld’ or another diff tool to view the differences:
meld /var/lib/permission-hardener/existing_mode/statoverride /var/lib/permission-hardener/new_mode/statoverride

/var/lib/dpkg/info/security-misc.postinst: INFO: Permission hardening success.
Processing triggers for ca-certificates (20230311) …
Updating certificates in /etc/ssl/certs…
0 added, 0 removed; done.
Running hooks in /etc/ca-certificates/update.d…
done.

sudo systemctl restart tor

E: Failed to fetch tor + https deb kicksecure com dists bookworm InRelease Certificate verification failed: The certificate is NOT trusted. The revocation or OCSP data are old and have been superseded. Could not handshake: Error in the certificate verification. [IP: xxx.x.x.x xxxx]

That was a server issue / nginx bug on kicksecure.com server side.

Not a user error. Not fixable by users.