Bug #119397 CA certificate file expired
Submitted: 15 Nov 3:58
Reporter: Qingping Zhu Email Updates:
Status: Open Impact on me:
None 
Category:Tools: MTR / mysql-test-run Severity:S3 (Non-critical)
Version:trunk OS:Linux
Assigned to: CPU Architecture:x86
Tags: mtr

[15 Nov 3:58] Qingping Zhu
Description:
CA certificate file expired.
x.mysqlxtest_mode_ssl mtr test fail.

==============================================================================
                  TEST NAME                       RESULT  TIME (ms) COMMENT
------------------------------------------------------------------------------
[ 50%] x.mysqlxtest_mode_ssl                     [ fail ]
        Test ended at 2025-11-15 11:19:40

CURRENT_TEST: x.mysqlxtest_mode_ssl
WARNING: MYSQL_OPT_RECONNECT is deprecated and will be removed in a future version.
WARNING: MYSQL_OPT_RECONNECT is deprecated and will be removed in a future version.
WARNING: MYSQL_OPT_RECONNECT is deprecated and will be removed in a future version.
mysqltest: At line 33: Command "$MYSQLXTEST_SSLCA_TEST $USE_SOCKET -v%EXPECT%=ON --ssl-mode=preferred  2>&1" failed.

Output from before failure:
Error, printing flow history:>>>> SEND 279 Mysqlx.Connection.CapabilitiesSet {

[zqp@c1cdb7d92b0b mysql-server]$ openssl x509 -in mysql-test/std_data/ca-cert-verify.pem -noout -text
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            ef:d0:74:a2:c4:0d:07:57
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=IN, ST=Karnatka, L=Bangalore, O=MySQL
        Validity
            Not Before: Jan  5 10:05:08 2016 GMT
            Not After : Nov 13 10:05:08 2025 GMT
        Subject: C=IN, ST=Karnatka, L=Bangalore, O=MySQL
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:a7:4e:0a:e4:b6:0b:37:c1:4c:9d:b1:f1:20:33:
                    63:42:7b:71:82:5f:34:9b:cc:0c:5d:5c:bc:03:67:
                    86:42:21:b6:79:16:b7:f1:d9:e4:32:7d:37:17:97:
                    ab:98:7b:14:92:c0:8b:88:1d:76:a7:64:fe:db:d0:
                    27:0d:15:ea:06:5e:a4:9a:ff:98:a5:67:30:f8:af:
                    17:9f:a8:1c:f7:3d:64:94:0c:5f:a0:77:14:13:70:
                    5b:29:66:00:27:79:18:ac:7c:23:f1:ff:31:7c:ae:
                    85:04:dc:a1:5f:ff:01:bf:b6:a4:8f:11:1d:e6:1b:
                    06:c9:b7:94:71:fe:b5:7e:db:45:4e:a6:50:58:e7:
                    7a:a3:29:88:29:1b:24:7b:7a:05:66:62:59:1d:74:
                    3b:aa:4c:b8:64:3d:f9:d0:dd:b0:b8:44:57:57:e3:
                    dc:27:2d:10:fc:16:ea:bb:38:21:9c:c3:f3:19:79:
                    9f:ef:1c:cb:ba:ae:e9:e6:07:5a:df:ec:9f:0b:13:
                    ce:4a:ee:7d:e3:11:a9:3b:6a:7a:5c:4e:37:d7:a8:
                    43:06:0e:47:5a:07:de:f3:44:56:57:1b:ba:82:40:
                    bd:a5:8e:a8:14:4e:50:17:5f:d7:64:8f:4d:84:9d:
                    3f:d9:e5:46:1e:e5:4c:a4:0e:cb:03:78:91:8b:7a:
                    2e:a5
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                9E:1C:F6:D2:9A:51:4D:0F:12:30:6A:E4:6D:B4:EE:38:D7:23:B4:40
            X509v3 Authority Key Identifier: 
                keyid:9E:1C:F6:D2:9A:51:4D:0F:12:30:6A:E4:6D:B4:EE:38:D7:23:B4:40

            X509v3 Basic Constraints: 
                CA:TRUE
    Signature Algorithm: sha256WithRSAEncryption
         14:67:53:28:f6:d6:81:62:d1:21:89:83:f2:b9:fb:c2:dc:e2:
         7e:8e:c1:55:3f:36:02:ce:ca:c2:01:d1:b6:88:3f:f4:6a:79:
         ac:de:e7:dc:46:fe:ff:45:3d:08:01:95:67:09:2b:74:5a:6c:
         ec:b0:c7:96:f1:03:17:5c:ba:cf:b5:ca:9e:63:e2:1d:fb:42:
         ad:7f:aa:48:2a:99:eb:ef:75:20:0f:6b:43:81:41:b2:db:fb:
         9f:3f:9d:a5:7e:cb:05:29:09:86:7a:7e:52:dd:08:c1:f7:7d:
         7b:83:4a:54:aa:aa:b0:b3:9d:ec:6d:8e:88:ed:59:b9:f3:ac:
         19:82:98:99:97:58:67:76:81:26:89:0e:f6:fd:d1:96:69:fc:
         49:6d:de:f3:75:b2:08:d6:d0:cf:c9:12:46:f8:30:9d:6b:ea:
         77:c3:fc:51:eb:da:55:30:04:79:b6:ca:4e:c1:96:8b:f1:ef:
         1e:1d:fc:8a:77:a6:09:64:eb:77:0d:3b:f4:67:d1:20:53:76:
         85:43:4b:62:c1:f5:db:b7:3e:1a:b6:4d:98:8b:dc:da:d1:30:
         65:0d:c2:67:5a:6a:fc:ab:27:16:8f:ab:90:fe:49:f6:b8:2d:
         83:f7:30:c6:03:e0:a8:4b:a2:03:73:22:5d:bd:f6:7e:63:a3:
         28:b3:94:9c

How to repeat:
Run mtr test case.
./mtr auth_sec.admin_channel_tls_startup auth_sec.admin_channel_tls auth_sec.cert_verify_openssl auth_sec.cert_verify x.mysqlxtest_mode_ssl x.mysqlxtest_mode_ssl_unixsocket

Suggested fix:
Update CA certificate file for MTR test.
Refer to commit.
https://github.com/mysql/mysql-server/commit/13380bf81f6bc20d39549f531f9acebdfb5a8c37#diff...