The lftp command doesn't verify the TLS certificate by default in Red Hat Enterprise Linux 6
Issue
- I used the
lftp
command to connect theTLS
enabledvsftpd
server, and I saw a difference of the behavior betweenRHEL6
andRHEL7
. - The server certificate on the
vsftpd
server was not valid, and thelftp
command verified the certificate and failed to connect it onRHEL7
as expected. - But, the
lftp
command onRHEL6
doesn't verify the certificate and could connect the server unexpectedly. - What caused the difference?
Environment
Red Hat Enterprise Linux 6 (RHEL6)
Red Hat Enterprise Linux 7 (RHEL7)
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.