Bug with IAAPlus authenticator Fedora 40

,

We tried to install
https://www.ausfuhrplus.internetzollanmeldung.de/iaap/lizok.do?LzOk=Lizenzvertrag+akzeptieren
Linux 64 bit
Running the programm a crash report results. The Browser (Firefox) shows an error code 8123.
According to the official support it is a firewall problem.
We deactivated the firewalld and tried to turn off ssh with no success.
A new instllation of Fedora 39 lead to the same problem.
Has anyone an idea how to proceed?

Do not disable the firewall!

The normal practice is to add rules to firewalld to support a new app.
But this is only needed for apps that connect from outside the machine.
I assume this app is calling out not in so no firewall changes should be needed.

Why do you think turning off ssh required?

What did the support say exactly for that error? (In English please)

1 Like

The Firewall is activated again and it was only a temporary try.
The support message was:
"The error message indicates the use of SSL inspection/interception in your infrastructure (original certificate of a website is exchanged for a certificate generated by the firewall/proxy application).

Since the authenticator expects the original certificate from the website https://www.ausfuhrplus.internetzollanmeldung.de and not the certificate exchanged by the proxy server,
in this case, an exception would have to be set up for the https://www.ausfuhrplus.internetzollanmeldung.de/* page in a corresponding positive list.

Depending on the software you are using, the IP address of the page https://www.ausfuhrplus.internetzollanmeldung.de must also be released: 80.245.152.46."

The issue is that we can neither open the program as is, nor access it via the website which leads me to believe the issue has nothing to do with our browser but rather the system itself. We don’t use a proxy server and only have the default settings for firewalld as it comes with installing Fedora 40.

I am also unsure on how to set up an exception for the firewall, so my only attempt to work around that was to temporarily turn it off.

I think this issue might not be with Fedora after all, I think it has to do with your gateway/router or firewall appliance connecting Fedora to the internet. Have you tried to access the software locally and see if the issue goes away? (if you even can).

You could also remove your concerns regarding Fedora being the issue by temporarily setting it up on a virtual machine with a different (supported) OS and check if the problem persists.

1 Like

In what way do you mean accessing it locally?
We do have the software installed and running on a different pc in the same network, which is running on Fedora 39, however someone else set that up and we don’t know what they did differently. It also works perfectly fine on Windows 11.

I will try loading up a virtual machine with a different OS if I can.

That works for me, it is unnecessary to perform the suggested test I mentioned at that point, since it works on other systems. We are back on Fedora 40 and possibly the configurations of it being the issue. Works on Fedora 39 and Windows 11.

My suggestion of trying it locally came from trying to remove variables (Aka whatever your firewall is) and single out the error. You got that info already.

I hope someone else here is able to assist you.

Best of luck.

Thanks so far for your suggestions, we will try further.

FYI: ssh has nothing to do with SSL.

That error sounds like you have an enterprise content inspecting proxy/firewall between your system and the internet.

Is that the setup?

If it is you should talk to your network admin and tell them about the issue.
They may need to add a bypass for IAAPlus (assuming they approve of its use).