Skip to content

Webex Is Looking For Your Certificates On A Cisco Build Server

Webex 46.8.0.35631 on Fedora 44 sits behind a yellow banner reading “Offline - No internet connection” while every other program on the machine reaches the internet without complaint. It stopped the VoIP line dead. The network was never the problem: Cisco bundle their own fork of OpenSSL and built it with OPENSSLDIR set to /workspace/.conan2/p/b/cisco8ee8b59cf93de/p/ssl, a directory that exists on a build container and nowhere else, so it loads no trust anchors and every handshake fails. The post runs in order: what the broken state actually is, asking the shipped library where it thinks its certificates live, reproducing the exact error code outside Webex, why nothing warns you, the two fixes that do not work and why, and the one that does. Then the build process: they used $ORIGIN for the code and left three data paths absolute, the RPM header names a container ID so the container was already in the pipeline and never used to run the result, the package requires a glibc from 2018 because they will not link statically, 2.2 GB is shipped twice, and it carries no documentation and no file marked as configuration. Then how it should have been built, the six fixes and the one-line check that catches it. And finally the cross-check: Cisco hold 98 entries in CISA’s known-exploited catalogue, second only to Microsoft, and a trust path nobody checked and a bypass nobody checked are the same failure at different stakes.

15th September 2026 Â· 42 min Â· 9141 words Â· Damien Dye

IPsec Was a Good Idea. It Is Time to Turn It Off.

IPsec was right in 1995: encrypt below the application, bind the security association to the IP address, let every protocol inherit it. Then NAT arrived, carrier-grade NAT finished the job, and the fix was to wrap the whole thing in UDP and keep a timer running so a translation table would not forget you. This post shows how it falls down, diagram by diagram — the security association that cannot survive a rewritten header, the two translators every CGNAT line now has, the NAT64 standard that names IPsec as out of scope, the tunnel that cannot use a second link because ESP has no ports, the MTU nobody owns, and L2TP and PPTP as the two protocols that were never fit to be here. It carries the vendor documentation from Cisco, Juniper and Microsoft that admits every one of those, the eighteen pieces that call themselves an IPsec VPN including the two that were never standards at all, why the Fisher-Price OS has never truly interoperated with an open stack, a working method for diagnosing IPsec while you still run it, and the case for retiring the lot with dates.

13th September 2026 Â· 68 min Â· 16979 words Â· Damien Dye

Is Your MSP Lying To You To Sell You Premium Products?

Part 1 of 3. Some are lying. Most never have to, because they are paid by the vendor whose product they are recommending and nobody has to tell you. The tells that say you are being sold to rather than engineered for, and what never makes it onto the shortlist.

28th August 2026 Â· 41 min Â· 8599 words Â· Damien Dye

What Your MSP Built You, And Who Else Can Reach It

Part 2 of 3. What actually gets built once the paperwork is signed: cloud for a business with one building, the box they will not be talked out of, the basics that were the thing you bought, and the agent on every machine that answers to somebody else’s console.

28th August 2026 Â· 39 min Â· 8289 words Â· Damien Dye