$ sudo pacman-mirrors -c Global -i -fc
::INFO Downloading mirrors from Manjaro
::INFO => Mirror pool: https://repo.manjaro.org/mirrors.json
::INFO => Mirror status: https://repo.manjaro.org/status.json
::INFO Using custom mirror file
::INFO Querying mirrors - This may take some time
0.191 Global : https://mirrors.manjaro.org/repo/
0.201 Global : https://mirrors2.manjaro.org/
0.150 Global : https://mirrors.cicku.me/manjaro/
It’s a blessing in disguise. You taught me a good command.
I was able to remove the site in question. It may not be what you intended. I’m glad I asked. I’m happy.
In my environment, only this server is not synchronized with UNSTABLE. However, the mirror check page shows that it is synchronized. I have no intention of arguing at all.
I prioritize domestic
I don’t think anyone is interested, but the following is the server I use. I prioritize domestic, followed by global.
Mirror #1 OK 03:08 Japan https://mirrors.xtom.jp/manjaro/
Mirror #2 OK 00:45 Japan http://ftp.tsukuba.wide.ad.jp/Linux/manjaro/
Mirror #3 OK 00:45 Japan https://mirror.phoepsilonix.love/manjaro/
Mirror #4 OK 00:05 Global https://mirrors2.manjaro.org/
Mirror #5 OK 00:05 Global https://mirrors.manjaro.org/repo/
omano ~ $ lang=C sudo pacman-mirrors -c Global
::INFO Downloading mirrors from Manjaro
::INFO => Mirror pool: https://repo.manjaro.org/mirrors.json
::INFO => Mirror status: https://repo.manjaro.org/status.json
::INFO User generated mirror list
::------------------------------------------------------------
::INFO Custom mirror file saved: /var/lib/pacman-mirrors/custom-mirrors.json
::INFO Using custom mirror file
::INFO Querying mirrors - This may take some time
0.167 Global : https://mirrors.manjaro.org/repo/
0.179 Global : https://mirrors2.manjaro.org/
..... Global : https://mirrors.cicku.me/manjaro/
::ERROR Connection: HTTPSConnectionPool(host='mirrors.cicku.me', port=443): Max retries exceeded with url: /manjaro/unstable/core/x86_64/core.db.tar.gz (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1028)')))
::INFO Writing mirror list
::Global : https://mirrors.manjaro.org/repo/unstable/$repo/$arch
::Global : https://mirrors2.manjaro.org/unstable/$repo/$arch
::INFO Mirror list generated and saved to: /etc/pacman.d/mirrorlist
::INFO To reset custom mirrorlist 'sudo pacman-mirrors -id'
::INFO To remove custom config run 'sudo pacman-mirrors -c all'
::ERROR Connection: HTTPSConnectionPool(host=‘mirrors.cicku.me’, port=443): Max retries exceeded with url: /manjaro/unstable/core/x86_64/core.db.tar.gz (Caused by SSLError(SSLCertVerificationError(1, ‘[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1028)’)))
This mirror seems problematic since a few weeks I would say. From a web browser I don’t see the issue with the certificate.
From a terminal
omano ~ $ openssl s_client -connect mirrors.cicku.me:443 -showcerts
Connecting to 104.18.130.116
CONNECTED(00000003)
depth=2 C=US, O=SSL Corporation, CN=SSL.com TLS Transit ECC CA R2
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=1 C=US, O=CLOUDFLARE, INC., CN=Cloudflare TLS Issuing ECC CA 1
verify return:1
depth=0 CN=mirrors.cicku.me
verify return:1
---
Certificate chain
0 s:CN=mirrors.cicku.me
i:C=US, O=CLOUDFLARE, INC., CN=Cloudflare TLS Issuing ECC CA 1
a:PKEY: EC, (prime256v1); sigalg: ecdsa-with-SHA256
v:NotBefore: Apr 1 16:03:57 2025 GMT; NotAfter: Jun 30 16:11:28 2025 GMT
-----BEGIN CERTIFICATE-----
MIID7DCCA5KgAwIBAgIQaMn7ile3xSu7ddpGbJ/5cTAKBggqhkjOPQQDAjBSMQsw
CQYDVQQGEwJVUzEZMBcGA1UECgwQQ0xPVURGTEFSRSwgSU5DLjEoMCYGA1UEAwwf
Q2xvdWRmbGFyZSBUTFMgSXNzdWluZyBFQ0MgQ0EgMTAeFw0yNTA0MDExNjAzNTda
Fw0yNTA2MzAxNjExMjhaMBsxGTAXBgNVBAMMEG1pcnJvcnMuY2lja3UubWUwWTAT
BgcqhkjOPQIBBggqhkjOPQMBBwNCAAReEQbUIM69V8zDDBCIQR50TIQMePia9/Hg
wuymFcHkOjfMHtlh2nmpEWJDQkz0SnIlJbXRLATsXzuv7dC6gTvHo4ICfzCCAnsw
DAYDVR0TAQH/BAIwADAfBgNVHSMEGDAWgBScxAlyRxgXe6caibOSNdXhA4z+kjBs
BggrBgEFBQcBAQRgMF4wOQYIKwYBBQUHMAKGLWh0dHA6Ly9pLmNmLWIuc3NsLmNv
bS9DbG91ZGZsYXJlLVRMUy1JLUUxLmNlcjAhBggrBgEFBQcwAYYVaHR0cDovL28u
Y2YtYi5zc2wuY29tMC8GA1UdEQQoMCaCEG1pcnJvcnMuY2lja3UubWWCEioubWly
cm9ycy5jaWNrdS5tZTAjBgNVHSAEHDAaMAgGBmeBDAECATAOBgwrBgEEAYKpMAED
AQEwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMD4GA1UdHwQ3MDUwM6Ax
oC+GLWh0dHA6Ly9jLmNmLWIuc3NsLmNvbS9DbG91ZGZsYXJlLVRMUy1JLUUxLmNy
bDAOBgNVHQ8BAf8EBAMCB4AwDwYJKwYBBAGC2kssBAIFADCCAQQGCisGAQQB1nkC
BAIEgfUEgfIA8AB3AKLjCuRF772tm3447Udnd1PXgluElNcrXhssxLlQpEfnAAAB
lfIhiJAAAAQDAEgwRgIhANqIhOpsW+d1sqt30MZfRHHbP1q0TbhZ82T8FWxCzB27
AiEA0PNpF9ZBvuOZ8eXIHbv9HbjjNghLCoG54A6BieJyFDoAdQDM+w9qhXEJZf6V
m1PO6bJ8IumFXA2XjbapflTA/kwNsAAAAZXyIYi9AAAEAwBGMEQCIA5zEH5IBb/o
myJTDHRD9dNGaOtS7oEEvMi+WN3J1sTdAiBCk/yP+Ii8tSh7LCGrR8IhEAuTCduN
vsEb9GSUM+AYfjAKBggqhkjOPQQDAgNIADBFAiEA7peBAbs0wZUEpk2dKVBrlE22
VEvl58rMQQUzu/D5dbACIELR0yLQ/TGG3CIeHPnqYv/PJi2trguIu8BXyMTY9rZM
-----END CERTIFICATE-----
1 s:C=US, O=CLOUDFLARE, INC., CN=Cloudflare TLS Issuing ECC CA 1
i:C=US, O=SSL Corporation, CN=SSL.com TLS Transit ECC CA R2
a:PKEY: EC, (prime256v1); sigalg: ecdsa-with-SHA384
v:NotBefore: Oct 31 17:17:49 2023 GMT; NotAfter: Oct 28 17:17:48 2033 GMT
-----BEGIN CERTIFICATE-----
MIIC5DCCAmqgAwIBAgIQLD+iaS9BE707f+W2BLSdTTAKBggqhkjOPQQDAzBPMQsw
CQYDVQQGEwJVUzEYMBYGA1UECgwPU1NMIENvcnBvcmF0aW9uMSYwJAYDVQQDDB1T
U0wuY29tIFRMUyBUcmFuc2l0IEVDQyBDQSBSMjAeFw0yMzEwMzExNzE3NDlaFw0z
MzEwMjgxNzE3NDhaMFIxCzAJBgNVBAYTAlVTMRkwFwYDVQQKDBBDTE9VREZMQVJF
LCBJTkMuMSgwJgYDVQQDDB9DbG91ZGZsYXJlIFRMUyBJc3N1aW5nIEVDQyBDQSAx
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEByHHIHytNSzTS+F3JA7hHMDGd2cp
cY9i3MLTKmE6DJTKc6JwvW50pwKodvd2Qj4RAAy2jSejsVgw5jeh6syt3KOCASMw
ggEfMBIGA1UdEwEB/wQIMAYBAf8CAQAwHwYDVR0jBBgwFoAUMqLH2FiL/3/APPJV
aTPszswfvJcwSAYIKwYBBQUHAQEEPDA6MDgGCCsGAQUFBzAChixodHRwOi8vY2Vy
dC5zc2wuY29tL1NTTC5jb20tVExTLVQtRUNDLVIyLmNlcjARBgNVHSAECjAIMAYG
BFUdIAAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMD0GA1UdHwQ2MDQw
MqAwoC6GLGh0dHA6Ly9jcmxzLnNzbC5jb20vU1NMLmNvbS1UTFMtVC1FQ0MtUjIu
Y3JsMB0GA1UdDgQWBBScxAlyRxgXe6caibOSNdXhA4z+kjAOBgNVHQ8BAf8EBAMC
AYYwCgYIKoZIzj0EAwMDaAAwZQIxAL0Sk3RweR6uG1aSHF3JgHQptubP9xoZyUmz
HSa+SSdY5wTGSx5qAowrLPCpLio2PAIwXQGgYzf5QzD/1Bsu87WrUcIVtLixr5KQ
wKBaFAyIJ7OOiWgW0HV/NA1UeuSe0zmN
-----END CERTIFICATE-----
2 s:C=US, O=SSL Corporation, CN=SSL.com TLS Transit ECC CA R2
i:C=GB, ST=Greater Manchester, L=Salford, O=Comodo CA Limited, CN=AAA Certificate Services
a:PKEY: EC, (secp384r1); sigalg: sha256WithRSAEncryption
v:NotBefore: Jun 21 00:00:00 2024 GMT; NotAfter: Dec 31 23:59:59 2028 GMT
-----BEGIN CERTIFICATE-----
MIID0DCCArigAwIBAgIRAK2NLfZGgaDTZEfqqU+ic8EwDQYJKoZIhvcNAQELBQAw
ezELMAkGA1UEBhMCR0IxGzAZBgNVBAgMEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4G
A1UEBwwHU2FsZm9yZDEaMBgGA1UECgwRQ29tb2RvIENBIExpbWl0ZWQxITAfBgNV
BAMMGEFBQSBDZXJ0aWZpY2F0ZSBTZXJ2aWNlczAeFw0yNDA2MjEwMDAwMDBaFw0y
ODEyMzEyMzU5NTlaME8xCzAJBgNVBAYTAlVTMRgwFgYDVQQKDA9TU0wgQ29ycG9y
YXRpb24xJjAkBgNVBAMMHVNTTC5jb20gVExTIFRyYW5zaXQgRUNDIENBIFIyMHYw
EAYHKoZIzj0CAQYFK4EEACIDYgAEZOd9mQNTXJEe6vjYI62hvyziY4nvKGj27dfw
7Ktorncr5HaXG1Dr21koLW+4NrmrjZfKTCKe7onZAj/9enM6kI0rzC86N4PaDbQt
RRtzcgllX3ghPeeLZj9H/Qkp1hQPo4IBJzCCASMwHwYDVR0jBBgwFoAUoBEKIz6W
8Qfs4q8p74Klf9AwpLQwHQYDVR0OBBYEFDKix9hYi/9/wDzyVWkz7M7MH7yXMA4G
A1UdDwEB/wQEAwIBhjASBgNVHRMBAf8ECDAGAQH/AgEBMB0GA1UdJQQWMBQGCCsG
AQUFBwMBBggrBgEFBQcDAjAjBgNVHSAEHDAaMAgGBmeBDAECATAOBgwrBgEEAYKp
MAEDAQEwQwYDVR0fBDwwOjA4oDagNIYyaHR0cDovL2NybC5jb21vZG9jYS5jb20v
QUFBQ2VydGlmaWNhdGVTZXJ2aWNlcy5jcmwwNAYIKwYBBQUHAQEEKDAmMCQGCCsG
AQUFBzABhhhodHRwOi8vb2NzcC5jb21vZG9jYS5jb20wDQYJKoZIhvcNAQELBQAD
ggEBAB4oL4ChKaKGZVZK8uAXjj8wvFdm45uvhU/t14QeH5bwETeKiQQXBga4/Nyz
zvpfuoEycantX+tHl/muwpmuHT0Z6IKYoICaMxOIktcTF4qHvxQW2WItHjOglrTj
qlXJXVL+3HCO60TEloSX8eUGsqfLQkc//z3Lb4gz117+fkDbnPt8+2REq3SCvaAG
hlh/lWWfHqTAiHed/qqzBSYqqvfjNlhIfXnPnhfAv/PpOUO1PmxCEAEYrg+VoS+O
+EBd1zkT0V7CfrPpj30cAMs2h+k4pPMwcLuB3Ku4TncBTRyt5K0gbJ3pQ0Rk9Hmu
wOz5QAZ+2n1q4TlApJzBfwFrCDg=
-----END CERTIFICATE-----
---
Server certificate
subject=CN=mirrors.cicku.me
issuer=C=US, O=CLOUDFLARE, INC., CN=Cloudflare TLS Issuing ECC CA 1
---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: ecdsa_secp256r1_sha256
Negotiated TLS1.3 group: X25519MLKEM768
---
SSL handshake has read 4140 bytes and written 1629 bytes
Verification error: unable to get local issuer certificate
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Protocol: TLSv1.3
Server public key is 256 bit
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 20 (unable to get local issuer certificate)
---