Bear with me please, for I am losing my mind over this. I have changed the name of my domain to example.com in this post for privacy.
The problem
I have a server running nginx with a Letsencrypt TLS certificate. It looks like this according to openssl s_client:
Certificate chain
0 s:CN = example.com
i:C = US, O = Let's Encrypt, CN = R3
1 s:C = US, O = Let's Encrypt, CN = R3
i:C = US, O = Internet Security Research Group, CN = ISRG Root X1
2 s:C = US, O = Internet Security Research Group, CN = ISRG Root X1
i:O = Digital Signature Trust Co., CN = DST Root CA X3
I want make a request to this server in a python script. This script works:
import requests
requests.get('https://example.com/')
To make my script independent from my systems SSL configuration, I have copied the server's certificate fullchain.pem over to my client and specified it in my script:
import requests
requests.get('https://example.com/', verify='/home/jan/fullchain.pem')
This gives me:
ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get issuer certificate (_ssl.c:1131)
What I have tried
Maybe the requests module only wants to know the certificate chain without the concrete
example.comcertificate. So I have deleted the first certificate block from/home/jan/fullchain.pem. Still the same error.I have noticed
fullchain.pemdoesn't actually include the root certificate. So I have downloaded the root certificate from sslchecker.com and appended it to/home/jan/fullchain.pem. Still the same error.I have noticed that running
openssl verifyon my server's certificate returnserror 20 at 0 depth lookup: unable to get local issuer certificate. Maybe I should also append the root certificate to my server's certificate file. This makes nginx throw an error:
nginx: [emerg] SSL_CTX_set0_chain("/root/.ssl/actualfull.pem") failed (SSL: error:1415418E:SSL routines:ssl_cert_set0_chain:ca md too weak)
My question
Why does
openssl verifyfail on the unmodified SSL certificate chain provided by letsencrypt?Why does nginx give an error when I append the root certificate to the chain?
And most importantly: How can I specify the certificate chain in my python script without getting an error?