Specifying a custom certificate chain leads to "unable to get local issuer certificate"-error

Viewed 246

Bear with me please, for I am losing my mind over this. I have changed the name of my domain to example.com in this post for privacy.

The problem

I have a server running nginx with a Letsencrypt TLS certificate. It looks like this according to openssl s_client:

Certificate chain
 0 s:CN = example.com
   i:C = US, O = Let's Encrypt, CN = R3
 1 s:C = US, O = Let's Encrypt, CN = R3
   i:C = US, O = Internet Security Research Group, CN = ISRG Root X1
 2 s:C = US, O = Internet Security Research Group, CN = ISRG Root X1
   i:O = Digital Signature Trust Co., CN = DST Root CA X3

I want make a request to this server in a python script. This script works:

import requests
requests.get('https://example.com/')

To make my script independent from my systems SSL configuration, I have copied the server's certificate fullchain.pem over to my client and specified it in my script:

import requests
requests.get('https://example.com/', verify='/home/jan/fullchain.pem')

This gives me:

ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get issuer certificate (_ssl.c:1131)

What I have tried

  • Maybe the requests module only wants to know the certificate chain without the concrete example.com certificate. So I have deleted the first certificate block from /home/jan/fullchain.pem. Still the same error.

  • I have noticed fullchain.pem doesn't actually include the root certificate. So I have downloaded the root certificate from sslchecker.com and appended it to /home/jan/fullchain.pem. Still the same error.

  • I have noticed that running openssl verify on my server's certificate returns error 20 at 0 depth lookup: unable to get local issuer certificate. Maybe I should also append the root certificate to my server's certificate file. This makes nginx throw an error:

nginx: [emerg] SSL_CTX_set0_chain("/root/.ssl/actualfull.pem") failed (SSL: error:1415418E:SSL routines:ssl_cert_set0_chain:ca md too weak)

My question

  1. Why does openssl verify fail on the unmodified SSL certificate chain provided by letsencrypt?

  2. Why does nginx give an error when I append the root certificate to the chain?

  3. And most importantly: How can I specify the certificate chain in my python script without getting an error?

0 Answers
Related