Rails logging: interpreting which end of API has bad certificate

Viewed 29

The following log entry is curious to this viewer:

app/controllers/telegram_webhooks_controller.rb:64:in `message'
Started POST "/telegram/[uniq_string]" for 91.108.6.62 at 2022-02-22 10:49:02 +0000
Processing by TelegramWebhooksController#message
  Update: {"update_id":222555282,"message":{"message_id":393,"from":{"id" [...}}}
Responded with message
Completed in 7ms

OpenSSL::SSL::SSLError (SSL_connect returned=1 errno=0 state=error: certificate verify failed (certificate has expired)):

• A webhook receives a request. note: the webhook was re-verified with result {"ok":true,"result":true,"description":"Webhook is already set"}

• The webhook controller receives and processes the request with a response message.
• The action is completed
• then an SSL error is raised

Who's certificate would be at fault according to this line of the log? The application's or the Telegram server's?
it would be odd that the application's cert were expired, as otherwise the site would not be accessible for all its other functions AND the webhook was set, presumably with the Telegram verifying the cert before doing so. Even odder that Telegram would operate its server without a cert.

Update the discussion with @Yan has pointed to a trace of solution. nginx configurations were reviewed and certs renewed.

openssl s_client -connect site.example.online:443 -cert certname
Error opening client certificate private key file certname
49295:error:02001002:system library:fopen:No such file or directory:/SourceCache/OpenSSL098/OpenSSL098-52.8.4/src/crypto/bio/bss_file.c:356:fopen('certname','r')
49295:error:20074002:BIO routines:FILE_CTRL:system lib:/SourceCache/OpenSSL098/OpenSSL098-52.8.4/src/crypto/bio/bss_file.c:358:
unable to load client certificate private key file

$ openssl s_client -connect site.example.online:443 -certform format
CONNECTED(00000003)
49310:error:1407742E:SSL routines:SSL23_GET_SERVER_HELLO:tlsv1 alert protocol version:/SourceCache/OpenSSL098/OpenSSL098-52.8.4/src/ssl/s23_clnt.c:593:

openssl version returns OpenSSL 1.1.1f Meanwhile, the web pages are being served via https and verifying the data provided through the browser has no red flags.

0 Answers
Related