Duaer

Troubleshooting

Fix Duaer HTTP Request certificate errors such as self-signed certificate

When Duaer HTTP Request calls an internal or test service and fails with self-signed certificate or unable to verify the first certificate, the server certificate is not trusted.

Certificate errors in Duaer

  • self-signed certificate, self-signed certificate in certificate chain: the server uses a self-signed cert or an internal CA.
  • unable to verify the first certificate: the server does not send its intermediate certificate. The browser works and Duaer fails, usually for this reason.
  • certificate has expired: the certificate expired.
  • Hostname/IP does not match certificate's altnames: you call an IP or alias that is not on the certificate.

Fix in this order

  1. Fix the server when you can: renew, serve the full chain (server plus intermediate), and call the name on the certificate. Only this keeps full security.
  2. Self-hosted Duaer calling services signed by an internal CA: mount the CA certificate, set NODE_EXTRA_CA_CERTS to its path, and restart.
  3. Short internal tests only: turn on Ignore SSL Issues (Insecure) under HTTP Request Options. Certificates are no longer checked, so avoid it for public endpoints and sensitive data.

Questions

Why does Duaer HTTP Request fail on a URL the browser opens fine?

Browsers fill in a missing intermediate certificate, Duaer HTTP Request does not. Have the server send the full chain.

Can I use NODE_EXTRA_CA_CERTS on Duaer Cloud?

No. It is an environment variable for self-hosted Duaer. Services called from Duaer Cloud need a publicly trusted certificate.

In this section