WARNING: THIS SITE IS A MIRROR OF GITHUB.COM / IT CANNOT LOGIN OR REGISTER ACCOUNTS / THE CONTENTS ARE PROVIDED AS-IS / THIS SITE ASSUMES NO RESPONSIBILITY FOR ANY DISPLAYED CONTENT OR LINKS / IF YOU FOUND SOMETHING MAY NOT GOOD FOR EVERYONE, CONTACT ADMIN AT ilovescratch@foxmail.com
Skip to content

apache reverse-proxy error #4099

@mqu

Description

@mqu

Description of problem

I have Kiwi-TCSM 13.5 behind apache reverse-proxy having this error when I open URL of application (error 500) :

Proxy Error
The proxy server could not handle the request

Reason: Error during SSL Handshake with remote server

Version or commit hash (if applicable)

Kiwi-TCSM 13.5


did not understand why having this error, tried many things before finding internal Kiwi-TCMS certificate was expired :

openssl s_client -connect localhost:EXTERNAL-PORT
...
Certificate chain
 0 s:C = BG, L = Sofia, O = Kiwi TCMS, OU = Quality Engineering, CN = buildkitsandbox
   i:C = BG, L = Sofia, O = Kiwi TCMS, OU = ca-9030488614878644057, CN = buildkitsandbox
   a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
   v:NotBefore: Aug  6 20:03:40 2024 GMT; NotAfter: Sep  8 20:03:40 2025 GMT

apache configuration

Applying this configuration allow Apache Reverse-proxy to deliver Kiwi-TCSM again (SSLProxyCheckPeerExpire):

    SSLProxyEngine On
    SSLProxyCheckPeerCN Off
    SSLProxyCheckPeerName Off
    SSLProxyVerify none
    SSLProxyCheckPeerExpire off

It is now impossible to make Kiwi-TCSM expose on HTTP (80) port without SSL. Default certificate is not (may not) be valid for 10 years.

related links and docs

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions