Showing posts with label ssl. Show all posts
Showing posts with label ssl. Show all posts

Thursday, May 23, 2024

Quasar failed to proxy pass via https

When failed to proxy pass with https in Quasar framework, it is very likely that the target-host HTTPS are configured incorrectly.  As a workaround, you can modify the quasar.conf.js with secure:false as following:

        "/context/path1/": {
          target: "https://target-host/path1/",
          secure: false,
          changeOrigin: true,
          pathRewrite: {
            "^/context/path1/": "",
          },
        },


Sunday, July 19, 2020

Tuesday, July 14, 2020

curl returns "ssl_choose_client_version:unsupported protocol" error in Ubuntu 20.x

If you encountered "ssl_choose_client_version:unsupported protocol" when using curl in Ubuntu 20:

    $ curl https://somehost/
 
curl: (35) error:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol


It may because the "somehost" only accepts old protocol (e.g. TLS v1, etc.), but in Ubuntu 20.x, the OpenSSL assumes minimum = TLS v1.2 by default. 

If the "somehost" just cannot upgrade to TLS v1.2, you might consider fixing it with the following:

1) Modify /etc/ssl/openssl.cnf

Search for the line "oid_section = new_oids"

Add the following lines below it:

openssl_conf = default_conf

[default_conf]
ssl_conf = ssl_sect

[ssl_sect]
system_default = system_default_sect

[system_default_sect]
MinProtocol = TLSv1.1
CipherString = DEFAULT@SECLEVEL=1

2) curl "somehost" with the following parameters

$ curl --tlsv1 https://somehost

3) If the "somehost" just using a self-signed certificate

    $ curl -k --tlsv1 https://somehost

Reference:



CSP on Apache

To add CSP to root if sort of funny. The following will NOT work for most cases !!     <LocationMatch "^/$">        Header s...