NaN
:gun_error : {:stream_error, :protocol_error, :"Stream reset by server."}
In Phoenix. The stream ref is created, but somewhere before upgrade the above error presents itself. The request is never passed to &Node.Socket.init/2 Non-tls connection work fine.
Certs from GlobalSign. The same cert works fine over the web for Phx.
Any ideas??
{:gun, "~> 2.0"}
{:plug_cowboy, "~> 2.5"}
server:
defmodule Node.Server do
use GenServer
def start_link(opts) do
GenServer.start_link(__MODULE__, opts, name: __MODULE__)
end
def init(opts) do
routes = [
{:_,
[
{"/", Node.Socket, []}
]}
]
# Compile the routes into a dispatch list
dispatch = :cowboy_router.compile(routes)
{protocol, start_fn, opts} =
case System.get_env("IS_DOCKER") do
"true" ->
{:https, &:cowboy.start_tls/3,
[
{:port, opts.port},
{:cacertfile, "/app/priv/ssl/http/ca.crt"},
{:certfile, "/app/priv/ssl/http/server.crt"},
{:keyfile, "/app/priv/ssl/http/server.key"},
]}
_ ->
{:http, &:cowboy.start_clear/3,
[
{:port, opts.port}
]}
end
{:ok, _} =
start_fn.(
protocol,
opts,
%{
env: %{dispatch: dispatch}
}
)
{:ok, %{}}
end
end
client:
defp connect_to_node({admin_domain, admin_port, port} = node, token, state) do
admin_domain = admin_domain |> String.to_charlist()
options =
case System.get_env("IS_DOCKER") do
"true" ->
%{
transport: :tls,
tls_opts: [
{:port, port},
{:verify, :verify_peer},
{:server_name_indication, admin_domain},
{:customize_hostname_check, [{:match_fun, :public_key.pkix_verify_hostname_match_fun(:https)}]},
{:cacerts, :public_key.cacerts_get()}
]
}
_ ->
%{
tcp_opts: [{:port, port}]
}
end
{:ok, conn_pid} = :gun.open(admin_domain, admin_port, options)
Logger.debug("Attempting to connect to Admin Node @ #{admin_domain}:#{admin_port} from local port #{port}")
case :gun.await_up(conn_pid) do
{:ok, _} ->
token = token || fetch_token()
headers = %{
"authorization" => "#{token}"
}
# created fine here
stream_ref = :gun.ws_upgrade(conn_pid, ~c"/", headers) |> IO.inspect()
Node.Identity.set(%{
connected_node: node
})
if Node.Identity.get().primary_node != node do
:timer.send_after(900_000, self(), :connect_to_primary)
end
{:ok, %{state | conn_pid: conn_pid, stream_ref: stream_ref}}
{:error, error} ->
Logger.debug("Failed to connect to Admin Node @ #{admin_domain}:#{admin_port} from local port #{port} | Error: #{inspect(error)}")
:gun.shutdown(conn_pid)
{:error, state}
end
end
Node.Socket.inti : (again, non-tls auths fine, but this is never called when using tls)
def init(req, _opts) do
Logger.debug("Initiating websocket connection with request: #{inspect(req)}")
case Map.get(req.headers, "authorization") do
nil ->
:cowboy_req.reply(401, req)
{:cowboy_websocket, req, %{}}
auth ->
{:ok, shared_key} = Node.Identity.shared_key()
case Node.Auth.decrypt(auth, shared_key) do
{:ok, _decrypted} ->
{:cowboy_websocket, req, %{}, %{idle_timeout: :infinity}}
_ ->
:cowboy_req.reply(401, req)
{:cowboy_websocket, req, %{}}
end
end
end
1/9/23 ~6:30 moved due to cat mistake
Trending in Questions
Hello!
Suppose you are building workflow (order / task / payment) processing system with the following requirements:
Each workflow con...
New
Hey guys,
I’ve got a huge CSV ( around 10 GB ) that needs to be processed hourly
Do you guys have any suggestions what is the best prac...
New
Kia ora,
We have been using elixir-google-api to connect to Google Drive. However, with the updates to Tesla due to CVEs this is now bro...
New
Hello!
Could someone please give me a help/sample code, how to delete a file from s3 using waffle/waffle_ecto from Phoenix app.
I creat...
New
I have what I’ve heard referred to as a “lookup table” in my database. This is a way of assigning codes to common values. One common lo...
New
Hello,
I’m developing a online persistent chat system (what’s app) like using elixir/dynamodb/aws for a mobile app(flutter).
The diffic...
New
What approach to take when sending live updates to “random” users Hi! I have a question, I have a little chat app, and when I create a DM...
New
Other Trending Topics
Hobbes is a low-level distributed database for the Elixir programming language.
Hobbes provides a simple, safe, and scalable storage lay...
New
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge & Solve.
They are GUI (Emerge) and State management (S...
New
Corex is an accessible, unstyled UI component library for Phoenix that integrates Zag.js state machines using Vanilla JavaScript and Live...
New
There are three potential reasons for members of this forum to have a look at https://vutuv.de
You are tired or annoyed of LinkedIn.
Yo...
New
Latest Phoenix Threads
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #deployment
- #library
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #channels
- #elixirconf
- #exunit
- #discussion
- #code-sync
- #javascript
- #podcasts
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixir-ls
- #blog-post
- #ai
- #phoenix_html
- #iex
- #elixirconf-us
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #hex
- #security
- #metaprogramming










Showing Posts 1 to 10- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
Tyson
My guess would be TLS handshake failure because your cacerts don’t match. Where are you getting
/app/priv/ssl/http/*from on the server?NaN
GlobalSign
NaN
It gets past the handshake. fails at upgrade, unless I dont understand the process.
Tyson
What if you configure the client and server to both use the GlobalSign cacert?
NaN
same error:
Tyson
Does it help if you use a self-signed cert?
NaN
The same cert works fine over the web.
Tyson
Then we’ll have to wait for some smarter experts to show up
NaN
No worries. TY… its just as likely you mention something that solves it. worst case someone learns something.
NaN
I have used multiple sets of
tls_optsat this point.verify_none, withcacerts, with acacertfile, etc… all of them render the same error fromrst_stream_frameunless of course I dont pass the opts needed to get past handshake. In which case I can see the hand shake fail on server and clientthis is the only place I can find in the code that produces the error… any idea why?