Codball
Been trying to generate a self-signed certificate for HTTPS testing on a webserver hosted on an AWS EC2 instance. When I run MIX_ENV=prod mix phx.server I get the error:
19:09:05.450 [error] Failed to start Ranch listener BlackbookWeb.Endpoint.HTTPS in
:ranch_ssl:listen([cacerts: :..., key: :..., cert: :..., alpn_preferred_protocols: ["h2", "http/1.1"],
next_protocols_advertised: ["h2", "http/1.1"], reuse_sessions: true, secure_renegotiate: true, certfile:
'/home/ubuntu/documents/blackbook/_build/prod/lib/blackbook/priv/cert/selfsigned.pem', keyfile:
'/home/ubuntu/documents/blackbook/_build/prod/lib/blackbook/priv/cert/selfsigned_key.pem', port: 443]) for
reason :eacces (permission denied)
Did I generate the cert wrong with mix phx.gen.cert?
When I try setting up Let’s Encrypt using certbot certonly it gives me a failed authorization procedure as well.
I’ve added only: ~w(css fonts images js favicon.ico robots.txt .well-known) to my endpoint.ex under Plug.Static.
My config looks like:
config :blackbook, BlackbookWeb.Endpoint,
load_from_system_env: true,
http: [port: 4000],
server: true,
secret_key_base: Application.get_env(:blackbook, :secret_key_base),
url: [host: "bb.bba.com", port: 443],
cache_static_manifest: "priv/static/cache_manifest.json",
https: [port: 443,
otp_app: :blackbook,
keyfile: Application.get_env(:blackbook, :keyfile),
certfile: Application.get_env(:blackbook, :certfile)
],
force_ssl: [hsts: true]
Having trouble finding my error. Do I need to tell my Ubuntu EC2 instance to listen on 443? My admin says he has forwarded the port already, though it’s possible he did it incorrectly.
Trending in Questions
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
Hello,
I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
Documentation
While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
Hi everyone,
I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding.
I sta...
New
So my question is quite simple and i have found no conclusive answer on forum, google or AI.
Should we use :erlang.float for Integer to ...
New
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
I’m new to elixir and just tried to install the elixirLS extension for VScode(ium) and it is throwing some errors that I would like help ...
New
Other Trending Topics
Edit: 2026 May 15 - This post is archived.
Mob is alive!!
Main docs: mob v0.7.11 — Documentation
A bit of explanation for the slightly c...
New
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
I am happy to introduce the very α version of the new programming language compiled to BEAM.
Welcome Cure.
It has literally three kille...
New
Hobbes is a low-level distributed database for the Elixir programming language.
Hobbes provides a simple, safe, and scalable storage lay...
New
Hi there! We created Gust: A task orchestrator inspired by Airflow.
For those who have never heard about Aiflow, it’s a Python-based wor...
New
Hi everyone!
The first release candidate for the Expert language server project is now available!
We’ve published a press release detai...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #ai
- #elixirconf-us
- #blog-post
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #elixirconf-eu
- #metaprogramming
- #hex










Showing Posts 1 to 9- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
alexgaribay
To me, that looks like the app doesn’t have permission to read the cert files.
Codball
how do I give it permission to read the cert files?
idi527
With
chmod, probably.Codball
Do you have an example? Relatively new to Ubuntu.
yurko
whoamiunder the same user that you run mix tasks will give you the username, thensudo chown -R username:username /home/ubuntu/documents/blackbookto make this user (and their group) own the project root and all dirs / files recusrsivelyNobbZ
Standard users are usually not allowed to listen on ports lower than 1024. You need to use another port.
I do assume, that
/home/ubuntu/is the homefolder of the user that you are using to run the application. And I therefore I usually assume that the certificates have proper permissions set.Gazler
There was recently a PR with a very detailed guide on this topic opened on Plug.
https://github.com/elixir-plug/plug/pull/803
patrickdm
thanks @NobbZ, that was a good hint for me! (+ a note for my-future-self: check What's the best way to serve restricted ports (e.g. 80, 443) with Phoenix?
SZJX
For some reason the
chownstill didn’t work in my case. I had to start the server with sudo:sudo MIX_ENV=prod mix phx.server. It might have something to do with the way this particular server is configured.