Within the past few days we’ve started getting an ...
# pact-broker
n
Within the past few days we’ve started getting an SSL error hitting our pact broker API. (We used the dius/pact-broker). Am i correct in assuming that the problem is probably our client images upgrading OpenSSL such that they’re no longer compatible with the (presumably outdated) TLS version used by the dius/pact-broker?
Copy code
+ pact-broker create-version-tag '--broker-base-url=((redacted))' '--broker-username=((redacted))' '--broker-password=((redacted))' '--pacticipant=((redacted)' '--version=((redacted))' '--tag=pr'
/usr/lib/ruby/3.1.0/net/protocol.rb:46:in `connect_nonblock': SSL_connect returned=1 errno=0 peeraddr=((redacted)):443 state=error: unsafe legacy renegotiation disabled (OpenSSL::SSL::SSLError)
m
hmm that does look like the
pact-broker
client is trying to negotiate an old TLS protocol. I don’t think the issue is the Pact Broker docker image (the runtime), presumably you have a load balancer that is terminating TLS and is configured to only use a certain set of protocols. This error indicates to me the client (
pact-broker
command) is initiating a connection that is failing (at the point of TLS termination) before contacting the actual Pact Broker.
💯 1
That might be one and the same place, i’m not sure
n
interesting, thanks for your thoughts, i’ll investigate this. i saw that the change seemed to coincide with pact-ruby-cli being updated to alpine 3.17 which upgrades OpenSSL to version 3, but perhaps that was a red herring
🤔 1
m
hmm interesting