# Upgrade Failure - Unable to verify certificate

**URL:** https://meta.discourse.org/t/upgrade-failure-unable-to-verify-certificate/64058
**Category:** Support
**Created:** [June 6, 2017, 8:24pm UTC](https://meta.discourse.org/t/upgrade-failure-unable-to-verify-certificate/64058 "2017-06-06T20:24:03Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![Rob\_Burkman](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Rob\_Burkman](https://meta.discourse.org/u/Rob_Burkman)
#### Post date: [June 6, 2017, 8:24pm UTC](https://meta.discourse.org/t/upgrade-failure-unable-to-verify-certificate/64058/1 "2017-06-06T20:24:03Z")

</div>

A few months ago, I inherited a discourse site that we use internally, so I am pretty new to all of this. In the past, I’ve been able to upgrade smoothly via the one-click browser upgrade feature, but today it failed with the following message. Any help is appreciated!

```
rake aborted!
Excon::Error::Certificate: SSL_connect returned=1 errno=0 state=error: certificate verify failed (OpenSSL::SSL::SSLError) Unable to verify certificate. This may be an issue with the remote host or with Excon. Excon has certificates bundled, but these can be customized:

            `Excon.defaults[:ssl_ca_path] = path_to_certs`
            `ENV['SSL_CERT_DIR'] = path_to_certs`
            `Excon.defaults[:ssl_ca_file] = path_to_file`
            `ENV['SSL_CERT_FILE'] = path_to_file'
            `Excon.defaults[:ssl_verify_callback] = callback`
                (see OpenSSL::SSL::SSLContext#verify_callback)
or:
            `Excon.defaults[:ssl_verify_peer] = false` (less secure).

```

The full [log.pdf](https://global.discourse-cdn.com/meta/original/3X/b/2/b26236d064fa4e3d26f2ae24925e2f10d8b90f30.pdf) (376.0 KB).

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [June 6, 2017, 9:32pm UTC](https://meta.discourse.org/t/upgrade-failure-unable-to-verify-certificate/64058/2 "2017-06-06T21:32:42Z")

</div>

Given that your hostname still resolves to your site, try:

```plaintext
cd /var/discourse
./launcher rebuild app

```

---

<div class="post-metadata">

### Author: ![mpalmer](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mpalmer/32/45740_2.png) [@mpalmer](https://meta.discourse.org/u/mpalmer)
#### Post date: [June 6, 2017, 11:51pm UTC](https://meta.discourse.org/t/upgrade-failure-unable-to-verify-certificate/64058/3 "2017-06-06T23:51:06Z")

</div>

That’s a first… build log as a PDF. I’m not up for reading through that, it’s a mess. Drop it in a gist or a pastebin or something more sane, please.

---

<div class="post-metadata">

### Author: ![robbyoconnor](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/robbyoconnor/32/120330_2.png) [@robbyoconnor](https://meta.discourse.org/u/robbyoconnor)
#### Post date: [June 7, 2017, 12:07am UTC](https://meta.discourse.org/t/upgrade-failure-unable-to-verify-certificate/64058/4 "2017-06-07T00:07:03Z")

</div>

> [@mpalmer](#):
>
> That’s a first… build log as a PDF. I’m not up for reading through that, it’s a mess. Drop it in a gist or a pastebin or something more sane, please.

Also, make sure you read the log – I’ve seen a few people now not bother to read the log – but just panic – take a step back and read it..it’s telling you what’s wrong.

---

<div class="post-metadata">

### Author: ![Rob\_Burkman](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Rob\_Burkman](https://meta.discourse.org/u/Rob_Burkman)
#### Post date: [June 7, 2017, 1:31pm UTC](https://meta.discourse.org/t/upgrade-failure-unable-to-verify-certificate/64058/5 "2017-06-07T13:31:05Z")

</div>

> [@pfaffman](#):
>
> Given that your hostname still resolves to your site, try:
> 
> cd /var/discourse  
> ./launcher rebuild app

I get the same error when I attempt to rebuild the app.

> [@mpalmer](#):
>
> That’s a first… build log as a PDF. I’m not up for reading through that, it’s a mess. Drop it in a gist or a pastebin or something more sane, please.

I created a [gist](https://gist.github.com/rburkman/3df49b3ce83bf691fc63eb0df8e7ed09).

> [@robbyoconnor](#):
>
> Also, make sure you read the log – I’ve seen a few people now not bother to read the log – but just panic – take a step back and read it..it’s telling you what’s wrong.

The only thing that jumped out to me was the error. Am I missing something else?

---

<div class="post-metadata">

### Author: ![mpalmer](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mpalmer/32/45740_2.png) [@mpalmer](https://meta.discourse.org/u/mpalmer)
#### Post date: [June 8, 2017, 5:46am UTC](https://meta.discourse.org/t/upgrade-failure-unable-to-verify-certificate/64058/6 "2017-06-08T05:46:05Z")

</div>

> [@Rob\_Burkman](#):
>
> I created a gist.

A gist! A palpable gist! 🎉

> [@robbyoconnor](#):
>
> it’s telling you what’s wrong

_What_ is wrong is not quite the same thing as _why_ it is going wrong, and in this case, that’s something of a mystery. What’s the environment this is running in? I’m strongly suspecting HTTPS-mangling middlebox as the culprit, given that [https://cdn.discourse.org/](https://cdn.discourse.org/) is most definitely presenting a valid cert. What does `openssl s_client -connect cdn.discourse.org:443 -servername cdn.discourse.org`, run on the host where you’re running `./launcher`, say about the certificate chain being presented? Here’s what it _should_ look like:

```
Certificate chain
 0 s:/C=US/ST=California/L=San Francisco/O=Fastly, Inc./CN=j.ssl.fastly.net
   i:/C=BE/O=GlobalSign nv-sa/CN=GlobalSign Organization Validation CA - SHA256 - G2
 1 s:/C=BE/O=GlobalSign nv-sa/CN=GlobalSign Organization Validation CA - SHA256 - G2
   i:/C=BE/O=GlobalSign nv-sa/OU=Root CA/CN=GlobalSign Root CA

```

---

<div class="post-metadata">

### Author: ![Rob\_Burkman](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Rob\_Burkman](https://meta.discourse.org/u/Rob_Burkman)
#### Post date: [June 8, 2017, 1:38pm UTC](https://meta.discourse.org/t/upgrade-failure-unable-to-verify-certificate/64058/7 "2017-06-08T13:38:22Z")

</div>

I’m getting the following certificate chain.

```
Certificate chain
 0 s:/C=US/ST=California/L=San Francisco/O=Fastly, Inc./CN=j.ssl.fastly.net
   i:/C=US/ST=California/O=Zscaler Inc./OU=Zscaler Inc./CN=Zscaler Intermediate Root CA (zscalertwo.net)/emailAddress=support@zscaler.com
 1 s:/C=US/ST=California/O=Zscaler Inc./OU=Zscaler Inc./CN=Zscaler Intermediate Root CA (zscalertwo.net)/emailAddress=support@zscaler.com
   i:/C=US/ST=California/L=San Jose/O=Zscaler Inc./OU=Zscaler Inc./CN=Zscaler Root CA/emailAddress=support@zscaler.com

```

---

<div class="post-metadata">

### Author: ![Rob\_Burkman](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Rob\_Burkman](https://meta.discourse.org/u/Rob_Burkman)
#### Post date: [June 8, 2017, 7:07pm UTC](https://meta.discourse.org/t/upgrade-failure-unable-to-verify-certificate/64058/8 "2017-06-08T19:07:47Z")

</div>

I was able to successfully upgrade the site after whitelisting `cdn.discourse.org` like this [post](https://meta.discourse.org/t/excon-openssl-problem-on-upgrade/64099/7).

---

<div class="post-metadata">

### Author: ![mpalmer](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mpalmer/32/45740_2.png) [@mpalmer](https://meta.discourse.org/u/mpalmer)
#### Post date: [June 8, 2017, 11:20pm UTC](https://meta.discourse.org/t/upgrade-failure-unable-to-verify-certificate/64058/9 "2017-06-08T23:20:12Z")

</div>

So, SSL middlebox ftl. Lucky you.

---

<div class="post-metadata">

### Author: ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### Post date: [June 8, 2024, 12:44pm UTC](https://meta.discourse.org/t/upgrade-failure-unable-to-verify-certificate/64058/10 "2024-06-08T12:44:42Z")

</div>

This topic was automatically closed after 2558 days. New replies are no longer allowed.
