Re: inetc / ssl problem

Ingela Andin <[email protected]>
Newsgroups gmane.comp.lang.erlang.general
Message-ID <CAFj9NSRp3KW9kbScjXSwCmbZM0HSUfavuapA4R4rw8Sa7dNUMw@mail.gmail.com>
Hi!

Because you are just enforcing the insecure default of not verifying the
certificate path!
If you want to get rid of the warning you need to use {verify, verify_peer}
and then you also need
to supply  some trusted certs.  One of the reasons for the default is just
that, that the secure way requires more config.

Regards Ingela Erlang/OTP Team - Ericsson AB

Den tors 2 sep. 2021 kl 14:07 skrev Eckard Brauer <[email protected]>:

> Hello,
>
> I'm bit stuck with trying to avoid an ssl warning when retrieving a
> HTTPS page like that:
>
> ssl:start(),
> inets:start(),
> Url = "https://www.heise.de/newsticker",
> {ok, {{_, 200,__}, _,  Contents}} =
>         httpc:request(get,
>                       {Url, []},
>                       [{ssl, [{verify, verify_none}]}],
>                       []).
>
> getting that:
> =WARNING REPORT==== 2-Sep-2021::13:46:08.010679 ===
> Description: "Authenticity is not established by certificate path
> validation"
>      Reason: "Option {verify, verify_peer} and cacertfile/cacerts is
> missing"
> ...
>
>
> What's the reason the warning won't go away with the ssl verify option -
> where's my fault?
>
> Thanks in advance
> Eckard
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.