Repository navigation
Can't connect from ws client to ws server: TLS handshake failure #1227
Copy link
Copy link
Closed
Description
Activity
What happens if you try to connect to your
webserverusing thehttpsmodule? For example:const https = require('https'); const request = https.get({ hostname: 'websocket.example.com', headers: { upgrade: 'websocket', connection: 'Upgrade', 'Sec-WebSocket-Key': 'rfeGe1izPRq2JyonWunAQw==', 'Sec-WebSocket-Version': 13 } }); request.on('error', (err) => console.error(err)); request.on('upgrade', () => console.log('upgraded'));
Does not work too.
Debug output:
NET 4912: pipe false null NET 4912: connect: find host websocket.example.com NET 4912: connect: dns options { family: undefined, hints: 32 } NET 4912: _read NET 4912: _read wait for connection NET 4912: afterConnect TLS 4912: start NET 4912: _read NET 4912: Socket._read readStart NET 4912: afterWrite -71 NET 4912: write failure { Error: write EPROTO 140504342898496:error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure:../deps/openssl/openssl/ssl/s23_clnt.c:772: at _errnoException (util.js:1031:13) at WriteWrap.afterWrite [as oncomplete] (net.js:873:14) errno: 'EPROTO', code: 'EPROTO', syscall: 'write' } NET 4912: destroy NET 4912: close NET 4912: close handle { Error: write EPROTO 140504342898496:error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure:../deps/openssl/openssl/ssl/s23_clnt.c:772: at _errnoException (util.js:1031:13) at WriteWrap.afterWrite [as oncomplete] (net.js:873:14) errno: 'EPROTO', code: 'EPROTO', syscall: 'write' } NET 4912: emit closeShould I open an issue at node repo or do you have an idea?
Yes, I think it makes sense to open an issue in the node repo.
I got it working with the
httpsmodule:const https = require('https'); const request = https.get({ hostname: 'api.fortytwo.cloud.local', headers: { upgrade: 'websocket', connection: 'Upgrade', 'Sec-WebSocket-Key': 'rfeGe1izPRq2JyonWunAQw==', 'Sec-WebSocket-Version': 13 }, rejectUnauthorized: false, // <-- For testing with self signed certificate ecdhCurve: 'auto' // <-- Does the trick }); request.on('error', (err) => console.error(err)); request.on('upgrade', () => console.log('upgraded'));Unfortunately
WebSocketdoes not support theecdhCurvesetting fromtls.createSecureContext.Should it be added to
wsor is there another option?Anyway
ecdhCurve's default value should beauto, I will suggest this in the node repo.Should it be added to ws or is there another option?
Yes, it should. Do you want to open a PR?
I will try to implement this.
- added 2 commits that reference this issue
on Nov 1, 2017
Metadata
Metadata
Assignees
Labels
No labels
Description
If I try to connect with the attached ws client to the attached ws server I get the following error:
But Chrome and Firefox can connect to the ws server, so the problem must be in the ws client.
Reproducible in:
version: 3.2.0
Node.js version(s): 9.0.0
OS version(s): elementary OS 0.4.1 Loki, based on Ubuntu 16.04.3 LTS
Steps to reproduce:
Expected result:
Connecting to websocket without error.
Actual result:
Not connecting to websocket, producing an error.
Attachments:
Debug output:
Websocket Server:
Websocket client: