From: Brian Candler Date: 2010-09-01T17:37:10+09:00 Subject: Re: certificate verify failed Charles Rajesh wrote: > > Am using a X509 PEM certificate with the key for integrating a payment > gateway api. > But am not able to establish the SSL connection as the certificate > verification fails.. It looks like there are two certificate verifications going on: * the server verifying your client certificate * the ruby client verifying the server's certificate and possibly it's the second which is failing. Is the server's certificate signed by a standard CA, or your own CA, or self-signed? Try the following on the command line: openssl s_client -connect server.host.name:443 What does the verify result show? If it's not 0 (OK) then an error will be shown. What is it? If the server.host.name certificate is signed by your own CA, then try openssl s_client -CAfile /path/to/cacert.pem -connect server.host.name:443 where cacert.pem is your CA's root certificate. If that verifies, then use http.ca_file = .... to do the same in the Ruby client. You can see this documented in /usr/lib/ruby/1.8/net/https.rb (or wherever it is on your system) Or, you could install your CA's cert into openssl's global certificate directory. How to do this varies from system to system, and may involve you using the c_rehash script. HTH, Brian. -- Posted via http://www.ruby-forum.com/.