From: "Gerald A." Date: 2010-10-19T01:14:41+09:00 Subject: Re: Ubuntu, SSL, Ruby 1.9.2 Oops, forgot the chain: Certificate chain 0 s:/O=www.mydomain.com/OU=Domain Control Validated/CN=www.mydomain.com i:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certificates.godaddy.com/repository/CN=Go Daddy Secure Certification Authority/serialNumber=07969287 Gerald A. wrote in post #955157: > Brian, Thanks for response. Sure enough, it's still not verifying: > > depth=0 /O=www.mydomain.com/OU=Domain Control > Validated/CN=www.mydomain.com > verify error:num=20:unable to get local issuer certificate > verify return:1 > depth=0 /O=www.mydomain.com/OU=Domain Control > Validated/CN=www.mydomain.com > verify error:num=27:certificate not trusted > verify return:1 > depth=0 /O=www.mydomain.com/OU=Domain Control > Validated/CN=www.mydomainj.com > verify error:num=21:unable to verify the first certificate > verify return:1 > > I guess I'll start googling on that, if you have suggestions I'm more > than all ears ; ) > > Thanks! > Gerald > > > Brian Candler wrote in post #955152: >> Gerald A. wrote in post #955125: >>> SSL_connect returned=1 errno=0 state=SSLv3 read server certificate B: >>> certificate verify failed >> >> First, take Ruby out of the loop: use >> >> openssl s_client -CApath /etc/ssl/certs -connect x.x.x.x:p >> >> and if you don't understand what you see, you can post it here. >> >> If s_client verifies OK, but ruby doesn't, then you're probably missing >> the CApath parameter in your ruby code or have pointed it to the wrong >> directory. -- Posted via http://www.ruby-forum.com/.