"Your site has a certificate error" INC-2440

Open2 versionsNetworking · Hard · Incident · about 45 min ·Linux, root

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Ana Costa opened INC-2440 at 14:44SEV-2

Since 14:40 customers opening the tracking site get a certificate warning, then a 404. The tracking certificate is fine. Nobody touched it.

Two changes landed at 14:31: a new site for the label portal, and what the change log calls "formatting only" for tracking.conf. Both passed nginx -t.

"Customers are calling about a certificate warning. Some clicked through and got a 404. Can you look? The certificate guy says the cert is fine." (Ana)

Your task

Find out which server block is answering for tracking and why, fix it so tracking is served by its own block again, validate and reload nginx, verify from the customer side, and fill in incident/timeline.md. Keep the label portal working and Waybill on its private address.

On the machine

  • curl -v https://tracking.northstar.example/healthz
  • /etc/nginx/sites-enabled/ (tracking.conf, labels.conf), nginx -T
  • /var/log/nginx/
  • /srv/deploy/changes.log

Timeline

14:31Ivo adds a site for the new label portal on the edge and "tidies" tracking.conf.
14:31nginx -t passes. nginx reloads.
14:40Customers see a certificate warning on track.northstar.example.
14:44Ana: support lines are filling up.

Done when

  1. https://tracking.northstar.example/healthz answers from Waybill with normal certificate verification.
  2. The new label portal still works and Waybill stays private.
  3. incident/timeline.md records the change, why it broke tracking, the fix, and how you verified it.

Hints

Hint 1

`curl -v https://tracking.northstar.example/healthz` shows which certificate the edge sends.

Hint 2

Which certificate is that, and which server block owns it?

Hint 3

nginx picks a server block by matching the requested name against `server_name`. If nothing matches, the `default_server` answers; if two blocks claim the same name, the first one loaded wins and `nginx -t` warns about it.

Hint 4

`sudo nginx -T | grep -n server_name` lists every name every block answers for. Fix the block that is wrong, then `sudo nginx -t` and `sudo nginx -s reload`.

Show the solution

`curl -v` shows the label portal's certificate and its 404 for tracking's name. `sudo nginx -T | grep -n server_name` shows why. Either tracking.conf's tidy-up left `server_name trackng.northstar.example` (a missing i), so the name matches no block and the default server, the label portal, answers; or labels.conf, copied from tracking.conf, still lists `tracking.northstar.example`, and because it is read first it wins (`nginx -t` warns about a conflicting server name). Fix the server_name in the block that is wrong, run `sudo nginx -t`, reload, verify both sites with curl, and write the timeline.