Valid certificate, broken chain INC-2519

Open2 versionsNetworking · Hard · Fix · about 35 min ·Linux

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Ana Costa opened INC-2519 at 07:12SEV-2

depot-3's gateway certificate was renewed yesterday. This morning every cold-storage scanner rejects it, yet the gateway opens fine in a browser on Ana's laptop.

Pallets in the cold store must be scanned within the hour or checked again by hand. The scanners talk to depot-3's gateway over TLS and trust exactly one certificate: the Northstar root.

"Opens fine in my browser, padlock and everything. So it's the scanners?" (Ana, 07:05)

The renewed certificate is not expired, and its name matches the gateway.

Your task

Make Gatehouse send a chain that a client trusting only the Northstar root can verify. Fix it on the server, not on the scanners.

On the machine

  • bin/scanner-test runs what a scanner runs
  • openssl s_client -connect 127.0.0.3:8443 -servername depot3.northstar.example -showcerts
  • etc/nginx/nginx.conf, etc/ssl/, and the files from the PKI portal in home/sasha/renewal/
  • trust/northstar-root.crt, the only certificate the scanners trust

Timeline

2026-10-03Sasha renews the depot-3 gateway certificate (CHG-4460) and installs it.
06:30Cold-storage scanners: "unable to get local issuer certificate". Pallets queue offline.
07:05"Opens fine in my browser, padlock and everything." (Ana)
07:12INC-2519 lands with you.

Done when

  1. A scanner that trusts only the Northstar root verifies depot3.northstar.example.
  2. Gatehouse sends the depot-3 certificate followed by the 2026 issuing CA, and nothing else.
  3. The scanners' trust store is unchanged; it holds only the Northstar root.
  4. The fix survives a restart and a reboot of depot-3.

Hints

Hint 1

Run `bin/scanner-test`, then look at how many certificates `openssl s_client -showcerts` prints.

Hint 2

Compare the Issuer of the depot-3 certificate with the Subject of each CA certificate you have.

Hint 3

nginx's ssl_certificate file may hold several certificates. Order matters: the server's own first.

Hint 4

The issuing CA in etc/ssl/northstar/ is last year's. Check its Subject.

Show the solution

Concatenate the depot-3 certificate and `home/sasha/renewal/northstar-issuing-ca-2026.crt`, in that order, into one file (for example `etc/ssl/depot3/fullchain.pem`), point `ssl_certificate` at it, check the configuration, and reload Gatehouse with `bin/hostctl reload gatehouse`.