<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Https fota fails on a specific site</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/70899/https-fota-fails-on-a-specific-site</link><description>Hi , 
 I&amp;#39;m trying to use http_application_update , on an https website, and i get: 
 I: Attempting to connect over IPv4 I: Setting up TLS credentials E: Unable to connect, errno 45 fota_download_start() failed, err -22 
 the download does work from a</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Thu, 11 Feb 2021 09:32:30 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/70899/https-fota-fails-on-a-specific-site" /><item><title>RE: Https fota fails on a specific site</title><link>https://devzone.nordicsemi.com/thread/293917?ContentTypeID=1</link><pubDate>Thu, 11 Feb 2021 09:32:30 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:a4e8badc-855e-45bd-b58c-d5046d19b513</guid><dc:creator>Didrik Rokhaug</dc:creator><description>&lt;p&gt;Hi, and sorry for the very late reply.&lt;/p&gt;
&lt;p&gt;I ran your server through &lt;a href="https://www.ssllabs.com/ssltest/analyze.html?d=esr.etrogsystems.com&amp;amp;hideResults=on"&gt;SSLabs.com&lt;/a&gt;, and it doesn&amp;#39;t look like your server supports any of the cipher suites supported by the nRF9160.&lt;/p&gt;
&lt;p&gt;Your server therefore rejects the TLS connection.&lt;/p&gt;
&lt;p&gt;You can find the list of supported cipher suites on &lt;a href="https://www.nordicsemi.com/Products/Low-power-cellular-IoT/nRF9160/Download#infotabs"&gt;our website&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Best regards,&lt;/p&gt;
&lt;p&gt;Didrik&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Https fota fails on a specific site</title><link>https://devzone.nordicsemi.com/thread/292382?ContentTypeID=1</link><pubDate>Tue, 02 Feb 2021 08:13:02 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:4fca9124-5972-4804-8587-89fbdbe4e3d9</guid><dc:creator>MosheSmartAmr</dc:creator><description>&lt;p&gt;Hi,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I pulled the certificate from firefox, and still I was unable to connect&lt;/p&gt;
&lt;p&gt;this is the certificate I got:&lt;/p&gt;
&lt;p&gt;&lt;pre class="ui-code" data-mode="text"&gt;-----BEGIN CERTIFICATE-----
MIIFLjCCBBagAwIBAgISBHJI4XB6nfQ3SfOb3f9Is+nZMA0GCSqGSIb3DQEBCwUA
MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD
EwJSMzAeFw0yMTAxMjUxNDQ2MDVaFw0yMTA0MjUxNDQ2MDVaMB8xHTAbBgNVBAMT
FGVzci5ldHJvZ3N5c3RlbXMuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB
CgKCAQEAn2Dg33FDWuaO5v9pKH3iGDeA4NTiW3nYYsLmfRR3teG13rJhXAF45G+Z
/maGjMsk6GHAveQbD8I0Zwo7ffAdcwfhBj2UmbaVoRhh8gkx0wfuwUVAYV4rruZX
g/cO8ecYj/yDG5fYoGzQt486ZN3ZrDRTQ0xWu82LW8TMs6PXXb+UgBzbqn5cjIUQ
f5rzj1X+n1+4Va0EcqDfhgz6Fy71Rit9Bo5d4TJNa4O15u8swChiggmQAG366jIH
H1YtAsO8GcmdQ4ND9VpkQYcQL4XEm0ubnAt14HX/FJL0rB6BgNtsZ/C9FBSdVyNn
a4euK2F1yQWyichsVclsPnA7pI2NqQIDAQABo4ICTzCCAkswDgYDVR0PAQH/BAQD
AgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAA
MB0GA1UdDgQWBBTa+bwY8OlyMhKBD6JesY1lgqV/5DAfBgNVHSMEGDAWgBQULrMX
t1hWy65QCUDmH6+dixTCxjBVBggrBgEFBQcBAQRJMEcwIQYIKwYBBQUHMAGGFWh0
dHA6Ly9yMy5vLmxlbmNyLm9yZzAiBggrBgEFBQcwAoYWaHR0cDovL3IzLmkubGVu
Y3Iub3JnLzAfBgNVHREEGDAWghRlc3IuZXRyb2dzeXN0ZW1zLmNvbTBMBgNVHSAE
RTBDMAgGBmeBDAECATA3BgsrBgEEAYLfEwEBATAoMCYGCCsGAQUFBwIBFhpodHRw
Oi8vY3BzLmxldHNlbmNyeXB0Lm9yZzCCAQQGCisGAQQB1nkCBAIEgfUEgfIA8AB1
AFzcQ5L+5qtFRLFemtRW5hA3+9X6R9yhc5SyXub2xw7KAAABdzo5PqUAAAQDAEYw
RAIgFSmo47JXJhIBgKLOrMLVJpO7sRI8pN91gr5rwDIergUCIBXhjYQRgZp67EPB
lSL3FpN7QTMRMxQTa//7lHbeCeesAHcA9lyUL9F3MCIUVBgIMJRWjuNNExkzv98M
LyALzE7xZOMAAAF3Ojk+jgAABAMASDBGAiEA6Wwvo33OlSG7qxffpGYfvVZgTqkc
ueoAbWC/w3t8PrUCIQD8myaPfD7UD0aanmWFB1ZOY4kZRZs+pHP7Vtp8TELSYTAN
BgkqhkiG9w0BAQsFAAOCAQEAmD4L8tAAB8tH/2ANNSBkSjMrRBv5a75m/43r3ZOK
pZ+0kf0g01WeGeJ9i1FI10lkPW+lJ1xPwuAB61TylFyEUuc5Dbf1YfWUEg1xerOS
ICnU6voH/M4dT/okI64jNImLrOH+h4xM9gixPPcT/D04g1JkMI0JrVPlD8L5yH/+
DZk31Wz2mMiuLkWxOZ3gN3IeRdNfyG/W+YHgQVPtjlnxfHWbyesiU8Mse8gc5PoV
C5yq36Jab0FjY+AoPvCI/TCzXU8pgAalg3Cnb+o8CDe3rEaHAh1HZ11PqMev8R+i
TiuwjMVdw0cTlF2B2oEVe/SRg8hLpX1unI4W2jDu1fH+rw==
-----END CERTIFICATE-----&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;any idea how to debug this ?&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Https fota fails on a specific site</title><link>https://devzone.nordicsemi.com/thread/292241?ContentTypeID=1</link><pubDate>Mon, 01 Feb 2021 13:16:50 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:aebeb405-98b8-4e44-a13a-5b5f022dd5d2</guid><dc:creator>Didrik Rokhaug</dc:creator><description>&lt;p&gt;Hi, and sorry for the late reply.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
[quote user="MosheSmartAmr"]How do I know what is the right certificate.[/quote]
&lt;p&gt;&amp;nbsp;There are many ways, including using your browser (e.g. click on the padlock in the URL field in Firefox), or you can use openssl as explained here: &lt;a href="https://stackoverflow.com/questions/7885785/using-openssl-to-get-the-certificate-from-a-server"&gt;https://stackoverflow.com/questions/7885785/using-openssl-to-get-the-certificate-from-a-server&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
[quote user="MosheSmartAmr"]as I understand the certificate in the code is a global certificate.[/quote]
&lt;p&gt;Typically, a server will have a chain of certificates, and if one of the certificates in the chain matches a &amp;quot;known and trusted&amp;quot; certificate, the connection is established.&lt;/p&gt;
&lt;p&gt;Web browsers typically has a set of certificates from &lt;em&gt;certificate authorities&lt;/em&gt; which are trusted. A server would then ask one of the certificate authorities to sign its certificate, so web browsers can connect to the server.&lt;/p&gt;
&lt;p&gt;However, in the case of the nRF91, we currently only support one CA certificate at a time. This means that if the server&amp;#39;s certificate isn&amp;#39;t signed by the trusted CA certificate, the connection will be rejected. In your case, it seems your server&amp;#39;s certificate has been signed by a different certificate authority than CyberTrust.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Https fota fails on a specific site</title><link>https://devzone.nordicsemi.com/thread/291336?ContentTypeID=1</link><pubDate>Tue, 26 Jan 2021 15:30:33 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:cc2d9f97-3893-42a6-973e-5fbc10e811d1</guid><dc:creator>MosheSmartAmr</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;How do I know what is the right certificate.&lt;/p&gt;
&lt;p&gt;as I understand the certificate in the code is a global certificate.&lt;/p&gt;
&lt;p&gt;the Domain is,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://esr.etrogsystems.com/"&gt;https://esr.etrogsystems.com/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Https fota fails on a specific site</title><link>https://devzone.nordicsemi.com/thread/291323?ContentTypeID=1</link><pubDate>Tue, 26 Jan 2021 14:47:54 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:f7769923-64e1-4a58-9dd5-195d8f710911</guid><dc:creator>Didrik Rokhaug</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;Does the HTTPS website use the same certificates as the S3 bucket, or have you provisioned the right certificates to the device?&lt;/p&gt;
&lt;p&gt;Best regards,&lt;/p&gt;
&lt;p&gt;Didrik&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>