GoulvenClech
HTTPoison.Error sending a mail with Brevo : {:options, :incompatible, [verify: :verify_peer, cacerts: :undefined]}
Hi everyone,
Recently, our transactional emails won’t launch and return HTTPoison.Error like :
%HTTPoison.Error{reason: {:options, :incompatible, [verify: :verify_peer, cacerts: :undefined]}, id: nil}
I’m using the Brevo API V3. And my guess is that’s a problem with SSL; I currently use [ssl: [{:versions, [:"tlsv1.2"]}]].
Any idea or lead to help me on this case?
Thanks.
UPDATE :
Linked to OTP 26 upgrade. I obtain some progress by changing my request otps like :
def process_request_options(_options) do
[
ssl: [
verify: :verify_peer,
cacerts: :public_key.cacerts_get(),
versions: [:"tlsv1.2"]
]
]
Now the error is :
%HTTPoison.Error{reason: {:tls_alert, {:handshake_failure, ~c"TLS client: In state certify at ssl_handshake.erl:2140 generated CLIENT ALERT: Fatal - Handshake Failure\n {bad_cert,hostname_check_failed}"}}, id: nil}
Marked As Solved
ruslandoga
Note that for wildcard certs you need to add an additional option, :customize_hostname_check
[
ssl: [
verify: :verify_peer,
cacerts: :public_key.cacerts_get(),
versions: [:"tlsv1.2"],
customize_hostname_check: [
match_fun: :public_key.pkix_verify_hostname_match_fun(:https)
]
]
]
More info: Erlang standard library: ssl | EEF Security WG (note the depth option as well)
And for :public_key.cacerts_get() to work, you might need to first :public_key.cacerts_load() the certs (e.g. during application startup). Right now in your case it seems to be returning :undefined.
Also Liked
quatermain
We use Finch with Brevo, we recently upgraded to Elixir 1.15.4 and OTP 26.0.2 and it works:
Finch.build(
:delete,
"https://api.sendinblue.com/v3/contacts/#{email}",
[
{"api-key", api_key()},
{"content-type", "application/json"}
]
)
|> Finch.request(PlatformFinch)
finch 0.16.0
ssl_verify_fun 1.1.6
``








