DennisKh
TLS client: In state cipher received SERVER ALERT: Fatal - Unknown CA for Apple Pay Payment Session
Hi all,
I’m stuck with a problem and would really appreciate any feedback or ideas you might have.
I followed the official documentation Apple Pay on the Web and finally got the Payment Processing Certificate (.cer) and the .p12 certificate. Then I extracted the certificate and the key from .p12 cert into 2 separate files.
The problem
I’m trying to start Payment Session via Httposon.post request like
opts = [
{:certfile, "priv/cert/apple_pay.cert.pem"},
{:keyfile, "priv/cert/apple_pay.key.pem"},
{:versions, [:"tlsv1.2"]},
]
with %{body: response} <- HTTPoison.post("#{validation_url}/paymentSession", body,
[{"Content-Type", "application/json"}],
ssl: opts),
{:ok, result} <- Jason.decode(response) do
IO.inspect(result)
else
_ -> false
end
Error
[info] TLS client: In state cipher received SERVER ALERT: Fatal - Unknown CA
{:error, %HTTPoison.Error{id: nil, reason: {:tls_alert, 'unknown ca'}}}
Marked As Solved
DennisKh
I finally figured out what the problem was.
I made a mistake in the beginning when creating certificates. The problem was that I did not have all the necessary additional certificates installed, namely:
Then I created new certificates and everything worked!
But now I have a new challenge. I need to decrypt the encrypted payment data as described here.
I found a sample code on JS, but I didn’t figure out how to rewrite it on Elixir.
I would be very grateful if you would show me a sample code on Elixir.
Also Liked
voltone
The server is saying it can’t accept your client certificate because it cannot build a trust chain to a trusted root CA. I’m guessing the p12 file contains not just an end certificate, but also one or more intermediate CAs. The server is expecting you to send the full chain, but in your current configuration only the end certificate is sent.
The challenge here is that Erlang’s :ssl application uses the cacerts / cacertfile option both as the local trust store (the root CA certificates it checks the server certificate against) and as a pool of intermediate CAs that may be sent with the client certificate. What’s more, HTTPoison (or rather Hackney) will set cacerts to its CA trust store, but only if you didn’t specify any ssl options of your own. Since you want to set a client certificate, you need to pass in a bunch of extra options to enable server certificate verification, or you’ll be susceptible to MitM attacks. See [here]https://erlef.github.io/security-wg/secure_coding_and_deployment_hardening/ssl and here for details.
The simplest way to get this working is to find out what is the root CA you need to talk to Apple, and put it in a file together with any intermediate CAs from the p12 file. Then add verify: :verify_peer, cacertfile: <path-to-your-new-file>, ... to the ssl options.
If you don’t want to pin the connection to one root CA, you could load the intermediate certificates into memory in DER format, and then pass verify: :verify_peer, cacertfile: [int_ca1_der, int_ca2_der | :certifi.cacert().








