kerryb

kerryb

Unable to install mix in OTP 27.0.1 on Centos/RHEL/OEL7 (ssl issue?)

I recently tried upgrading from OTP 27.0 to 27.0.1 (with Elixir 1.17.2). Unfortunately our production environment is still OEL7, which I realise is now EOL (although we still have enterprise support until the end of the year, by which time we should have migrated).

When I try to build a release of my application using docker from either a CentOS7 or OEL7 image, the mix installation fails with what looks like an ssl issue:

 > [25/37] RUN mix local.hex --force:
#0 18.28 ** (Mix) httpc request failed with: {:failed_connect, [{:to_address, {~c"builds.hex.pm", 443}}, {:tls, [server_name_indication: ~c"builds.hex.pm", cacerts: [{:cert, <<48, 130, 5, 86, 48, 130, 3, 62, 160, 3, 2, 1, 2, 2, 20, 67, 227, 113, 19, 216, 179, 89, 20, 93, 183, 206, 140, 253, 53, 253, 111, 188, 5, 141, 69, 48, 13, 6, 9, ...>>, {:OTPCertificate, {:OTPTBSCertificate, :v3, 387574501246983434957692974888460947164905180485, {:SignatureAlgorithm, {1, 2, 840, 113549, 1, 1, 11}, :NULL}, {:rdnSequence, [[{:AttributeTypeAndValue, {2, 5, 4, 6}, ~c"CN"}], [{:AttributeTypeAndValue, {2, 5, 4, 10}, {:printableString, ~c"iTrusChina Co.,Ltd."}}], [{:AttributeTypeAndValue, {2, 5, 4, 3}, {:printableString, ~c"vTrus Root CA"}}]]}, {:Validity, {:utcTime, ~c"180731072405Z"}, {:utcTime, ~c"430731072405Z"}}, {:rdnSequence, [[{:AttributeTypeAndValue, {2, 5, 4, 6}, ~c"CN"}], [{:AttributeTypeAndValue, {2, 5, 4, 10}, {:printableString, ~c"iTrusChina Co.,Ltd."}}], [{:AttributeTypeAndValue, {2, 5, 4, 3}, {:printableString, ~c"vTrus Root CA"}}]]}, {:OTPSubjectPublicKeyInfo, {:PublicKeyAlgorithm, {1, 2, 840, 113549, 1, 1, 1}, :NULL},  --- [Lots of key info removed for space] --- , :asn1_NOVALUE, :asn1_NOVALUE, [{:Extension, ...}, {...}, ...]}, {:SignatureAlgorithm, {1, 2, 840, 113549, 1, 1, 5}, :NULL}, <<190, 228, 92, 98, 78, 36, 244, 12, 8, 255, 240, ...>>}}, {:cert, <<48, 130, 3, 123, 48, 130, 2, 99, 160, 3, 2, 1, 2, 2, 1, ...>>, {:OTPCertificate, {:OTPTBSCertificate, :v3, 1, {:SignatureAlgorithm, {1, 2, 840, 113549, 1, 1, ...}, :NULL}, {:rdnSequence, [[{:AttributeTypeAndValue, {2, ...}, ~c"TW"}], [{:AttributeTypeAndValue, {...}, ...}], [{:AttributeTypeAndValue, ...}], [{...}]]}, {:Validity, {:utcTime, ~c"080828072433Z"}, {:utcTime, ~c"301231155959Z"}}, {:rdnSequence, [[{:AttributeTypeAndValue, ...}], [{...}], [...], ...]}, {:OTPSubjectPublicKeyInfo, {:PublicKeyAlgorithm, {...}, ...}, {:RSAPublicKey, ...}}, :asn1_NOVALUE, :asn1_NOVALUE, [{...}, ...]}, {:SignatureAlgorithm, {1, 2, 840, 113549, 1, 1, 5}, :NULL}, <<60, 213, 119, 61, 218, 223, 137, 186, 135, 12, ...>>}}, {:cert, <<48, 130, 5, 65, 48, 130, 3, 41, 160, 3, 2, 1, 2, 2, ...>>, {:OTPCertificate, {:OTPTBSCertificate, :v3, 3262, {:SignatureAlgorithm, {1, 2, 840, 113549, 1, ...}, :NULL}, {:rdnSequence, [[{:AttributeTypeAndValue, {...}, ...}], [{:AttributeTypeAndValue, ...}], [{...}], [...]]}, {:Validity, {:utcTime, ~c"120627062833Z"}, {:utcTime, ~c"301231155959Z"}}, {:rdnSequence, [[{...}], [...], ...]}, {:OTPSubjectPublicKeyInfo, {:PublicKeyAlgorithm, ...}, {...}}, :asn1_NOVALUE, :asn1_NOVALUE, [...]}, {:SignatureAlgorithm, {1, 2, 840, 113549, 1, 1, 11}, :NULL}, <<95, 52, 129, 118, 239, 150, 29, 213, 229, ...>>}}, {:cert, <<48, 130, 4, 99, 48, 130, 3, 75, 160, 3, 2, 1, 2, ...>>, {:OTPCertificate, {:OTPTBSCertificate, :v3, 1, {:SignatureAlgorithm, {1, 2, 840, 113549, ...}, :NULL}, {:rdnSequence, [[{:AttributeTypeAndValue, ...}], [{...}], [...], ...]}, {:Validity, {:utcTime, ~c"131125082555Z"}, {:utcTime, ...}}, {:rdnSequence, [[...], ...]}, {:OTPSubjectPublicKeyInfo, {...}, ...}, :asn1_NOVALUE, :asn1_NOVALUE, ...}, {:SignatureAlgorithm, {1, 2, 840, 113549, 1, 1, 11}, :NULL}, <<42, 63, 225, 241, 50, 142, 174, 225, ...>>}}, {:cert, <<48, 130, 3, 195, 48, 130, 2, 171, 160, 3, 2, 1, ...>>, {:OTPCertificate, {:OTPTBSCertificate, :v3, 1, {:SignatureAlgorithm, {1, 2, 840, ...}, :NULL}, {:rdnSequence, [[{...}], [...], ...]}, {:Validity, {:utcTime, ...}, {...}}, {:rdnSequence, [...]}, {:OTPSubjectPublicKeyInfo, ...}, :asn1_NOVALUE, ...}, {:SignatureAlgorithm, {1, 2, 840, 113549, 1, 1, ...}, :NULL}, <<86, 61, 239, 148, 213, 189, 218, ...>>}}, {:cert, <<48, 130, 3, 195, 48, 130, 2, 171, 160, 3, 2, ...>>, {:OTPCertificate, {:OTPTBSCertificate, :v3, 1, {:SignatureAlgorithm, {1, 2, ...}, :NULL}, {:rdnSequence, [[...], ...]}, {:Validity, {...}, ...}, {:rdnSequence, ...}, {...}, ...}, {:SignatureAlgorithm, {1, 2, 840, 113549, 1, ...}, :NULL}, <<49, 3, 162, 97, 11, 31, ...>>}}, {:cert, <<48, 130, 5, 189, 48, 130, 3, 165, 160, 3, ...>>, {:OTPCertificate, {:OTPTBSCertificate, :v3, 5700383053117599563, {:SignatureAlgorithm, {1, ...}, :NULL}, {:rdnSequence, [...]}, {:Validity, ...}, {...}, ...}, {:SignatureAlgorithm, {1, 2, 840, 113549, ...}, :NULL}, <<115, 198, 129, 224, 39, ...>>}}, {:cert, <<48, 130, 5, 186, 48, 130, 3, 162, 160, ...>>, {:OTPCertificate, {:OTPTBSCertificate, :v3, 13492815561806991280, {:SignatureAlgorithm, {...}, ...}, {:rdnSequence, ...}, {...}, ...}, {:SignatureAlgorithm, {1, 2, 840, ...}, :NULL}, <<39, 186, 227, 148, ...>>}}, {:cert, <<48, 130, 3, 239, 48, 130, 2, 215, ...>>, {:OTPCertificate, {:OTPTBSCertificate, :v3, 0, {:SignatureAlgorithm, ...}, {...}, ...}, {:SignatureAlgorithm, {1, 2, ...}, :NULL}, <<75, 54, 166, ...>>}}, {:cert, <<48, 130, 3, 221, 48, 130, 2, ...>>, {:OTPCertificate, {:OTPTBSCertificate, :v3, 0, {...}, ...}, {:SignatureAlgorithm, {1, ...}, :NULL}, <<17, 89, ...>>}}, {:cert, <<48, 130, 4, 15, 48, 130, ...>>, {:OTPCertificate, {:OTPTBSCertificate, :v3, 0, ...}, {:SignatureAlgorithm, {...}, ...}, <<5, ...>>}}, {:cert, <<48, 130, 3, 90, 48, ...>>, {:OTPCertificate, {:OTPTBSCertificate, :v3, ...}, {:SignatureAlgorithm, ...}, <<...>>}}, {:cert, <<48, 130, 5, 127, ...>>, {:OTPCertificate, {:OTPTBSCertificate, ...}, {...}, ...}}, {:cert, <<48, 130, 3, ...>>, {:OTPCertificate, {...}, ...}}, {:cert, <<48, 130, ...>>, {:OTPCertificate, ...}}, {:cert, <<48, ...>>, {...}}, {:cert, <<...>>, ...}, {:cert, ...}, {...}, ...], verify: :verify_peer, customize_hostname_check: [match_fun: #Function<6.75820660/2 in :public_key.pkix_verify_hostname_match_fun/1>]], {:tls_alert, {:unexpected_message, ~c"TLS client: In state hello_retry_middlebox_assert at ssl_gen_statem.erl:768 generated CLIENT ALERT: Fatal - Unexpected Message\n {unexpected_msg,\n     {internal,\n         {server_hello,\n             {3,3},\n             <<128,78,7,175,140,144,165,212,179,7,105,137,...>>,\n             <<11,131,58,129,245,122,149,191,175,234,207,...>>,\n             <<19,1>>,\n             \#{server_hello_selected_version =>\n                   {server_hello_selected_version,{3,4}},\n               pre_shared_key => undefined,\n               key_share =>\n                   {key_share_server_hello,\n                       {key_share_entry,secp384r1,<<4,208,217,...>>}}}}}}"}}}]}
#0 18.28
#0 18.28 Could not install Hex because Mix could not download metadata at https://builds.hex.pm/installs/hex-1.x.csv.
#0 18.28
#0 18.28 Alternatively, you can compile and install Hex directly with this command:
#0 18.28
#0 18.28     $ mix archive.install github hexpm/hex branch latest

The error buried at the end of that very long line relates to :public_key.pkix_verify_hostname_match_fun/1, and includes:

TLS client: In state hello_retry_middlebox_assert at ssl_gen_statem.erl:768 generated CLIENT ALERT: Fatal - Unexpected Message
 {unexpected_msg,
     {internal,
         {server_hello,
             {3,3},
             <<128,78,7,175,140,144,165,212,179,7,105,137,...>>,
             <<11,131,58,129,245,122,149,191,175,234,207,...>>,
             <<19,1>>,
             #{server_hello_selected_version =>
                   {server_hello_selected_version,{3,4}},
               pre_shared_key => undefined,
               key_share =>
                   {key_share_server_hello,
                       {key_share_entry,secp384r1,<<4,208,217,...>>}}}}}}

I’m not sure this is really an Erlang issue (or a mix issue), because presumably this OS is no longer supported, but is anyone aware of a workaround? for now I’ve just reverted to OTP 17.0, which works fine.

First Post!

dimitarvp

dimitarvp

My first guess would be to manually install the latest root certificates (if the now obsolete OS does not have them up-to-date in its package manager database). On Debian-like systems the package is called ca-certificates.

Where Next?

Popular in Questions Top

dotdotdotPaul
Okay, I'm having a heck of a time trying to figure out how to best handle the validation of belongs_to associations in Ecto. I'm sure I'...
New
yawaramin
In the Dialyzer docs ( http://erlang.org/doc/man/dialyzer.html#requesting-or-suppressing-warnings-in-source-files ), there is a way to tu...
New
fireproofsocks
I’m working on defining a simple Ecto schema for a table (in PostGres), but I don’t see where I can define a column as NOT NULL. Conside...
New
dokuzbir
Hello, I am trying to convert my lists to string without losing brackets.For start i have 3 map. They look like these buyer = %{ id: ...
New
makeitrein
Hey all, just started picking up Elixir last week and am writing a scraper as a learning project. Baby step #1 is extracting the number ...
New
shahryarjb
Hello, I have map which I want to convert it to string like this: the map: %{last_name: "tavakkoli", name: "shahryar"} the string I ne...
New
vonH
When I run the Plug and I recompile I wind up having to use Ctrl C to quit iex and start again. Witht the help of rlwrap I can use the cu...
New
Patoshizzle
After calling mix ecto.create I get this error: 17:00:32.162 [error] GenServer #PID&lt;0.412.0&gt; terminating ** (Postgrex.Error) FATAL...
New
Codball
Mix format works fine if run from the cmd. I’ve followed this to facilitate the implementation into VSC which involves downloading an ext...
New
wernerlaude
In AR this is so simple @articles = current_user.articles How to do in Ecto? def index(conn, _params) do current_user = conn.assig...
New

Other popular topics Top

_russellb
I want to try my hand at web scraping. What tools/libraries do I need to use. I’m hoping to turn this into something professional so don’...
New
KronicDeth
Elixir plugin for JetBrain’s IntelliJ Platform (including Rubymine) This is a plugin that adds support for Elixir to JetBrains IntelliJ...
289 35421 110
New
Harrisonl
We have an ECS cluster with 4 services, where each task joins a single cluster, via discovery ECS discovery service. Currently when I de...
New
SoCreat
i’m a new one to elixir which editor can i use vs code? or atom? Thanks! :smiley:
New
chrismccord
This release brings a number of exciting features, including integration with the new Phoenix LiveDashboard and Phoenix LiveView. There h...
New
freewebwithme
Using vs code and installed ElixirLS: support and debugger. And I got an error popped up on start up says Failed to run ‘elixir’ comma...
New
fayddelight
I tried installing elixir 1.11.2 erlang 23.3.4 via asdf in my zsh shell. Enabled the versions locally and globally. When I list them ...
New
shahryarjb
Hello, I have map which I want to convert it to string like this: the map: %{last_name: "tavakkoli", name: "shahryar"} the string I ne...
New
Fl4m3Ph03n1x
About me? ( if you have nothing better to do than reading about some random guy in the internet :stuck_out_tongue: ) Hello all, this is ...
New
siddhant3030
Hi, I have to write a raw query for one of my project. But till now I have used ecto queries and don’t have much experience writing raw ...
New

We're in Beta

About us Mission Statement