<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Webhook - HTTPS error &amp;quot;Certificate Unknown&amp;quot; in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/webhook-https-error-quot-certificate-unknown-quot/m-p/5446929#M13213</link>
    <description>&lt;P&gt;Have you checked which certificate you are presenting?  It's definitely the public certificate you have bought?&lt;/P&gt;&lt;P&gt;Can you point your web browser at your server and get it to connect with no TLS errors?&lt;/P&gt;&lt;P&gt;Is your server presenting a correct chain of certificates?&lt;/P&gt;</description>
    <pubDate>Tue, 08 Sep 2020 20:50:28 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2020-09-08T20:50:28Z</dc:date>
    <item>
      <title>Webhook - HTTPS error "Certificate Unknown"</title>
      <link>https://community.cisco.com/t5/endpoint-security/webhook-https-error-quot-certificate-unknown-quot/m-p/5446928#M13212</link>
      <description>&lt;P&gt;We are integrating meraki with another application which acts as web server. SSL certificate configured in application webserver. Certificated has been signed and issued by authorized CA &lt;/P&gt;&lt;P&gt;1. Webhook configured towards application webserver in Meraki &lt;/P&gt;&lt;P&gt;2. When we click "send test webhooks" from Meraki GUI it shows "failed" whereas in application server side below error reported,&lt;/P&gt;&lt;P&gt;Traceback (most recent call last):&lt;BR /&gt;File "/usr/lib64/python2.7/SocketServer.py", line 295, in _handle_request_noblock&lt;BR /&gt;self.process_request(request, client_address)&lt;BR /&gt;File "/usr/lib64/python2.7/SocketServer.py", line 321, in process_request&lt;BR /&gt;self.finish_request(request, client_address)&lt;BR /&gt;File "/usr/lib64/python2.7/SocketServer.py", line 334, in finish_request&lt;BR /&gt;self.RequestHandlerClass(request, client_address, self)&lt;BR /&gt;File "/usr/lib64/python2.7/SocketServer.py", line 649, in __init__&lt;BR /&gt;self.handle()&lt;BR /&gt;File "/usr/lib64/python2.7/BaseHTTPServer.py", line 340, in handle&lt;BR /&gt;self.handle_one_request()&lt;BR /&gt;File "/usr/lib64/python2.7/BaseHTTPServer.py", line 310, in handle_one_request&lt;BR /&gt;self.raw_requestline = self.rfile.readline(65537)&lt;BR /&gt;File "/usr/lib64/python2.7/socket.py", line 476, in readline&lt;BR /&gt;data = self._sock.recv(self._rbufsize)&lt;BR /&gt;Error: [('SSL routines', 'ssl3_read_bytes', 'sslv3 alert certificate unknown'), ('SSL routines', 'ssl23_read', 'ssl handshake failure')]&lt;/P&gt;&lt;P&gt;3. TCPDUMP shows Meraki responds backs "Certificate Unknown (46)" for "Server Hello, Certificate, Server Hello Done".&lt;/P&gt;&lt;P&gt;Questions,&lt;/P&gt;&lt;P&gt;1. How Meraki differentiates Known and unknown certificates?&lt;/P&gt;&lt;P&gt;2. Do we need add webserver certificates in Meraki?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 19:02:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/webhook-https-error-quot-certificate-unknown-quot/m-p/5446928#M13212</guid>
      <dc:creator>nabalaji</dc:creator>
      <dc:date>2020-09-08T19:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Webhook - HTTPS error "Certificate Unknown"</title>
      <link>https://community.cisco.com/t5/endpoint-security/webhook-https-error-quot-certificate-unknown-quot/m-p/5446929#M13213</link>
      <description>&lt;P&gt;Have you checked which certificate you are presenting?  It's definitely the public certificate you have bought?&lt;/P&gt;&lt;P&gt;Can you point your web browser at your server and get it to connect with no TLS errors?&lt;/P&gt;&lt;P&gt;Is your server presenting a correct chain of certificates?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 20:50:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/webhook-https-error-quot-certificate-unknown-quot/m-p/5446929#M13213</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2020-09-08T20:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: Webhook - HTTPS error "Certificate Unknown"</title>
      <link>https://community.cisco.com/t5/endpoint-security/webhook-https-error-quot-certificate-unknown-quot/m-p/5446930#M13214</link>
      <description>&lt;P&gt;&lt;SPAN&gt; &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/340"&gt;@Philip D'Ath&lt;/A&gt; &lt;/SPAN&gt;Thanks for response.&lt;/P&gt;&lt;P&gt;Sorry for the late update on this thread.&lt;BR /&gt;&lt;BR /&gt;The issue turned out to be one of the intermediate certificates was not issued by Global CA. So we created the entire chain of certificates again with proper Global CA and it resolved the issue.&lt;/P&gt;&lt;P&gt;Suggestions:&lt;/P&gt;&lt;P&gt;1. Ensure certificates are issued by Global CA.&lt;/P&gt;&lt;P&gt;2. If there are multiple chain of certificates then present all chain of certificates until root (server certificates + Intermediate certificates + root certificates) while connecting to Meraki.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 14:34:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/webhook-https-error-quot-certificate-unknown-quot/m-p/5446930#M13214</guid>
      <dc:creator>nabalaji</dc:creator>
      <dc:date>2020-09-23T14:34:19Z</dc:date>
    </item>
  </channel>
</rss>

