Closed Bug 1636684 Opened 5 years ago Closed 5 years ago

Trees Closed Raptor Certificate issue| mitmproxy.log shows 127.0.0.1:49883: Failed to send error response to client: ClientHandshakeException('Cannot establish TLS with client (sni: m.media-amazon.com)

Categories

(Testing :: Condprofile, defect, P1)

defect

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: intermittent-bug-filer, Assigned: tarek)

Details

Attachments

(1 file)

Filed by: btara [at] mozilla.com
Parsed log: https://treeherder.mozilla.org/logviewer.html#?job_id=301543990&repo=autoland
Full log: https://firefox-ci-tc.services.mozilla.com/api/queue/v1/task/TZcoO9lsRgOKq9PL-RfpGQ/runs/0/artifacts/public/logs/live_backing.log


mitmproxy log: https://firefox-ci-tc.services.mozilla.com/tasks/TZcoO9lsRgOKq9PL-RfpGQ/runs/0/logs/https%3A%2F%2Ffirefox-ci-tc.services.mozilla.com%2Fapi%2Fqueue%2Fv1%2Ftask%2FTZcoO9lsRgOKq9PL-RfpGQ%2Fruns%2F0%2Fartifacts%2Fpublic%2Ftest_info%2Fmitmproxy.log#L1447

127.0.0.1:49876: POST https://aan.amazon.com/cem
    Host: aan.amazon.com
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Firefox/78.0
    Accept: */*
    Accept-Language: en-US,en;q=0.5
    Accept-Encoding: gzip, deflate, br
    Content-Type: text/plain;charset=UTF-8
    Content-Length: 164
    Origin: https://www.amazon.com
    Connection: keep-alive
    Referer: https://www.amazon.com/s?k=laptop&ref=nb_sb_noss_1
    Sec-Fetch-Dest: empty
    Sec-Fetch-Mode: cors
    Sec-Fetch-Site: same-site
[replay]  << 200 OK 20b
    Server: Server
    Date: Sat, 09 May 2020 12:10:26 -0000
    Content-Type: application/json
    Content-Length: 20
    Connection: keep-alive
    x-amzn-RequestId: d96f4e83-929a-11e9-8488-111d586bb5c9
    Access-Control-Allow-Origin: *
    Content-Encoding: gzip
    Cache-Control: no-store
    Cache-Control: must-revalidate
    Expires: 0
    Access-Control-Expose-Headers: x-amzn-RequestId,x-amzn-ErrorType,x-amzn-ErrorMessage,Date
    Pragma: no-cache
    x-amz-rid: CNWFS7ECMMDGXAMCMM46
    Vary: Accept-Encoding,X-Amzn-CDN-Cache,X-Amzn-AX-Treatment,User-Agent
127.0.0.1:49884: ALPN for client: b'h2'
127.0.0.1:49885: ALPN for client: b'h2'
127.0.0.1:49881: clientdisconnect
127.0.0.1:49883: Failed to send error response to client: ClientHandshakeException('Cannot establish TLS with client (sni: m.media-amazon.com): TlsException("SSL handshake error: Error([(\'SSL routines\', \'ssl3_read_bytes\', \'sslv3 alert bad certificate\')],)",)',)
127.0.0.1:49883: CONNECT m.media-amazon.com:443
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Firefox/78.0
    Proxy-Connection: keep-alive
    Connection: keep-alive
    Host: m.media-amazon.com:443
 << Cannot establish TLS with client (sni: m.media-amazon.com): TlsException("SSL handshake error: Error([('SSL routines', 'ssl3_read_bytes', 'sslv3 alert bad certificate')],)",)
127.0.0.1:49887: Set new server address: m.media-amazon.com:443
Priority: P5 → P1
Flags: needinfo?(rthijssen)
Severity: normal → S1
Summary: Trees Closed Certificate issue| mitmproxy.log shows 127.0.0.1:49883: Failed to send error response to client: ClientHandshakeException('Cannot establish TLS with client (sni: m.media-amazon.com) → Trees Closed Raptor Certificate issue| mitmproxy.log shows 127.0.0.1:49883: Failed to send error response to client: ClientHandshakeException('Cannot establish TLS with client (sni: m.media-amazon.com)

deactivate complex condprofs

Severity: S1 → --
Flags: needinfo?(rthijssen)

Forcing a rerun of FBy33qUJRwq-51C8imhAbg seems to have solved the issue.

Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → FIXED

(In reply to Tarek Ziadé (:tarek) from comment #2)

Bug 1636684 - deactivate complex condprofs

deactivate complex condprofs

Are we going to re-enable complex profiles? If yes, where can I find the follow-up bug? Or should we keep this bug open?

Flags: needinfo?(tarek)
Flags: needinfo?(gmierz2)
Assignee: server-ops-webops → tarek
Component: SSL Certificates → Condprofile
Product: Infrastructure & Operations → Testing
QA Contact: cshields

Tarek, would you have a bug open about re-enabling the full and settled2 conditioned profiles?

Flags: needinfo?(gmierz2)
Flags: needinfo?(tarek)
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: