Repository navigation
HTTP/HTTPS client requests throwing EPROTO #3692
Description
Activity
@brandonros I'm suspecting it has to do with the first-class IPv6 support Node v4 has. cc @mscdex maybe.
Edit: added IPv6
- addedhttpIssues and PRs related to the http subsystem.Issues and PRs related to the http subsystem.
on Nov 6, 2015 What OS and OS version is this on?
Linux Nigel 3.13.0-43-generic #72-Ubuntu SMP Mon Dec 8 19:35:44 UTC 2014 i686 i686 i686 GNU/LinuxNo LSB modules are available. Distributor ID: Ubuntu Description: Ubuntu 14.04.3 LTS Release: 14.04 Codename: trusty@Fishrock123 @mscdex Any other information I can provide? Would love to get this fixed quickly. I'm sure it has to be something on my end, otherwise a huge portion of people would be experiencing it.
The code used to work without issue, but it started happening a) when I changed machines and b) when I switched versions.
I installed with nvm if that matters.
Is it happening with the same server(s)? If so, are these public servers? Otherwise, if you can, it might be helpful to see what types of addresses the servers are resolving to (e.g. IPv4, IPv6) and what types of addresses are assigned to the outgoing network interface the requests are going out.
@mscdex It is happening on the same offending server. It seems to happen on both requests made to localhost, and external APIs. All IPv4.
Also encountered on OS X (My computer) and Ubuntu (Travis-CI) and Windows Server (AppVeyor) when using npm package 'request', the error trace is exactly same as described by @brandonros
Reacted by Bruno Brant, Nate Ben and JoeIt sounds like you are trying to use port 80 for https?
Reproduced via:
require('https').get('https://google.com:80', function(res) { console.log(res.statusCode) }).on('error', console.log)
Reacted by Jaime, Augustin Riedinger, iugo, Thiago Bustamante, Christian Bundy, Twixr, Suresh Alse, xerq, Alexander Bykhov, Aron Jones and 68 moreReacted by Jaime, Thiago Bustamante, Christian Bundy, Chief Sloperator, Alexis, Julian Soto, Emin Arakelian, Nikita Gubchenko, herosu77, Lavrentii Prokopovych and 15 moreReacted by Esen Sagynov, Thiago Bustamante, Twixr, Chief Sloperator, Loren, Valer Cara, Francois Wouts, Ryan McElroy, Salimcan Venedik, Joe and 1 moreReacted by Jaime, Alex Kabakaev, Thiago Bustamante, xerq, Chief Sloperator, fernandodesarriera, Nikita Gubchenko, Alberto Vazquez, Valer Cara, Sendy Halim and 11 moreReacted by Sohan, Udara Jayawardena, Salimcan Venedik, Joe, awned and CEbbinghausThe reason that isn't the problem in my case is because it only happens
semi-frequently on otherwise valid endpoints.On Sunday, November 8, 2015, Evan Lucas notifications@github.com wrote:
It sounds like you are trying to use port 80 for https?
Reproduced via:
require('https').get('https://google.com:80', function(res) { console.log(res.statusCode) }).on('error', console.log)
—
Reply to this email directly or view it on GitHub
#3692 (comment).Reacted by John Ottenlips Franke and NatalieGusevaIt will be difficult for us to help debug the issue without being able to see some of the code. Is there any that you could share?
I went to dumb down some code I have, and it really just boils down to any HTTP or HTTPS request. Nothing else.
@trotyl Do you think it has anything to do with DNS or nginx rewrites? I'm really stretching here. I can't come up with anything else.
It appears on some certain urls and randomly, I cannot even cause it to appear manually, and I have used a 'retry(100)' of RxJS to get rid of this problem. But it seems not a good solution.
Some url(s) on my crawler of my university site may cause the problem at some low possibility, I do have no idea where it came from as error trace directly begin from 'net.js', But what I can guess seems to be DNS or HTTPS or something relevant.
The url I have problem with seems to be 'https://uis.uestc.edu.cn/amserver/UI/Login' with method 'POST' with form 'IDToken0&IDToken=2012019050020&IDToken2=811073&IDButton=Submit&goto=aHR0cDovL3BvcnRhbC51ZXN0Yy5lZHUuY24vbG9naW4ucG9ydGFs&encoded=true&gx_charset=UTF-8', (the id and password is not mine but valid)
Upgrading to 5.0, changing machines, and switching to 64-bit seems to have fixed the problem. I don't want to jinx anything, but I have not seen the error in 3 days.
The error is still happening. I am installing longjohn on all of my servers to get more information.
@trotyl Any update?
135 remaining items
I got the error :
{ [Error: write EPROTO 101057795:error:140770FC:SSL routines:SSL23_GET_SERVER_HELLO:unknown protocol:openssl\ssl\s23_clnt.c:794:
] code: 'EPROTO', errno: 'EPROTO', syscall: 'write' }Reacted by Kiril Popov, Sergei Voronin, 🍉 🍉 🍉, Guilherme Chaguri, pssupport, FireTercel, limion, Jeremy Wallez, Oded Leiba, Jimmy Breck-McKye and 16 moreeBay will add TLS1.2 support to our Production API endpoints on 9/15
https://api.ebay.com
https://svcs.ebay.com@j-langlois IIRC the problem was not the lack of TLS 1.2 support, it was that there were maybe 10 machines in the eBay load balancer, several of them supported TLS 1.2 and several of them did not. The node client couldn't correctly handle the protocol downgrade
Reacted by Kári Tristan HelgasonUsing the following worked for me.
agentOptions: {
ciphers: 'ALL',
secureProtocol: 'TLSv1_1_method',
},Using just TLSv1_method, I cannot load https://www.jewishvoice.org
Reacted by Morten Garbøl Franck, GP, symphonyDev and Judah Gabriel HimangoI can't request my site via HTTPS either.
> { Error: write EPROTO 139966196083584:error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure:s23_clnt.c:772: at _errnoException (util.js:1031:13) at WriteWrap.afterWrite [as oncomplete] (net.js:873:14) errno: 'EPROTO', code: 'EPROTO', syscall: 'write' }My nginx ssl configurations are
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_certificate /***/fullchain.pem; ssl_certificate_key /***/privkey.pem; ssl_ciphers kEECDH+ECDSA+AES256+AESGCM:kEECDH+AES256+AESGCM:kEDH+AES256+AESGCM:kEECDH+ECDSA+AESGCM:kEECDH+AESGCM:kEDH+AESGCM:!DES-CBC3-SHA:!SHA1:!aNULL:!eNULL:!MEDIUM:!LOW:!kECDH:!DSS:!MD5:!EXP:!PSK:!SRP:!CAMELLIA:!SEED; ssl_prefer_server_ciphers on; ssl_session_cache shared:SSL:10m; ssl_ecdh_curve secp384r1;Node.js v9.2.0
OpenSSL 1.1.0g 2 Nov 2017
nginx/1.12.2It has worked before, I don't know when this error started occuring but I've noticed just now
EDIT: I found better help from #16196, setting
tls.DEFAULT_ECDH_CURVEto"auto"fixes my issue- added a commit that references this issue
on Dec 7, 2017 I'll close this out, doesn't look like there's anything left to do. The upstream openssl changes were merged last year.
Reacted by Tristan SlominskiReacted by Marti Martz, Thibault Jan Beyer, Mark, Steve, Slava, John Mora, astroanu, Jean Pierre, Arman Yeghiazaryan, Kv Manohar and 19 morecreate-react-app failed, reason: write EPROTO 14100:error:14094438:SSL
SSL routines:ssl3_read_bytes:tlsv1 alert internalany answer please
Reacted by rurouni and 二休Im getting a very similar error using a truffle for Ethereum development. happens in my virtual machine, host machine and MacOS. Not getting a lot of answers from the Truffle Devs. They just shrugged.
✔ Preparing to download box ⠏ DownloadingError: write EPROTO 4569120192:error:1408F10B:SSL routines:ssl3_get_record:wrong version number:../deps/openssl/openssl/ssl/record/ssl3_record.c:252: at WriteWrap.afterWrite (net.js:779:14)LOL got this error when using simplest nodejs module - request (https://www.npmjs.com/package/request).
It happened when I tried to access this page:
https://pclab.pl/Error: write EPROTO 140329133451072:error:1414D172:SSL routines:tls12_check_peer_sigalg:wrong signature type:../ssl/t1_lib.c:1145:I have no idea WTF is going one... and how to fix this.
getting this in v16.14.0
Reacted by Ramzi Abdoch, Thomas Harris, __df, Pratik Bodawala, Billy Riantono, Aaron Kauffman, Ze Chen, Minghe, Misha, Oleksandr Sek and 1 moreGot this error while using the
https.request()method to proxy incoming connections on an express server. Problem for me was thehostheader, stripping it from the proxied request fixed this bug for me.Might not be the solution for everyone but hopefully this helps.
node v18.11.0
Reacted by Elevenhey @naatebarber would appreciate if you could provide an example or snippet,
thank youReacted by spamator12, Zayn Hao and Cindy Lin
My code is littered with both HTTP and HTTPS requests. I have no idea what is causing this error but it is occurring in many places since I've upgraded to 4.2.1 from 0.12.7. Please tell me what information I need to provide to help debug this.