# Curl: (77) Problem with the SSL CA cert (path? access rights?)

**URL:** <https://discuss.elastic.co/t/curl-77-problem-with-the-ssl-ca-cert-path-access-rights/338761>\
**Category:** Elastic Security\
**Created:** [July 19, 2023, 9:29am UTC](https://discuss.elastic.co/t/curl-77-problem-with-the-ssl-ca-cert-path-access-rights/338761 "2023-07-19T09:29:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![PodarcisMuralis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/podarcismuralis/32/122606_2.png) [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Post date:** [July 19, 2023, 9:29am UTC](https://discuss.elastic.co/t/curl-77-problem-with-the-ssl-ca-cert-path-access-rights/338761/1 "2023-07-19T09:29:39Z")

</div>

Hi,

I use a shell script to send curl to elasticsearch. But I got this error:

`curl: (77) Problem with the SSL CA cert (path? access rights?)`

My curl is like:

`RESPONSE=$(curl -v -s -w "%{http_code}" -o /dev/null -XDELETE -u "${USERNAME}:${PASSWORD}" --cacert "${CACERT_PATH}" "${ELASTICSEARCH_URL}/${INDEX}")`

CACERT\_PATH= /etc/certs/mycert.cer  
ELASTICSEARCH\_URL="[https://HOST:9200](https://HOST:9200)"

- When I disable certificate usage with -k or --insecure, it works perfect.

- The script and elasticsearch are on the same Linux server.

The problem should be either user rights or certificate itself. Because it works without certificate check.

Thanks.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 19, 2023, 2:22pm UTC](https://discuss.elastic.co/t/curl-77-problem-with-the-ssl-ca-cert-path-access-rights/338761/2 "2023-07-19T14:22:37Z")

</div>

> [@PodarcisMuralis](#):
>
> CACERT\_PATH= /etc/certs/mycert.cer

That needs to be a CA perhaps that is just the normal cert

Can you run just run curl with the -v and show the output

---

<div class="post-metadata">

**Author:** ![PodarcisMuralis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/podarcismuralis/32/122606_2.png) [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Post date:** [July 20, 2023, 6:30am UTC](https://discuss.elastic.co/t/curl-77-problem-with-the-ssl-ca-cert-path-access-rights/338761/3 "2023-07-20T06:30:54Z")

</div>

```auto
[user]$ ./shellscript.sh
START -----> shell script
  % Total % Received % Xferd Average Speed Time Time Time Current
                                 Dload Upload Total Spent Left Speed
  0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0* About to connect() to MYHOST port 9200 (#0)
* Trying IP...
* Connected to MYHOST (IP) port 9200 (#0)
* Initializing NSS with certpath: sql:/etc/pki/nssdb
* Closing connection 0
curl: (77) Problem with the SSL CA cert (path? access rights?)

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 20, 2023, 1:18pm UTC](https://discuss.elastic.co/t/curl-77-problem-with-the-ssl-ca-cert-path-access-rights/338761/4 "2023-07-20T13:18:34Z")

</div>

Again, looks to me like you're using a normal cert not a CA..  
Did you create those certs yourself?

Did you check the path information on the file?

> [@PodarcisMuralis](#):
>
> `sql:/etc/pki/nssdb`

That looks odd too.

You should try running the curl manually outside your script

Also you should look up some of the openssl commands and just check the cert something like this

`openssl x509 -in /etc/certs/mycert.cer -text -noout`

---

<div class="post-metadata">

**Author:** ![PodarcisMuralis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/podarcismuralis/32/122606_2.png) [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Post date:** [August 10, 2023, 7:39am UTC](https://discuss.elastic.co/t/curl-77-problem-with-the-ssl-ca-cert-path-access-rights/338761/5 "2023-08-10T07:39:34Z")

</div>

Finally I found out the reason.

I used .cer certificate but it did not work.  
I converted it to .pem file beginning with "BEGIN CERTIFICATE" and ending with "END CERTIFICATE".  
It also did not work.

I used the same pem but added at the beginning the bag attributes.

```auto
Bag Attributes
localKeyID: ...
subject=...
issuer=...
subject=...
issuer=...
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
Bag Attributes: <Empty Attributes>
subject=...
issuer=...
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----

```

and it worked fine.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2023, 7:40am UTC](https://discuss.elastic.co/t/curl-77-problem-with-the-ssl-ca-cert-path-access-rights/338761/6 "2023-09-07T07:40:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
