TTN West and EU Router certs expired?

Noticed the nodes I have bridged to my mosquitto server stopped updating on the 24th, and an openssl call looks like the certs expired?
CONNECTED(00000003)
depth=2 O = Digital Signature Trust Co., CN = DST Root CA X3
verify return:1
depth=1 C = US, O = Let’s Encrypt, CN = Let’s Encrypt Authority X3
verify return:1
depth=0 CN = us-west.thethings.network
verify error:num=10:certificate has expired
notAfter=Dec 24 10:27:13 2019 GMT
verify return:1
depth=0 CN = us-west.thethings.network
notAfter=Dec 24 10:27:13 2019 GMT
verify return:1

EU expired yesterday:
CONNECTED(00000003)
depth=2 O = Digital Signature Trust Co., CN = DST Root CA X3
verify return:1
depth=1 C = US, O = Let’s Encrypt, CN = Let’s Encrypt Authority X3
verify return:1
depth=0 CN = eu.thethings.network
verify error:num=10:certificate has expired
notAfter=Dec 25 02:54:14 2019 GMT
verify return:1
depth=0 CN = eu.thethings.network
notAfter=Dec 25 02:54:14 2019 GMT
verify return:1

Mosquitto not letting me connect:
1577394483: Connecting bridge bridge-to-ttn (eu.thethings.network:8883)
1577394483: Connecting bridge bridge-to-ttn-us-west (us-west.thethings.network:8883)
1577394483: OpenSSL Error: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
1577394483: Socket error on client local.mqtt.bridge-to-ttn, disconnecting.
1577394483: OpenSSL Error: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
1577394483: Socket error on client local.mqtt.bridge-to-ttn-us-west, disconnecting.
1577394514: Connecting bridge bridge-to-ttn (eu.thethings.network:8883)

2 Likes

Meanwhile, this has been fixed.

As usual: please check https://status.thethings.network and report in the #ops channel in Slack, if not already done so. To get access to Slack, get an invite through https://account.thethingsnetwork.org/

From Slack:

@matthijskooijman_2 2019-12-26 8:19 PM

Hey folks. The TLS certificate on eu.thethings.network 8833 (MQTT) has expired, causing new connections to fail:

openssl s_client -connect eu.thethings.network:8883 2>/dev/null | openssl x509 -text |grep Validity -A 2

Validity
Not Before: Sep 26 02:54:14 2019 GMT
Not After : Dec 25 02:54:14 2019 GMT

@htdvisser 2019-12-27 9:39 AM

Looks like the updated certificate wasn’t picked up by the MQTT server, so we reloaded it manually

1 Like

I wasn’t aware they had Slack for this, thank you!

1 Like