[AMS 2.2 EE] Let's Encrypt Certificate Problem

475 views
Skip to first unread message

Daniel Biagi

unread,
Nov 4, 2020, 11:43:36 AM11/4/20
to Ant Media Server
Hello guys, how are you?


Just deployed AMS 2.2 from AWS Marketplace, did the setup (disabled IP filter) and although the dashboard is working securely, I can't call any REST endpoints because of a certificate error.

My application can't connect to it and even Postman returns me an error:

unable to verify the first certificate

Checking the generated certificate also don't appear to be right:
image.png

Can you help me, please?


Thanks,

Daniel.

burak

unread,
Nov 5, 2020, 1:30:16 PM11/5/20
to Ant Media Server
Can you login to management panel?

4 Kasım 2020 Çarşamba tarihinde saat 19:43:36 UTC+3 itibarıyla Daniel Biagi şunları yazdı:

Daniel Biagi

unread,
Nov 5, 2020, 4:43:22 PM11/5/20
to burak, Ant Media Server
Yes, I can login and operate everything normally from the management panel but all REST API invocations fail because of the certificate issue.
I can disable SSL verification but then there would be no reason to use HTTPS at all and could lead to future problems in production environment.


Daniel Biagi


--
You received this message because you are subscribed to the Google Groups "Ant Media Server" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ant-media-serv...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ant-media-server/a6596ba8-bd45-4bc1-8604-82874ac825aen%40googlegroups.com.

Jake Withecombe

unread,
Nov 6, 2020, 6:44:47 AM11/6/20
to Ant Media Server
We have exactly the same issue using the community edition: https://www.sslshopper.com/ssl-checker.html#hostname=https://ant.onvp.io:5443

Jake Withecombe

unread,
Nov 6, 2020, 8:04:40 AM11/6/20
to Ant Media Server

burak

unread,
Nov 7, 2020, 12:46:51 AM11/7/20
to Ant Media Server
Hi Friends,
I have tried and confirmed the issue also brought the the Jake's GitHub issue to the top of the list.

6 Kasım 2020 Cuma tarihinde saat 16:04:40 UTC+3 itibarıyla Jake Withecombe şunları yazdı:

burak

unread,
Nov 17, 2020, 2:36:28 PM11/17/20
to Ant Media Server

There is a simple solution for now. But we are working on a better one. For now you can use the ready one.

Copy chain.pem to conf. 
sudo cp /etc/letsencrypt/live/your_domain/chain.pem /usr/local/antmedia/conf

Add this line
http.ssl_certificate_chain_file=conf/chain.pem
after
http.ssl_certificate_file=conf/fullchain.pem
Add this line
<entry key="SSLCertificateChainFile" value="${http.ssl_certificate_chain_file}" />
after
<entry key="SSLCertificateFile" value="${http.ssl_certificate_file}" /> 
7 Kasım 2020 Cumartesi tarihinde saat 08:46:51 UTC+3 itibarıyla burak şunları yazdı:

burak

unread,
Nov 25, 2020, 10:59:05 AM11/25/20
to Ant Media Server
Copy chain.pem to conf. 
sudo cp /etc/letsencrypt/live/your_domain/chain.pem /usr/local/antmedia/conf

Add this line
http.ssl_certificate_chain_file=conf/chain.pem
after
http.ssl_certificate_file=conf/fullchain.pem
in
/usr/local/antmedia/conf/red5.properties file.
Add this line
<entry key="SSLCertificateChainFile" value="${http.ssl_certificate_chain_file}" />
after
<entry key="SSLCertificateFile" value="${http.ssl_certificate_file}" /> 
in
/usr/local/antmedia/conf/jee-container.xml

17 Kasım 2020 Salı tarihinde saat 22:36:28 UTC+3 itibarıyla burak şunları yazdı:

Orana Wildlife Park

unread,
Jan 21, 2021, 2:54:28 PM1/21/21
to Ant Media Server
burak has this issue been fixed yet?

Ant Media Support

unread,
Jan 22, 2021, 4:45:48 PM1/22/21
to oranawild...@gmail.com, ant-medi...@googlegroups.com
Hi Orana,
​The process I told in my last main will be done automatically in the next release. But you need to do that manually for the current version. 

Give star to Ant Media Server on Github and get a chance to win an AMS Enterprise License.

Regards,
Burak Kekec
, Orana Wildlife Park <oranawild...@gmail.com> wrote:

Orana Wildlife Park

unread,
Jan 22, 2021, 9:41:57 PM1/22/21
to Ant Media Server
I tried that and for whatever reason it didn't work so rolled back to 2.1. Do you have an ETA on the next release? Thanks

Ant Media Support

unread,
Jan 23, 2021, 10:02:57 AM1/23/21
to oranawild...@gmail.com, ant-medi...@googlegroups.com
Hi Orana,
We are planning to release it in two weeks.
Give star to Ant Media Server on Github and get a chance to win an AMS Enterprise License.

Regards,
Burak Kekec
On Sat, 23 Jan at 4:42 AM
, Orana Wildlife Park <oranawild...@gmail.com> wrote:
I tried that and for whatever reason it didn't work so rolled back to 2.1. Do you have an ETA on the next release? Thanks

On Saturday, January 23, 2021 at 10:45:48 AM UTC+13 support wrote:
Hi Orana,
​The process I told in my last main will be done automatically in the next release. But you need to do that manually for the current version. 

Give star to Ant Media Server on Github and get a chance to win an AMS Enterprise License.

Regards,
Burak Kekec
On Thu, 21 Jan at 9:54 PM
burak has this issue been fixed yet?

Reply all
Reply to author
Forward
0 new messages