# NO HTTPS support?

**URL:** <https://cylc.discourse.group/t/no-https-support/783>\
**Category:** Cylc Support\
**Created:** [October 18, 2023, 7:19pm UTC](https://cylc.discourse.group/t/no-https-support/783 "2023-10-18T19:19:22Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![schaferk](https://yyz2.discourse-cdn.com/free1/user_avatar/cylc.discourse.group/schaferk/32/92_2.png) [@schaferk](https://cylc.discourse.group/u/schaferk)\
**Post date:** [October 18, 2023, 7:19pm UTC](https://cylc.discourse.group/t/no-https-support/783/1 "2023-10-18T19:19:23Z")

</div>

cylc-7.9.1

recently after a maintenance upgrade our suites began failing with:

```auto
.service/ssl.pem does not exist.
.service/ssl.cert does not exist.

```

Previously upon install and initiation of a suite.rc  
in response to

```auto
2023-10-18T19:21:05Z ERROR - no HTTPS/OpenSSL support. Aborting...
2023-10-18T19:21:05Z ERROR - "No HTTPS support. 
Configure user's global.rc to use HTTP."

```

we changed (in global.rc)

```auto
method = http -> method =https

```

This change (prior to the ‘upgrade’) would  
permit suites to run.

a recent workaround in response to the ‘missing’ files (post upgraded)  
consisted of editing global.rc:

```auto
< host = `hostname -f`
< method = hardwired

```

we were then informed that ‘http’ would no longer be permitted and  
that ‘https’ is required.

my questions:

where do I begin?  
will a patch to cylc be required?

it would be best if the global.rc file generated by

```auto
cylc get-global-config > global.rc

```

could be used.

thank you for your time.

---

<div class="post-metadata">

**Author:** ![hilary.j.oliver](https://yyz2.discourse-cdn.com/free1/user_avatar/cylc.discourse.group/hilary.j.oliver/32/4_2.png) [@hilary.j.oliver](https://cylc.discourse.group/u/hilary.j.oliver)\
**Post date:** [October 18, 2023, 8:49pm UTC](https://cylc.discourse.group/t/no-https-support/783/2 "2023-10-18T20:49:33Z")

</div>

If you want to use HTTPS (in any context, not just with Cylc) you need the right SSL libraries on the system, and an SSL certificate.

For SSL use with Cylc 7, the installation requirements are here: [3. Installation — The Cylc Suite Engine 7.9.3 documentation](https://cylc.github.io/cylc-doc/7.9.3/html/installation.html#third-party-software-packages)

If you have those packages installed, Cylc will automatically generate the certificate `ssl.cert` and private key `ssl.pem` files. Presumably they have not been installed?

The only alternative is plain HTTP, which it seems you’re not allowed to use anymore.

OR migrate to Cylc 8! (Which doesn’t use HTTP(S) for job comms, and manages software dependencies automatically, via `pip` or `conda`).

---

<div class="post-metadata">

**Author:** ![schaferk](https://yyz2.discourse-cdn.com/free1/user_avatar/cylc.discourse.group/schaferk/32/92_2.png) [@schaferk](https://cylc.discourse.group/u/schaferk)\
**Post date:** [October 18, 2023, 9:05pm UTC](https://cylc.discourse.group/t/no-https-support/783/3 "2023-10-18T21:05:54Z")

</div>

thank you H:  
I/ll review the installation requirements.

---

<div class="post-metadata">

**Author:** ![dpmatthews](https://yyz2.discourse-cdn.com/free1/user_avatar/cylc.discourse.group/dpmatthews/32/26_2.png) [@dpmatthews](https://cylc.discourse.group/u/dpmatthews)\
**Post date:** [October 19, 2023, 6:46am UTC](https://cylc.discourse.group/t/no-https-support/783/4 "2023-10-19T06:46:03Z")

</div>

Run `cylc check-software` and it will tell you whether your installation meets the requirements for the https comms.

---

<div class="post-metadata">

**Author:** ![russbnavy](https://yyz2.discourse-cdn.com/free1/user_avatar/cylc.discourse.group/russbnavy/32/96_2.png) [@russbnavy](https://cylc.discourse.group/u/russbnavy)\
**Post date:** [October 19, 2023, 2:42pm UTC](https://cylc.discourse.group/t/no-https-support/783/5 "2023-10-19T14:42:55Z")

</div>

So, interestingly, I’ve had similar issues on our RHEL 8 upgrade system to where check-software on Cylc 7.9.7 reports no issues but connections to the suite instances hang on SSL handshake and we haven’t had any luck solving it. We’ve tried turning off SE linux, opening up ip tables all the way, generating keys with different cyphers, etc and just can’t get past the SSL handshake. Has anyone else reported that kind of behavior? We gave up and disabled HTTPS for now.

Edit:  
The specific test we used was given a suite host running on HOST:PORT:

```auto
openssl s_client -msg -debug -state -connect HOST:PORT

```

After connecting and getting some handshake hex, it hangs on:

```auto
SSL_connect:SSLv3/TLS write client hello

```

We’re seeing this behavior on two seperate clusters now…

---

<div class="post-metadata">

**Author:** ![hilary.j.oliver](https://yyz2.discourse-cdn.com/free1/user_avatar/cylc.discourse.group/hilary.j.oliver/32/4_2.png) [@hilary.j.oliver](https://cylc.discourse.group/u/hilary.j.oliver)\
**Post date:** [October 19, 2023, 10:56pm UTC](https://cylc.discourse.group/t/no-https-support/783/6 "2023-10-19T22:56:53Z")

</div>

@russbnavy - thanks for the info.

> Has anyone else reported that kind of behavior?

This is the first I’ve heard, but maybe your move to RHEL 8 on HPC is ahead of others still using Cylc 7.

> check-software on Cylc 7.9.7 reports no issues

check-software only checks that the right packages are installed and available in your environment.

> The specific test we used was given a suite host running on HOST:PORT:…

Just to confirm, you are seeing this behaviour with openssl itself, independent of Cylc? If so, that’s (arguably!) good, and I would hope that it has been reported elsewhere. Have you tried asking at the openssl project?

---

<div class="post-metadata">

**Author:** ![russbnavy](https://yyz2.discourse-cdn.com/free1/user_avatar/cylc.discourse.group/russbnavy/32/96_2.png) [@russbnavy](https://cylc.discourse.group/u/russbnavy)\
**Post date:** [October 20, 2023, 2:17pm UTC](https://cylc.discourse.group/t/no-https-support/783/7 "2023-10-20T14:17:34Z")

</div>

Unfortunately we haven’t seen this issue with any other tools that utilize OpenSSL but good point, I’ll try reaching out to the OpenSSL project to see if there’s a way to glean more information besides hanging at the first stage of the handshake.

Edit: we’re seeing it on SUSE Enterprise 15 SP4 as well as RHEL 8… So perhaps it’s a Python 2.7 bug with the latest OpenSSL…

---

<div class="post-metadata">

**Author:** ![schaferk](https://yyz2.discourse-cdn.com/free1/user_avatar/cylc.discourse.group/schaferk/32/92_2.png) [@schaferk](https://cylc.discourse.group/u/schaferk)\
**Post date:** [October 20, 2023, 5:06pm UTC](https://cylc.discourse.group/t/no-https-support/783/8 "2023-10-20T17:06:31Z")

</div>

```auto
check-software shows (my edit):

*OPTIONAL SOFTWARE for the HTTPS communications layer*                  
Python:requests (2.4.2+).FOUND& min. version MET (2.9.1)
Python:urllib3 (any)..........FOUND (1.13.1)
Python:OpenSSL (any).....NOT FOUND (-)

looking at the NOT FOUND.

edit:
Python:OpenSSL (any)....................FOUND (21.0.0)

yahoo
```

---

<div class="post-metadata">

**Author:** ![schaferk](https://yyz2.discourse-cdn.com/free1/user_avatar/cylc.discourse.group/schaferk/32/92_2.png) [@schaferk](https://cylc.discourse.group/u/schaferk)\
**Post date:** [October 22, 2023, 4:01pm UTC](https://cylc.discourse.group/t/no-https-support/783/9 "2023-10-22T16:01:57Z")

</div>

> [@russbnavy](#):
>
> `openssl s_client -msg -debug -state -connect HOST:PORT`

```auto
testing russbnavy's openssl debug (above)

...
edit:
SSL routines:ssl3_get_record:wrong version number:ssl/record/ssl3_record.c:332:

```

---

<div class="post-metadata">

**Author:** ![dpmatthews](https://yyz2.discourse-cdn.com/free1/user_avatar/cylc.discourse.group/dpmatthews/32/26_2.png) [@dpmatthews](https://cylc.discourse.group/u/dpmatthews)\
**Post date:** [October 23, 2023, 9:05am UTC](https://cylc.discourse.group/t/no-https-support/783/10 "2023-10-23T09:05:42Z")

</div>

I have https working on Centos 8 with pyOpenSSL 19.0 installed via

```auto
sudo pip2 install "pyOpenSSL<19.1"

```

I can’t remember why I needed “\<19.1” but it seems to work.

---

<div class="post-metadata">

**Author:** ![russbnavy](https://yyz2.discourse-cdn.com/free1/user_avatar/cylc.discourse.group/russbnavy/32/96_2.png) [@russbnavy](https://cylc.discourse.group/u/russbnavy)\
**Post date:** [October 23, 2023, 4:51pm UTC](https://cylc.discourse.group/t/no-https-support/783/11 "2023-10-23T16:51:24Z")

</div>

Hey! That was it for us, downgrading pyOpenSSL to \<19.1 from 20.0.1 did the trick. Thanks!

---

<div class="post-metadata">

**Author:** ![schaferk](https://yyz2.discourse-cdn.com/free1/user_avatar/cylc.discourse.group/schaferk/32/92_2.png) [@schaferk](https://cylc.discourse.group/u/schaferk)\
**Post date:** [October 23, 2023, 10:08pm UTC](https://cylc.discourse.group/t/no-https-support/783/12 "2023-10-23T22:08:31Z")

</div>

```auto
modifying the definition file of the container referenced

```

[Cylc and Singularity container](https://cylc.discourse.group/t/cylc-and-singularity-container/274)

```auto
a container running cylc-7.9.8 ran a simple suite using the HTTPS layer.
key changes (including pyOpenSSl<19.0) are listed at the referenced URL.
```
