<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL peer certificate or SSH remote key was not OK in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40736#M22112</link>
    <description>Changing our DNS from OpenDNS to Google DNS resolved the issue for us yesterday as well. Could have saved you some troubleshooting by replying yesterday, but I was swamped. Not sure what to really make of this, but it worked.</description>
    <pubDate>Wed, 23 Apr 2014 22:01:08 GMT</pubDate>
    <dc:creator>BrandonM</dc:creator>
    <dc:date>2014-04-23T22:01:08Z</dc:date>
    <item>
      <title>SSL peer certificate or SSH remote key was not OK</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40678#M22084</link>
      <description>&lt;P&gt;I have a production site that worked fine with authorize.net up until about 2:00PM EST today. cURL is throwing back a "&lt;SPAN&gt;SSL peer certificate or SSH remote key was not OK" error when attempting to post data to&amp;nbsp;&lt;A href="https://secure.authorize.net/gateway/transact.dll." target="_blank"&gt;https://secure.authorize.net/gateway/transact.dll.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am the only developer on the site, and I have not logged in at all today until someone reported an issue where they could not complete their transaction. Can anyone provide me with any direction? I have tried restarting the entire device just for good measure. No luck.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 20:02:48 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40678#M22084</guid>
      <dc:creator>BrandonM</dc:creator>
      <dc:date>2014-04-22T20:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: SSL peer certificate or SSH remote key was not OK</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40680#M22085</link>
      <description>&lt;P&gt;I'm presuming this is for an inbound API call for AIM or DPM. If wrong, please let me know.&lt;BR /&gt;&lt;BR /&gt;We haven't made any SSL changes to the Transact servers in about a year. Did you confirm you have up-to-date Entrust CA certificates in your key store?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 20:40:25 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40680#M22085</guid>
      <dc:creator>Lilith</dc:creator>
      <dc:date>2014-04-22T20:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSL peer certificate or SSH remote key was not OK</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40682#M22086</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We also have a machine that started reporting the same errors at approximately 1PM CST today.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Can someone please advise?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Gerald Bauer&lt;/P&gt;&lt;P&gt;JB Systems, LLC&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 20:50:25 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40682#M22086</guid>
      <dc:creator>Mrpbody4</dc:creator>
      <dc:date>2014-04-22T20:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSL peer certificate or SSH remote key was not OK</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40684#M22087</link>
      <description>&lt;P&gt;Additional details from CURL request:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;string(0) "" array(20) { ["url"]=&amp;gt; string(49) "&lt;A target="_blank" href="https://secure.authorize.net/gateway/transact.dll&amp;quot;"&gt;https://secure.authorize.net/gateway/transact.dll"&lt;/A&gt; ["content_type"]=&amp;gt; NULL ["http_code"]=&amp;gt; int(0) ["header_size"]=&amp;gt; int(0) ["request_size"]=&amp;gt; int(0) ["filetime"]=&amp;gt; int(-1) ["ssl_verify_result"]=&amp;gt; int(1) ["redirect_count"]=&amp;gt; int(0) ["total_time"]=&amp;gt; float(0.000953) ["namelookup_time"]=&amp;gt; float(5.7E-5) ["connect_time"]=&amp;gt; float(0.000999) ["pretransfer_time"]=&amp;gt; float(0) ["size_upload"]=&amp;gt; float(0) ["size_download"]=&amp;gt; float(0) ["speed_download"]=&amp;gt; float(0) ["speed_upload"]=&amp;gt; float(0) ["download_content_length"]=&amp;gt; float(-1) ["upload_content_length"]=&amp;gt; float(-1) ["starttransfer_time"]=&amp;gt; float(0) ["redirect_time"]=&amp;gt; float(0) } SSL peer certificate or SSH remote key was not OK&lt;BR /&gt;Array ( [url] =&amp;gt; &lt;A target="_blank" href="https://secure.authorize.net/gateway/transact.dll"&gt;https://secure.authorize.net/gateway/transact.dll&lt;/A&gt; [content_type] =&amp;gt; [http_code] =&amp;gt; 0 [header_size] =&amp;gt; 0 [request_size] =&amp;gt; 0 [filetime] =&amp;gt; -1 [ssl_verify_result] =&amp;gt; 1 [redirect_count] =&amp;gt; 0 [total_time] =&amp;gt; 0.000953 [namelookup_time] =&amp;gt; 5.7E-5 [connect_time] =&amp;gt; 0.000999 [pretransfer_time] =&amp;gt; 0 [size_upload] =&amp;gt; 0 [size_download] =&amp;gt; 0 [speed_download] =&amp;gt; 0 [speed_upload] =&amp;gt; 0 [download_content_length] =&amp;gt; -1 [upload_content_length] =&amp;gt; -1 [starttransfer_time] =&amp;gt; 0 [redirect_time] =&amp;gt; 0 )&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 21:12:35 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40684#M22087</guid>
      <dc:creator>Mrpbody4</dc:creator>
      <dc:date>2014-04-22T21:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSL peer certificate or SSH remote key was not OK</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40688#M22089</link>
      <description>&lt;P&gt;Could you please share HTTPS log data, please, so we can see where your SSL configuration is failing?&lt;BR /&gt;&lt;BR /&gt;I believe on IIS-based servers you may need to &lt;A href="http://msdn.microsoft.com/en-us/library/windows/desktop/bb648687(v=vs.85).aspx" target="_self" rel="nofollow"&gt;enable WinHTTP logging &lt;/A&gt;first, then &lt;A href="http://msdn.microsoft.com/en-us/library/windows/desktop/bb648706(v=vs.85).aspx" target="_self" rel="nofollow"&gt;check the log for SSL/TLS errors&lt;/A&gt;. There are similar steps you may need to take &lt;A href="http://wiki.apache.org/httpd/DebuggingSSLProblems#Enable_SSL_logging" target="_self" rel="nofollow"&gt;on Apache servers&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 21:18:44 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40688#M22089</guid>
      <dc:creator>Lilith</dc:creator>
      <dc:date>2014-04-22T21:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: SSL peer certificate or SSH remote key was not OK</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40690#M22090</link>
      <description>&lt;P&gt;Certainly. Just a few moments please...&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 21:19:23 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40690#M22090</guid>
      <dc:creator>Mrpbody4</dc:creator>
      <dc:date>2014-04-22T21:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSL peer certificate or SSH remote key was not OK</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40692#M22091</link>
      <description>&lt;P&gt;It appears our machine is not setup for logging this.&lt;BR /&gt;Any tips?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 21:24:08 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40692#M22091</guid>
      <dc:creator>Mrpbody4</dc:creator>
      <dc:date>2014-04-22T21:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL peer certificate or SSH remote key was not OK</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40694#M22092</link>
      <description>&lt;P&gt;Our server started establishing connections again. We rebooted Apache a couple of times through this process, otherwise&lt;/P&gt;&lt;P&gt;no significant changes were made.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Was something done on Authorize's end?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 21:38:50 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40694#M22092</guid>
      <dc:creator>Mrpbody4</dc:creator>
      <dc:date>2014-04-22T21:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL peer certificate or SSH remote key was not OK</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40720#M22105</link>
      <description>&lt;P&gt;As I mentioned, we haven't made any SSL configuration changes to the Transact servers in about a year. That's why I was asking for logs, so we can see exactly where the SSL negotiation is breaking down.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 16:14:06 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40720#M22105</guid>
      <dc:creator>Lilith</dc:creator>
      <dc:date>2014-04-23T16:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: SSL peer certificate or SSH remote key was not OK</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40726#M22108</link>
      <description>&lt;P&gt;We're also experiencing this issue. No changes have been made on our servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When trying to curl from command line:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;curl &lt;A target="_blank" href="https://secure.authorize.net/gateway/transact.dll"&gt;https://secure.authorize.net/gateway/transact.dll&lt;/A&gt;&lt;BR /&gt;curl: (51) SSL peer certificate or SSH remote key was not OK&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What other logs would you like to see?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 16:57:57 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40726#M22108</guid>
      <dc:creator>aniemi</dc:creator>
      <dc:date>2014-04-23T16:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSL peer certificate or SSH remote key was not OK</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40728#M22109</link>
      <description>&lt;P&gt;Strangely enough I was able o fix this problem by changing our DNS on the server from using OpenDNS to Google.&lt;/P&gt;&lt;P&gt;I'm not sure why/how, but it appears OpenDNS is having an issue.&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 18:15:02 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40728#M22109</guid>
      <dc:creator>aniemi</dc:creator>
      <dc:date>2014-04-23T18:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSL peer certificate or SSH remote key was not OK</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40736#M22112</link>
      <description>Changing our DNS from OpenDNS to Google DNS resolved the issue for us yesterday as well. Could have saved you some troubleshooting by replying yesterday, but I was swamped. Not sure what to really make of this, but it worked.</description>
      <pubDate>Wed, 23 Apr 2014 22:01:08 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40736#M22112</guid>
      <dc:creator>BrandonM</dc:creator>
      <dc:date>2014-04-23T22:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL peer certificate or SSH remote key was not OK</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40750#M22118</link>
      <description>&lt;P&gt;That's odd that OpenDNS was causing issues, but not Google DNS.&lt;BR /&gt;&lt;BR /&gt;I did a cursory poke at the DNS A records showing up on both servers and compared it to my local DNS A records, and they show the same IP addresses, so I'm not sure where the discrepancy lies.&lt;BR /&gt;&lt;BR /&gt;But I'm glad to know there is at least a workaround.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Aniemi, to answer your earlier question about curl: If you use the --verbose (-v for short) flag, it should dump every step of establishing the connection, including DNS lookup, SSL/TLS negotiation, and of course the raw HTTP data. &lt;BR /&gt;&lt;BR /&gt;I find it sometimes useful to run "curl -v &lt;A href="https://secure.authorize.net/gateway/transact.dll&amp;quot;" target="_blank"&gt;https://secure.authorize.net/gateway/transact.dll"&lt;/A&gt; to troubleshoot connection issues to us, and it may have exposed the OpenDNS issue you've now noticed.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2014 15:37:09 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SSL-peer-certificate-or-SSH-remote-key-was-not-OK/m-p/40750#M22118</guid>
      <dc:creator>Lilith</dc:creator>
      <dc:date>2014-04-24T15:37:09Z</dc:date>
    </item>
  </channel>
</rss>

