Secure Connection Failed

Hmm, yes, I just checked the address with the checker tool that was provided and can confirm that it is pointing to the correct IP and, to me, the SSL details all look correct.

The odd thing is that when I added the URL above, the following is displayed (screenshot)


None of that content is on the server I am currently troubleshooting. It is from the hospital website...which I have no control over or access to.

I'm guessing you are unable to access anything at the URL --> www.shizuoka-kikoesupport.jp?

I did clear my cache but it didn't change anything...aside from logging me out here. :slight_smile:

Results are:
Run as root

tcp        0      0 0.0.0.0:443             0.0.0.0:*               LISTEN      243670/nginx: maste 
tcp        0      0 127.0.0.1:8000          0.0.0.0:*               LISTEN      1702/python         
tcp        0      0 0.0.0.0:80              0.0.0.0:*               LISTEN      243670/nginx: maste 
tcp6       0      0 :::443                  :::*                   LISTEN      243670/nginx: maste 
tcp6       0      0 :::80                   :::*                    LISTEN      243670/nginx: maste 

Oops, sorry, guess that second one wasn't necessary.

Please show:
ps -ef | grep nginx | grep -v grep

4 Likes

Results are:

root      243670       1  0 16:37 ?        00:00:00 nginx: master process /usr/sbin/nginx -g daemon on; master_process on;
www-data  243671  243670  0 16:37 ?        00:00:00 nginx: worker process
www-data  243672  243670  0 16:37 ?        00:00:00 nginx: worker process
www-data  243673  243670  0 16:37 ?        00:00:00 nginx: worker process
www-data  243674  243670  0 16:37 ?        00:00:00 nginx: worker process
www-data  243675  243670  0 16:37 ?        00:00:00 nginx: worker process
www-data  243676  243670  0 16:37 ?        00:00:00 nginx: worker process
www-data  243677  243670  0 16:37 ?        00:00:00 nginx: worker process
www-data  243678  243670  0 16:37 ?        00:00:00 nginx: worker process
www-data  243679  243670  0 16:37 ?        00:00:00 nginx: cache manager process

I can't find a reason why this problem happens.

3 Likes

Hmm, ok, thanks. I'm kind of lost. :frowning: Just to confirm, you aren't able to access this site, correct? --> www.shizuoka-kikoesupport.jp

curl, wget, and openssl, as well as several online "tests" all seem to pass.

But my browser shows:
image

4 Likes

Here is the content of what is returned:

<!DOCTYPE html>
<html lang="jp">
<head>
<meta charset="UTF-8">
<meta name="keywords" content="静岡県立総合病院,がん医療,救急医療,循環器医療,静岡市,看護師">
<meta name="description" content="静岡県立総合病院は静岡市葵区にある総合病院です。30を超える診療科と救命医療・医療連携を推進し、地域の皆さまに安心の医療体制を提供。加えて、循環器病診療・がん診療連携拠点病院として質の高い医療を提供しています。">
<meta name="viewport" content="width=device-width">
<meta name="format-detection" content="telephone=no">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta property="og:title" content="きこえとことばのセンター(静岡県乳幼児聴覚支援センター)">
<meta property="og:type" content="article">
<meta property="og:description" content="静岡県立総合病院は静岡市葵区にある総合病院です。30を超える診療科と救命医療・医療連携を推進し、地域の皆さまに安心の医療体制を提供。加えて、循環器病診療・がん診療連携拠点病院として質の高い医療を提供しています。">
<meta property="og:site_name" content="静岡県乳幼児聴覚支援センター">
<title>きこえとことばのセンター(静岡県乳幼児聴覚支援センター) |  きこえとことばのセンター(静岡県乳幼児聴覚支援センター)</title>
<link rel="shortcut icon" type="image/x-icon" href="include/images/favicon.ico">
<link rel="apple-touch-icon" href="include/images/apple-touch-icon.png" sizes="180x180">
<link rel="stylesheet" href="include/css/top.pc.css" media="print, screen and (min-width: 641px)">
<link rel="stylesheet" href="include/css/top.sp.css" media="screen and (max-width: 640px)">
</head>
<body>
<div id="container">

<div id="header">
        <div class="container">
                <div class="h_logo">
                        <h1><a href="index.html"><img alt="きこえとことばのセンター(静岡県乳幼児聴覚支援センター)" src="include/images/h_logo.png"></a></h1>
                        <div class="h_swicth sp"><span>MENU</span></div>
                </div>
                <div id="navi">
                        <ul>
                                <li><a href="https://shizuokapho.eshizuoka.jp/" target="_blank"><span>お知らせ</span></a></li>
                                <li><a href="baby/index.html"><span>聴覚検査</span></a></li>
                                <li><a href="room/index.html"><span>きこえの相談室</span></a></li>
                                <li><a href="family/index.html"><span>きこえのお部屋</span></a></li>
                                <li><a href="notebook/index.html"><span>きこえの手帳</span></a></li>
                                <li><a href="hearingaid/index.html"><span>補聴援助</span></a></li>
                                <li><a href="#contact">お問い合わせ</a></li>
                        </ul>
                </div>
        </div>
</div>
<!--/header-->

<div class="container">

<div id="main">
        <div id="slider">
                <ul class="slides clearfix">
                        <li><img alt="静岡県立総合病院" src="include/images/visual_01.png"></li>
                        <li><img alt="静岡県立総合病院" src="include/images/visual_02.png"></li>
                        <li><img alt="静岡県立総合病院" src="include/images/visual_03.png"></li>
                        <li><img alt="静岡県立総合病院" src="include/images/visual_04.png"></li>
                        <li><img alt="静岡県立総合病院" src="include/images/visual_05.png"></li>
                </ul>
        </div>
</div>
<!--/main-->

<div id="news">
        <h2>お知らせ</h2>
        <div class="section">
                                <dl>
                                        <dt>2022年02月22日</dt>
                                        <dd><a href="https://shizuokapho.eshizuoka.jp/e2168689.html" target="_blank">沼津きこえの相談室 お休みの御連絡</a></dd>
                                </dl>
                                <dl>
                                        <dt>2022年01月27日</dt>
                                        <dd><a href="https://shizuokapho.eshizuoka.jp/e2164979.html" target="_blank">2月浜松きこえのお部屋 開催中止のお知らせ</a></dd>
                                </dl>
                                <dl>
                                        <dt>2021年09月21日</dt>
                                        <dd><a href="https://shizuokapho.eshizuoka.jp/e2146546.html" target="_blank">2021年度 精度管理WEB研修会について(10/28更新)</a></dd>
                                </dl>
                                <dl>
                                        <dt>2021年09月10日</dt>
                                        <dd><a href="https://shizuokapho.eshizuoka.jp/e2144872.html" target="_blank">沼津 きこえの相談室のご案内</a></dd>
                                </dl>
        </div>
        <ul>
                <li><a href="https://shizuokapho.eshizuoka.jp/" target="_blank">全てを見る</a></li>
        </ul>
</div>
<!--/news-->

<div id="baby">
        <div class="movie">
                <h2>赤ちゃんの聴覚検査</h2>
                <div class="section">
                        <figure data-id="8z3SCagQ7AA">
                                <img alt="新生児聴覚スクリーニング" src="include/images/baby_01.png">
                                <figcaption>新生児聴覚スクリーニング(7分)</figcaption>
                        </figure>
                </div>
                <div class="section">
                        <a href="baby/index.html">
                                <img alt="再検査になったら" src="include/images/baby_02.png"><br>
                                <span>再検査になったら</span>
                        </a>
                </div>
                <div class="section">
                        <figure data-id="Z7xsmNXL344">
                                <img alt="耳の仕組み" src="include/images/baby_03.png">
                                <figcaption>耳の仕組み(きこえとことばのセンター長 髙木明)(1分26秒)</figcaption>
                        </figure>
                </div>
        </div>
</div>
<!--/baby-->

<div class="overlay">
        <div class="overlay_body">
                <span class="overlay_close"></span>
                <iframe src="" allow="accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe>
        </div>
</div>
<!--/overlay-->

<div class="movie">
        <div id="room">
                <h2>きこえの相談室</h2>
                <div class="section">
                        <a href="room/index.html">
                                <img alt="きこえの相談室" src="include/images/room_01.png"><br>
                                <span>きこえの相談室</span>
                        </a>
                </div>
        </div>
</div>
<!--/room-->

<div class="movie">
        <div id="family">
                <h2>きこえのお部屋</h2>
                <div class="section">
                        <a href="family/index.html#family">
                                <img alt="親子教室・スタッフ紹介" src="include/images/family_01.png"><br>
                                <span>親子教室・スタッフ紹介</span>
                        </a>
                </div>
                <div class="section">
                        <figure data-id="mJ47PloGMNA">
                                <img alt="うたあそび" src="include/images/family_03.png">
                                <figcaption>うたあそび(4分33秒)</figcaption>
                        </figure>
                </div>
                <div class="section">
                        <figure data-id="EZP6AXuE_8M">
                                <img alt="絵本の読み語り" src="include/images/family_04.png">
                                <figcaption>絵本の読み語り(2分59秒)</figcaption>
                        </figure>
                </div>
        </div>
</div>
<!--/family-->

<div id="welfare">
        <div class="movie">
                <h2>福祉サービス</h2>
                <div class="section">
                        <a href="notebook/index.html">
                                <img alt="きこえの手帳" src="include/images/welfare_01.png"><br>
                                <span>きこえの手帳</span>
                        </a>
                </div>
                <div class="section">
                        <a href="hearingaid/index.html">
                                <img alt="補助援助システム" src="include/images/visual02.jpg"><br>
                                <span>補助援助システム</span>
                        </a>
                </div>
        </div>
</div>
<!--/welfare-->

<div id="contact">
        <div class="outline">
                <h2>お問い合わせ先</h2>
                <h3>静岡県乳幼児聴覚支援センター</h3>
                <div class="table">
                        <table>
                                <tr>
                                        <th>住所</th>
                                        <td>〒420-8527<br>静岡市葵区北安東4丁目27番1号 <br class="sp">静岡県立総合病院内 <br class="sp">先端医学棟5階 <br class="sp">静岡県乳幼児聴覚支援センター</td>
                                </tr>
                                <tr>
                                        <th>電話</th>
                                        <td><a href="tel:054-247-6111" class="tel">054-247-6111</a>(内線:8161)</td>
                                </tr>
                                <tr>
                                        <th>FAX</th>
                                        <td>054-247-6171</td>
                                </tr>
                                <tr>
                                        <th>メール<br class="sp">アドレス</th>
                                        <td><a href="&#109;&#97;&#105;&#108;&#116;&#111;&#58;&#103;&#104;&#45;&#110;&#121;&#117;&#121;&#111;&#106;&#105;&#45;&#97;&#115;&#99;&#64;&#105;&#46;&#115;&#104;&#105;&#122;&#117;&#111;&#107;&#97;&#45;&#112;&#104;&#111;&#46;&#106;&#112;">&#103;&#104;&#45;&#110;&#121;&#117;&#121;&#111;&#106;&#105;&#45;&#97;&#115;&#99;&#64;&#105;&#46;&#115;&#104;&#105;&#122;&#117;&#111;&#107;&#97;&#45;&#112;&#104;&#111;&#46;&#106;&#112;</a><br>※但、メールでのお問い合わせは随時行います。</td>
                                </tr>
                        </table>
                </div>
        </div>
</div>
<!--/contact-->

<div id="word">
        <div class="outline">
                <h2>医療機関の方へ</h2>
                <h3>各種様式は下記をご使用ください</h3>
                <ul>
                        <li><a href="https://www.shizuoka-pho.jp/sogo/section/infants-hearing/upload/20141021-093046-7161.doc">新生児聴覚スクリーニング検査申込書【自動ABR用・OAE用】(DOC : 49.5 KB)</a></li>
                        <li><a href="https://www.shizuoka-pho.jp/sogo/section/infants-hearing/upload/20141021-093046-6927.docx">スクリーニング機関から精密検査機関への紹介状(県立総合病院用)(DOCX : 16.54 KB)</a></li>
                        <li><a href="https://www.shizuoka-pho.jp/sogo/section/infants-hearing/upload/20190425-101241-3800.docx">スクリーニング機関から精密検査機関への紹介状(DOCX : 16.49 KB)</a></li>
                        <li><a href="https://shizuoka-pho.sakura.ne.jp/shizuoka-kikoesupport.jp/file/NHSmanual.pdf" class="pdf">新生児聴覚スクリーニング検査と事後対応マニュアル(PDF : 17.12MB KB)</a></li>
                </ul>
        </div>
</div>
<!--/word-->

</div>
<!--/container-->

<div id="footer">
        <div class="f_logo"><a href="https://www.shizuoka-pho.jp/sogo/" target="_blank"><img alt="静岡県立総合病院" src="include/images/f_logo.png"></a></div>
                <div class="f_navi">
                <ul>
                        <li>〒420-8527 静岡市葵区北安東4丁目27番1号</li>
                        <li>TEL:<a href="tel:054-247-6111">054-247-6111</a>(代表) FAX:054-247-6140</li>
                </ul>
                <address>Copyright &copy; Shizuoka Prefectural Hospital Organization.</address>
        </div>
</div>
<!--/footer-->

<p id="pagetop"><span>PAGE TOP</span></p>

</div>
<!--/container-->

<script src="https://code.jquery.com/jquery-3.3.1.min.js"></script>
<script src="include/js/jquery.common.js"></script>
<script src="include/js/jquery.top.js"></script>
<link rel="preload" href="include/css/font.css" as="style" onload="this.rel='stylesheet'">

<script async src="https://www.googletagmanager.com/gtag/js?id=UA-173242748-1"></script>
<script>
        window.dataLayer = window.dataLayer || [];
        function gtag(){dataLayer.push(arguments);}
        gtag('js', new Date());
        gtag('config', 'UA-173242748-1');
</script>

</body>
4 Likes

Very odd. I'm going to disable this site and re-enable the site on 80 so it is at least accessible. It's not a high traffic site but leaving it inaccessible indefinitely is a bad idea. :wink:

Yes, that is the HTML for the site. Ah, and that explains, maybe, the text preview that was occurring. There are links to the hospital web site in the html there.

Ok - the non SSL site is back up. Why I'm not able to get the SSL cert working is a mystery that I'll have to continue to troubleshoot.

1 Like

Is that correct for your site?

The working HTTPS server block doesn't use that.

4 Likes

Actually, I added that later...in my desperation...but everything was working without it. UTF-8 simply displays Japanese Kanji correctly, or should, for all browsers. As opposed to SHIFT-JIS which sometimes looks like unreadable garbage.

I can remove it and give it a shot. :slight_smile: Just a sec

No, that didn't seem to change anything. I tried on a different browser (to avoid being logged out again) and get this (Firefox):

An error occurred during a connection to www.shizuoka-kikoesupport.jp. SSL peer rejected a handshake message for unacceptable content.

Error code: SSL_ERROR_ILLEGAL_PARAMETER_ALERT

Will revert to the site on 80

1 Like

The extremely simple config (for 80) is: (Note - I am disabling this config when I try to use the SSL config)

server {
	listen 80 default_server;
	listen [::]:80 default_server;

	# SSL configuration
	#
	# listen 443 ssl default_server;
	# listen [::]:443 ssl default_server;
	#
	# Note: You should disable gzip for SSL traffic.
	# See: https://bugs.debian.org/773332
	#
	# Read up on ssl_ciphers to ensure a secure configuration.
	# See: https://bugs.debian.org/765782
	#
	# Self signed certs generated by the ssl-cert package
	# Don't use them in a production server!
	#
	# include snippets/snakeoil.conf;

	root /var/www/html;

	# Add index.php to the list if you are using PHP
	index index.html index.php index.htm index.nginx-debian.html;

	server_name _;

	location / {
		# First attempt to serve request as file, then
		# as directory, then fall back to displaying a 404.
		try_files $uri $uri/ =404;
	}

OK, I don't know how I missed this:

NGINX:

APACHE:

curl -Iik https://www.shizuokapho.eshizuoka.jp/
HTTP/1.1 404 Not found
Date: Sun, 10 Jul 2022 08:31:13 GMT
Server: Apache
Set-Cookie: id=245aa518672e9ad802d878a3cb36f56c; path=/
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/html; charset=UTF-8

Something is in front of your server.

4 Likes

Ah, yes...that is a page that is linked on the website. If you look at the site now (it's up on 80), it is a jump to a different site when clicking on any of those links under the slider at the top of the page. They look like this:
Screen Shot 2022-07-10 at 17.35.03

Sorry, it is late here (actually very early), and I got the names crossed.

I don't understand why you are having to touch that "default_server" file:

That should always remain and catch any/all names that are not matched by any server block.

5 Likes

Thanks again for your help here. And sorry to keep you up.

I just have been disabling it when I enable the SSL site. The problem is, if I enable the SSL config it makes the entire site inaccessible. I guess, if the SSL site was working it wouldn't hurt to leave the default on....although if my html root were empty then I would need to redirect, right?

That default should never be hit.
If it is, then something is wrong with the names.
Try changing lines like:

To single lines, like:
server_name www.screen.shizuoka-kikoesupport.jp;

5 Likes

I'm confused...the screen site (www.screen.shizuoka-kikoesupport.jp) is working fine. Do you mean that maybe the way it is configured is interfering with other configs?

You are adding and removing more than you are saying...
So, I can't be 100% certain about anything.
I can say that having to remove a "default" file is an indication of a more serious problem; As that file should never be matched.

5 Likes