# How To Solve Elm make HTTPS Certificate Problem

**URL:** <https://discourse.elm-lang.org/t/how-to-solve-elm-make-https-certificate-problem/2546>\
**Category:** Learn\
**Created:** [November 17, 2018, 9:18pm UTC](https://discourse.elm-lang.org/t/how-to-solve-elm-make-https-certificate-problem/2546 "2018-11-17T21:18:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Viir](https://yyz1.discourse-cdn.com/flex035/user_avatar/discourse.elm-lang.org/viir/32/4103_2.png) [@Viir](https://discourse.elm-lang.org/u/Viir)\
**Post date:** [November 17, 2018, 9:18pm UTC](https://discourse.elm-lang.org/t/how-to-solve-elm-make-https-certificate-problem/2546/1 "2018-11-17T21:18:18Z")

</div>

I am trying to use elm make on windows azure here. When I run it like this:

```auto
elm make StringBuilderWebApp.elm

```

It fails with following output:

```auto
-- HTTP PROBLEM ----------------------------------------------------------------

The following HTTP request failed:

    <https://package.elm-lang.org/all-packages>

Here is the error message I was able to extract:

    HttpExceptionRequest Request { host = "package.elm-lang.o
rg" port = 443
    secure = True requestHeaders =
    [("User-Agent","elm/0.19.0"),("Accept-Encoding","gzip")] path =
    "/all-packages" queryString = "" method = "GET" proxy = Nothing rawBody =
    False redirectCount = 10 responseTimeout = ResponseTimeoutDefault
    requestVersion = HTTP/1.1 } (InternalException (HandshakeFailed
    (Error_Protocol ("certificate has unknown CA",True,UnknownCa))))

```

How can I fix this?

Do I need to supply a certificate to use elm make?

I ran this test to see if connecting to [package.elm-lang.org](http://package.elm-lang.org) works over HTTP:

```auto
D:\home\test-elm>curl http://package.elm-lang.org
  % Total % Received % Xferd Average Speed Time Time Time Current
                                 Dload Upload Total Spent Left Speed
100 194 100 194 0 0 1031 0 --:--:-- --:--:-- --:--:-- 1127<html>
<head><title>301 Moved Permanently</title></head>
<body bgcolor="white">
<center><h1>301 Moved Permanently</h1></center>
<hr><center>nginx/1.10.3 (Ubuntu)</center>
</body>
</html>

```

---

<div class="post-metadata">

**Author:** ![andys8](https://yyz1.discourse-cdn.com/flex035/user_avatar/discourse.elm-lang.org/andys8/32/280_2.png) [@andys8](https://discourse.elm-lang.org/u/andys8)\
**Post date:** [November 17, 2018, 10:51pm UTC](https://discourse.elm-lang.org/t/how-to-solve-elm-make-https-certificate-problem/2546/2 "2018-11-17T22:51:21Z")

</div>

The messages says the system doesn’t know the CA. Certificate is issued by Let’s encrypt and the chain looks fine. Do you have issues with other websites using let’s encrypt?

[https://www.ssllabs.com/ssltest/analyze.html?d=package.elm-lang.org](https://www.ssllabs.com/ssltest/analyze.html?d=package.elm-lang.org)

---

<div class="post-metadata">

**Author:** ![razze](https://yyz1.discourse-cdn.com/flex035/user_avatar/discourse.elm-lang.org/razze/32/1650_2.png) [@razze](https://discourse.elm-lang.org/u/razze)\
**Post date:** [November 17, 2018, 11:12pm UTC](https://discourse.elm-lang.org/t/how-to-solve-elm-make-https-certificate-problem/2546/3 "2018-11-17T23:12:46Z")

</div>

The response says permanently moved, not sure but I heard, that the page side seems to be blocked from countries like russia etc. maybe that’s affecting you too?

---

<div class="post-metadata">

**Author:** ![malaire](https://avatars.discourse-cdn.com/v4/letter/m/b782af/32.png) [@malaire](https://discourse.elm-lang.org/u/malaire)\
**Post date:** [November 17, 2018, 11:19pm UTC](https://discourse.elm-lang.org/t/how-to-solve-elm-make-https-certificate-problem/2546/4 "2018-11-17T23:19:52Z")

</div>

> [@razze](#):
>
> The response says permanently moved …

That isn’t a problem, it’s just normal HTTP redirection:  
“[http://package.elm-lang.org](http://package.elm-lang.org)” is redirecting to “[https://package.elm-lang.org/](https://package.elm-lang.org/)”

```
malaire@box:~$ curl -I http://package.elm-lang.org
HTTP/1.1 301 Moved Permanently
Server: nginx/1.10.3 (Ubuntu)
Date: Sat, 17 Nov 2018 23:16:49 GMT
Content-Type: text/html
Content-Length: 194
Connection: keep-alive
Location: https://package.elm-lang.org/

```

---

<div class="post-metadata">

**Author:** ![Viir](https://yyz1.discourse-cdn.com/flex035/user_avatar/discourse.elm-lang.org/viir/32/4103_2.png) [@Viir](https://discourse.elm-lang.org/u/Viir)\
**Post date:** [November 18, 2018, 7:22am UTC](https://discourse.elm-lang.org/t/how-to-solve-elm-make-https-certificate-problem/2546/5 "2018-11-18T07:22:52Z")

</div>

> [@andys8](#):
>
> The messages says the system doesn’t know the CA. Certificate is issued by Let’s encrypt and the chain looks fine. Do you have issues with other websites using let’s encrypt?
> 
> [SSL Server Test: package.elm-lang.org (Powered by Qualys SSL Labs)](https://www.ssllabs.com/ssltest/analyze.html?d=package.elm-lang.org)

Thank you @andys8 for the pointer. After writing the first post, I tried to get it working by installing certificates on the system, so cannot answer your question for the past setup anymore. Looks like I got it working by installing a certificate. I downloaded the certificate from [package.elm-lang.org](http://package.elm-lang.org) and added it as a `Public Certificate` to the Azure app.

I used the export UI of the chrome browser to get a `.cer` file for a certificate on the path displayed in the chrome browser (I took the `DST Root CA X3` from the root)

 ![Screenshot Of Interface To Download Certificate For Elm Make](https://canada1.discourse-cdn.com/flex035/uploads/elm_lang/original/2X/1/1cd1b03736d9b022dabb3bcf9a23c7eba06d2032.png)

The import of this file went without error messages.

 ![Screenshot Of Interface To Install Certificate For Elm Make In Azure App](https://canada1.discourse-cdn.com/flex035/uploads/elm_lang/original/2X/0/0f7b3bb74431d5fd416d3c4bb1a670f0742cf6aa.png)

But at first, the elm make command still displayed the `certificate has unknown CA` error.

Yesterday, it was too late to continue investigating, and now after coming back it works, elm make produces the output file. I don’t know what happened in the meantime, maybe the host system was restarted.

While setting the certificate up, I also found this guide helpful to check if the certificate was loaded: [Azure App Services: How to determine if the client certificate is loaded | Microsoft Learn](https://blogs.msdn.microsoft.com/karansingh/2017/03/15/azure-app-services-how-to-determine-if-the-client-certificate-is-loaded/)

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex035/uploads/elm_lang/original/1X/50a05e53677a2c3b47776d7abd0f113eb50193a1.png) [@system](https://discourse.elm-lang.org/u/system)\
**Post date:** [November 28, 2018, 7:22am UTC](https://discourse.elm-lang.org/t/how-to-solve-elm-make-https-certificate-problem/2546/6 "2018-11-28T07:22:55Z")

</div>

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.
