HTTP & TLS Troubleshooting — Challenge
Take a failing HTTPS request apart layer by layer: DNS, TCP, TLS, HTTP — and know which one broke.
- Time
- 25 min
- Level
- Intermediate
- Objectives
- 4 objectives
- Cost
- Free
Where this fits in the platform
This lab adds
- The ability to diagnose a broken certificate before it is public
Which lets you
—
Before you start
You will need
- curl
- openssl
- dig
- nc
You do not need these already — the lab environment below provides them.
You will be able to
- Inspect a certificate chain and its expiry from the command line
- Separate a TLS failure from an HTTP failure
- Read `curl -v` output as a sequence of layers
Cost — Free
— uses public endpoints and a local container.
The goal#
Achieve the same outcome as HTTP & TLS Troubleshooting, from an empty starting point, without the steps.
"The site is down." It returns a certificate error in one browser, works in another, and curl fails with something different again.
Each of those is a different layer, and the fix depends entirely on which one.
Hands-on environment
Run this lab in a real terminal, free and in your browser. The environment is temporary and yours alone — break it as much as you like.
Start the challengeOpens in Killercoda, in a new tab — keep this page open for the steps.
This is the guided lab's environment — the same machine, with its walkthrough on the left. Work from the task above and leave those steps alone until you are done, or you are reading the answers.
Run it on your own machine
Run this lab on your own machine. One command starts the environment, with everything the lab needs already installed:
You will need:
- bash
- curl
git clone https://github.com/EgyKode/EgyKode-lab.git
cd EgyKode-lab
./egykode start
./egykode shellYou need Docker and Git installed. Everything else runs inside the environment. The first start downloads it and takes a few minutes; later starts are seconds.
Not sure what you already have? Run: npm run doctor — it checks and changes nothing.
Anything you tick here is your own record. EgyKode cannot see inside that terminal, so the success criteria stay self-assessed even when the environment checks your work for you.
What must be true when you are done
Step 1 of 3
What must be true when you are done#
- You can print a site's certificate subject, issuer and expiry without a browser.
- You can state which layer failed for three different broken URLs.
- You can explain what
SSL_ERROR_SYSCALLandcertificate verify failedeach imply. - You can prove a port is reachable independently of whether TLS succeeds.
Rules#
- Do not open the guided lab until you are finished, or until the same problem has held you up for 20 minutes.
- Documentation is allowed and encouraged.
- Verify every criterion with a command whose output you can read.
If you get stuck#
- What did you expect, exactly?
- What happened instead — the error text, not a paraphrase?
- Which layer is that error from?
- What is the smallest command that proves the layer below is fine?
You are done when
0 of 4
The concept behind it
Phase complete · 02 The application, in containers
You can now: The application runs locally in production-shaped containers, behind a reverse proxy, over TLS.
Next phase
Lab 13 of 59 on the project path