Post a reply

Before posting, please read how to report bug or request support effectively.

Bug reports without an attached log file are usually useless.

Options
Add an Attachment

If you do not want to add an Attachment to your Post, please leave the Fields blank.

(maximum 10 MB; please compress large files; only common media, archive, text and programming file formats are allowed)

Options

Topic review

FibreTTP

Connecting to a WebDAV server fails with mTLS (client auth)

Connecting to a WebDAV server with a client certificate returns "Connection failed" with error:
Could not read status line: SSL error: tlsv1 alert unknown ca

The upstream server is a FileBrowser Quantum (v2.0.9-beta) instance with a Caddy (v2.11.4) instance in front performing TLS termination, and reverse proxying to FileBrowser. It is hosted on a non-standard HTTPS port.
Caddy is serving a non-publicly trusted certificate, which was trusted in WinSCP when prompted, and of which the root CA was already imported into the trusted root certificate authority store in Windows (for the current user only). The same root CA has created a certificate, and it has been bundled with the private key into a P12 file which is loaded by WinSCP as a client certificate in the site settings.
Attempting to connect to the server will fail with the error shown above, but connecting with Firefox with no server configuration changes does work normally (it prompts to send the client certificate, and everything works).
Disabling mTLS in Caddy, then removing the path to the client certificate in WinSCP makes the connection work.
Details:

  • WinSCP version: 6.6.3 RC
  • Windows version: Windows 11
  • Protocol: WebDAV (TLS)

I have attached a session log, but the server hostname and certificate names are private, so quite a bit is redacted. To me, it looks like the client certificate CN is failing to be matched to something.