Connecting to a WebDAV server fails with mTLS (client auth)
Connecting to a WebDAV server with a client certificate returns "Connection failed" with error:
The upstream server is a FileBrowser Quantum (v2.0.9-beta) instance with a Caddy (v2.11.4) instance in front performing TLS termination, and reverse proxying to FileBrowser. It is hosted on a non-standard HTTPS port.
Caddy is serving a non-publicly trusted certificate, which was trusted in WinSCP when prompted, and of which the root CA was already imported into the trusted root certificate authority store in Windows (for the current user only). The same root CA has created a certificate, and it has been bundled with the private key into a P12 file which is loaded by WinSCP as a client certificate in the site settings.
Attempting to connect to the server will fail with the error shown above, but connecting with Firefox with no server configuration changes does work normally (it prompts to send the client certificate, and everything works).
Disabling mTLS in Caddy, then removing the path to the client certificate in WinSCP makes the connection work.
Details:
Could not read status line: SSL error: tlsv1 alert unknown ca
Caddy is serving a non-publicly trusted certificate, which was trusted in WinSCP when prompted, and of which the root CA was already imported into the trusted root certificate authority store in Windows (for the current user only). The same root CA has created a certificate, and it has been bundled with the private key into a P12 file which is loaded by WinSCP as a client certificate in the site settings.
Attempting to connect to the server will fail with the error shown above, but connecting with Firefox with no server configuration changes does work normally (it prompts to send the client certificate, and everything works).
Disabling mTLS in Caddy, then removing the path to the client certificate in WinSCP makes the connection work.
Details:
- WinSCP version: 6.6.3 RC
- Windows version: Windows 11
- Protocol: WebDAV (TLS)