# Snapshot repository certificate error with Oracle Cloud S3

**URL:** <https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461>\
**Category:** CrateDB\
**Created:** [April 24, 2023, 2:33pm UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461 "2023-04-24T14:33:38Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![iames](https://avatars.discourse-cdn.com/v4/letter/i/e99b99/32.png) [@iames](https://community.cratedb.com/u/iames)\
**Post date:** [April 24, 2023, 2:33pm UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/1 "2023-04-24T14:33:39Z")

</div>

Hi all,

I am currently trying to use OCI Object storage for repository in Crate 5.2.3 and I am facing a certificane common name error.

When adding the repository with `CREATE REPOSITORY` sentence I get the following error:

```auto
RepositoryVerificationException[[bemp_dev_s3_repo] Unable to verify the repository, [bemp_dev_s3_repo] is not accessible on master node:
SdkClientException 'Unable to execute HTTP request: Certificate for <bucket-name.namespace.compat.objectstorage.eu-frankfurt-1.oraclecloud.com> doesn't match any of the subject alternative names: [swiftobjectstorage.eu-frankfurt-1.oraclecloud.com]']

```

Looking in the internet I have found tha for OCI Object storage to work the client needs to use SNI [java - How to config Oracle cloud certificate? - Stack Overflow](https://stackoverflow.com/a/55249062)

Does Crate S3 client support SNI?

Best regards,

---

<div class="post-metadata">

**Author:** ![amotl](https://sea2.discourse-cdn.com/flex020/user_avatar/community.cratedb.com/amotl/32/617_2.png) [@amotl](https://community.cratedb.com/u/amotl)\
**Post date:** [April 26, 2023, 4:06pm UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/2 "2023-04-26T16:06:06Z")

</div>

Dear @iames,

thank you for writing in.

> Does Crate S3 client support SNI?

I would not know how it would work otherwise for all the S3 buckets out there, as all the user-specific alias names will probably hit the same server configuration, where virtual hosts are dispatched, well, by their host names, using SNI.

May I ask you to share the specific value of `bucket-name.namespace.compat.objectstorage.eu-frankfurt-1.oraclecloud.com` with us? If you think it’s too sensitive, don’t hesitate to shoot a private message at me. Thanks!

With kind regards,  
Andreas.

---

<div class="post-metadata">

**Author:** ![iames](https://avatars.discourse-cdn.com/v4/letter/i/e99b99/32.png) [@iames](https://community.cratedb.com/u/iames)\
**Post date:** [April 27, 2023, 6:37am UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/4 "2023-04-27T06:37:29Z")

</div>

I am sending that information via private message since namespace is unique for the tenant, used for other services and cannot be changed. Thank you.

---

<div class="post-metadata">

**Author:** ![amotl](https://sea2.discourse-cdn.com/flex020/user_avatar/community.cratedb.com/amotl/32/617_2.png) [@amotl](https://community.cratedb.com/u/amotl)\
**Post date:** [April 27, 2023, 1:46pm UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/5 "2023-04-27T13:46:54Z")

</div>

Hi @iames.

Thank you. I am responding here with an anonymized variant.

So, the problem is that accessing the HTTP resource on a bucket level fails, because of certificate SAN vs. hostname mismatch error.

```auto
Certificate for <bucket.namespace.compat.objectstorage.eu-frankfurt-1.oraclecloud.com> doesn't match any of the subject alternative names: [swiftobjectstorage.eu-frankfurt-1.oraclecloud.com]

```

However, we discovered that it works on the namespace level, i.e. `namespace.compat.objectstorage.eu-frankfurt-1.oraclecloud.com` does have a valid certificate, because it is the wildcard SSL certificate for `*.compat.objectstorage.eu-frankfurt-1.oraclecloud.com`.

A wildcard SSL certificate typically covers all subdomains of a domain, but it does not cover arbitrary labels or path components in the URL. From this, I am figuring that you would need to acquire a dedicated SSL certificate for accessing the resource on the bucket level. Oracle’s Cloud Console should offer an opportunity for that.

Please let us know if this helps, or if you think some other parts are co-responsible for the problem.

With kind regards,  
Andreas.

---

<div class="post-metadata">

**Author:** ![iames](https://avatars.discourse-cdn.com/v4/letter/i/e99b99/32.png) [@iames](https://community.cratedb.com/u/iames)\
**Post date:** [May 3, 2023, 10:12am UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/6 "2023-05-03T10:12:14Z")

</div>

Thank you Andreas.

I have been reading Oracle Object Storage documentation more carefully and in the [S3 compatibility section](https://docs.oracle.com/en-us/iaas/Content/Object/Tasks/s3compatibleapi.htm#usingAPI) in " **Modifying your application**" the fourth item says:

1. Use path-based access in your application. Virtual host-style access (accessing a bucket as `{bucketnamespace}.compat.objectstorage.{region}.oraclecloud.com`) is not supported.

I think this is the problem. I am not an expert in S3, but is Crate accessing using ‘virtual host-style’? Is there any way to change this behavior?

Best regards,

---

<div class="post-metadata">

**Author:** ![amotl](https://sea2.discourse-cdn.com/flex020/user_avatar/community.cratedb.com/amotl/32/617_2.png) [@amotl](https://community.cratedb.com/u/amotl)\
**Post date:** [May 22, 2023, 2:59pm UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/7 "2023-05-22T14:59:36Z")

</div>

Hi again,

apologies for the delayed response. I’ve just created a corresponding report on the issue tracker at [`CREATE REPOSITORY`: Compatibility with Oracle Cloud S3 · Issue #14177 · crate/crate · GitHub](https://github.com/crate/crate/issues/14177).

If you are on GitHub, you may want to subscribe on this issue, in order to get notified about any progress. Other than this, we will also respond to this discussion.

Thanks again for the report!

With kind regards,  
Andreas.

---

<div class="post-metadata">

**Author:** ![iames](https://avatars.discourse-cdn.com/v4/letter/i/e99b99/32.png) [@iames](https://community.cratedb.com/u/iames)\
**Post date:** [December 13, 2023, 10:09am UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/8 "2023-12-13T10:09:49Z")

</div>

I have been working on a solution for this and I have finally modified Crate code to include a new param ‘use\_path\_style\_access’ in the S3 repository definition. This parameter forces the call to `enablePathStyleAccess()` in the `AmazonS3ClientBuilder`.

Tested with Oracle Cloud and it works as expected.

Is quite a simple change, what is the best way to contribute this change? Can I upload a diff file here?

---

<div class="post-metadata">

**Author:** ![hernanc](https://sea2.discourse-cdn.com/flex020/user_avatar/community.cratedb.com/hernanc/32/676_2.png) [@hernanc](https://community.cratedb.com/u/hernanc)\
**Post date:** [December 13, 2023, 10:26am UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/9 "2023-12-13T10:26:35Z")

</div>

Thank you for your efforts, the best would be if you could raise a pull request for review in the crate/crate repo, please take a look at the  
[contributing guide](https://github.com/crate/crate/blob/master/CONTRIBUTING.rst).

---

<div class="post-metadata">

**Author:** ![iames](https://avatars.discourse-cdn.com/v4/letter/i/e99b99/32.png) [@iames](https://community.cratedb.com/u/iames)\
**Post date:** [December 19, 2023, 4:16pm UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/10 "2023-12-19T16:16:05Z")

</div>

I signed the CLA (ICLA) some days ago and I haven’t received any new notification. Do I have permission to create a new PR? Do I need to wait more? I know we are approaching complicated dates…

---

<div class="post-metadata">

**Author:** ![hernanc](https://sea2.discourse-cdn.com/flex020/user_avatar/community.cratedb.com/hernanc/32/676_2.png) [@hernanc](https://community.cratedb.com/u/hernanc)\
**Post date:** [December 20, 2023, 8:26am UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/11 "2023-12-20T08:26:17Z")

</div>

Hi, apologies for the delay on this, I just checked internally and confirmed we got your signed ICLA, feel free to go ahead raising the PR.

---

<div class="post-metadata">

**Author:** ![iames](https://avatars.discourse-cdn.com/v4/letter/i/e99b99/32.png) [@iames](https://community.cratedb.com/u/iames)\
**Post date:** [December 20, 2023, 11:43am UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/12 "2023-12-20T11:43:20Z")

</div>

I have tried to upload a new branch to Crate repository but permission denied. Am I missing something?

---

<div class="post-metadata">

**Author:** ![proddata](https://sea2.discourse-cdn.com/flex020/user_avatar/community.cratedb.com/proddata/32/1379_2.png) [@proddata](https://community.cratedb.com/u/proddata)\
**Post date:** [December 20, 2023, 11:58am UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/13 "2023-12-20T11:58:50Z")

</div>

You can’t directly commit a branch to the crate repository. You need to fork the repository and make your changes there in a commit. Then you can create a pull request to merge the changes into the crate repository.

---

<div class="post-metadata">

**Author:** ![iames](https://avatars.discourse-cdn.com/v4/letter/i/e99b99/32.png) [@iames](https://community.cratedb.com/u/iames)\
**Post date:** [December 20, 2023, 4:45pm UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/14 "2023-12-20T16:45:11Z")

</div>

I have finally managed to create de PR [#15222](https://github.com/crate/crate/pull/15222), I hope everything is correct. Sorry for my ignorance.

---

<div class="post-metadata">

**Author:** ![Baur](https://sea2.discourse-cdn.com/flex020/user_avatar/community.cratedb.com/baur/32/284_2.png) [@Baur](https://community.cratedb.com/u/Baur)\
**Post date:** [January 23, 2024, 5:17pm UTC](https://community.cratedb.com/t/snapshot-repository-certificate-error-with-oracle-cloud-s3/1461/15 "2024-01-23T17:17:27Z")

</div>

Thanks for your efforts. PR has been merged and will be available in CrateDB 5.7.0

Crossposting for the record: [`CREATE REPOSITORY`: Compatibility with Oracle Cloud S3 · Issue #14177 · crate/crate · GitHub](https://github.com/crate/crate/issues/14177#issuecomment-1906547438)
