# HTTP Request unsafe legacy renegotiation

**URL:** <https://discourse.nodered.org/t/http-request-unsafe-legacy-renegotiation/73309>\
**Category:** General\
**Tags:** http-request, security\
**Created:** [6 January 2023 19:16 UTC](https://discourse.nodered.org/t/http-request-unsafe-legacy-renegotiation/73309 "2023-01-06T19:16:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![HarryPottar](https://avatars.discourse-cdn.com/v4/letter/h/bb73d2/32.png) [@HarryPottar](https://discourse.nodered.org/u/HarryPottar)\
**Post date:** [6 January 2023 19:16 UTC](https://discourse.nodered.org/t/http-request-unsafe-legacy-renegotiation/73309/1 "2023-01-06T19:16:54Z")

</div>

Hi,

We're moving our flows from Node-Red V2.06 to V3.02

We have a subflow that connects to an older (Legacy) systems API. Under Node-Red V2 the http-request node works fine. Under V3 we get an error

```auto
RequestError: write EPROTO 886996BB0D7F0000:error:0A000152:SSL routines:final_renegotiate:unsafe legacy renegotiation disabled:../deps/openssl/openssl/ssl/statem/extensions.c:907:

```

Is there an option we can use through "ALPN Protocol" to Allow Legacy Renegotiation, or some other method. i.e. setting SSL\_OP\_ALLOW\_UNSAFE\_LEGACY\_RENEGOTIATION to true?

Ideally we could just allow it on this Subflow connector for known legacy API but leave the others alone.

Thanks In Advanced  
Harry

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [6 January 2023 20:48 UTC](https://discourse.nodered.org/t/http-request-unsafe-legacy-renegotiation/73309/2 "2023-01-06T20:48:45Z")

</div>

This looks to be something people are experiencing under certain conditions on nodejs v18+

You could try running node-red under node v16LTS

---

<div class="post-metadata">

**Author:** ![lqt123l](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lqt123l/32/76356_2.png) [@lqt123l](https://discourse.nodered.org/u/lqt123l)\
**Post date:** [19 February 2023 01:17 UTC](https://discourse.nodered.org/t/http-request-unsafe-legacy-renegotiation/73309/3 "2023-02-19T01:17:03Z")

</div>

For node18, set secureOptions like below:

```auto
import * as https from 'https';
import * as crypto from "crypto";

axios.create({
      baseURL: baseURL,
      httpsAgent: new https.Agent({
        secureOptions: crypto.constants.SSL_OP_LEGACY_SERVER_CONNECT,
      })
    });

```

---

<div class="post-metadata">

**Author:** ![HarryPottar](https://avatars.discourse-cdn.com/v4/letter/h/bb73d2/32.png) [@HarryPottar](https://discourse.nodered.org/u/HarryPottar)\
**Post date:** [19 February 2023 13:54 UTC](https://discourse.nodered.org/t/http-request-unsafe-legacy-renegotiation/73309/4 "2023-02-19T13:54:54Z")

</div>

Thanks this is very helpful and certainly a workaround.

Luckily, we where able to convince their IT of the security issue and the server SSL was updated and fixes our issue.

But once again, thank you so much for the workaround.  
Harry

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [19 February 2023 16:39 UTC](https://discourse.nodered.org/t/http-request-unsafe-legacy-renegotiation/73309/5 "2023-02-19T16:39:21Z")

</div>

> [@HarryPottar](#):
>
> Luckily, we where able to convince their IT of the security issue and the server SSL was updated and fixes our issue.

Always the best first approach - fix the security problem rather than work around it! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [5 March 2023 16:39 UTC](https://discourse.nodered.org/t/http-request-unsafe-legacy-renegotiation/73309/6 "2023-03-05T16:39:35Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
