# RequestError: EPROTO wrong signature type:ssl/t1\_lib.c

**URL:** <https://discourse.nodered.org/t/requesterror-eproto-wrong-signature-type-ssl-t1-lib-c/73863>\
**Category:** General\
**Tags:** http-request, home-assistant\
**Created:** [18 January 2023 13:17 UTC](https://discourse.nodered.org/t/requesterror-eproto-wrong-signature-type-ssl-t1-lib-c/73863 "2023-01-18T13:17:50Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dries](https://avatars.discourse-cdn.com/v4/letter/d/8e8cbc/32.png) [@Dries](https://discourse.nodered.org/u/Dries)\
**Post date:** [18 January 2023 13:17 UTC](https://discourse.nodered.org/t/requesterror-eproto-wrong-signature-type-ssl-t1-lib-c/73863/1 "2023-01-18T13:17:50Z")

</div>

Hi,

I tried to set up my first HTTP Request Node.

The assignment is (or should be) rather simple. It should GET this URL.  
[https://klanten.bizzsms.nl/api/send?username=SOMEUSER&code=TEST&text=TESTNODERED&phonenumbers=0032123456&sendertitle=TITLE](https://klanten.bizzsms.nl/api/send?username=SOMEUSER&code=TEST&text=TESTNODERED&phonenumbers=0032123456&sendertitle=TITLE)

If I paste this URL in my browser, I get a valid response. Obviously the URL above is modified to hide some username details, but even then, the response is a valid one "0|1|user not found". Feel free to try it.

However, if I try this via the HTTP request node with the settings below, it just doesn't work:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/7/b/7bd8f65996918e8827b9c5b71521d9bcc7840617.png)

I am received the following error message:  
RequestError: write EPROTO 3801D2F14F7F0000:error:0A000172:SSL routines:tls12\_check\_peer\_sigalg:wrong signature type:ssl/t1\_lib.c:1572:

So what am I doing wrong?

---

<div class="post-metadata">

**Author:** ![mudwalker](https://avatars.discourse-cdn.com/v4/letter/m/47e85d/32.png) [@mudwalker](https://discourse.nodered.org/u/mudwalker)\
**Post date:** [18 January 2023 13:35 UTC](https://discourse.nodered.org/t/requesterror-eproto-wrong-signature-type-ssl-t1-lib-c/73863/2 "2023-01-18T13:35:30Z")

</div>

I can only report that this appears to work for me both in Browser and Node-RED

```auto
0|1|user not found

```

Version of Node-RED  
Version of Node.js  
OS and version?

See from CMD/Terminal prompt after node-red-stop|node-red-start

```auto
Start Node-RED
 
Once Node-RED has started, point a browser at http://XX.XX.XX.XX:1880
On Pi Node-RED works better with the Firefox or Chrome browser
 
Use node-red-stop to stop Node-RED
Use node-red-start to start Node-RED again
Use node-red-log to view the recent log output
Use sudo systemctl enable nodered.service to autostart Node-RED at every boot
Use sudo systemctl disable nodered.service to disable autostart on boot
 
To find more nodes and example flows - go to http://flows.nodered.org
 
Starting as a systemd service.
18 Jan 13:32:12 - [info]
Welcome to Node-RED
===================
18 Jan 13:32:12 - [info] Node-RED version: v3.0.2
18 Jan 13:32:12 - [info] Node.js version: v16.19.0
18 Jan 13:32:12 - [info] Linux 5.15.0-58-generic x64 LE
18 Jan 13:32:12 - [info] Loading palette nodes

```

This will help people help you. (Beyond this, my knowledge ends....)

EDIT: Are you sure URL is correct in HTTP request?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [18 January 2023 13:46 UTC](https://discourse.nodered.org/t/requesterror-eproto-wrong-signature-type-ssl-t1-lib-c/73863/3 "2023-01-18T13:46:02Z")

</div>

> [@Dries](#):
>
> I am received the following error message:  
> RequestError: write EPROTO 3801D2F14F7F0000:error:0A000172:SSL routines:tls12\_check\_peer\_sigalg:wrong signature type:ssl/t1\_lib.c:1572:

Did you remember to put `https` on the front of the URL in node-red?

If it isn't that, it would appear to be a TLS signature incompatibility - are you using an old version of node.js?

---

<div class="post-metadata">

**Author:** ![Dries](https://avatars.discourse-cdn.com/v4/letter/d/8e8cbc/32.png) [@Dries](https://discourse.nodered.org/u/Dries)\
**Post date:** [18 January 2023 15:09 UTC](https://discourse.nodered.org/t/requesterror-eproto-wrong-signature-type-ssl-t1-lib-c/73863/4 "2023-01-18T15:09:32Z")

</div>

Hi both,

Thank you for your help. Node-Red is installed via Home Assistant as an add-on.

I currently run this:

```auto
Welcome to Node-RED
===================
18 Jan 16:00:23 - [info] Node-RED version: v3.0.2
18 Jan 16:00:23 - [info] Node.js version: v18.12.1
18 Jan 16:00:23 - [info] Linux 5.15.80 x64 LE

Add-on: Node-RED
 Flow-based programming for the Internet of Things
-----------------------------------------------------------
 Add-on version: 14.0.1
 You are running the latest version of this add-on.
 System: Home Assistant OS 9.4 (amd64 / qemux86-64)
 Home Assistant Core: 2023.1.5
 Home Assistant Supervisor: 2022.12.1
-----------------------------------------------------------

```

I'm pretty sure the URL is correct.  
If I change HTTPS to HTTP, it is working fine (it returns 0|1|user not found). But it should work with HTTPS as well...

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/a/4/a4f5122bd05d83a2d4b5130c7e00a53382f0c5d1.png)

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [18 January 2023 18:11 UTC](https://discourse.nodered.org/t/requesterror-eproto-wrong-signature-type-ssl-t1-lib-c/73863/5 "2023-01-18T18:11:19Z")

</div>

> [@Dries](#):
>
> `Home Assistant`

:sigh: . .

---

<div class="post-metadata">

**Author:** ![Dries](https://avatars.discourse-cdn.com/v4/letter/d/8e8cbc/32.png) [@Dries](https://discourse.nodered.org/u/Dries)\
**Post date:** [18 January 2023 20:15 UTC](https://discourse.nodered.org/t/requesterror-eproto-wrong-signature-type-ssl-t1-lib-c/73863/6 "2023-01-18T20:15:27Z")

</div>

> [@TotallyInformation](#):
>
> :sigh: . .

No sure how to read your response. Is that a "_sigh, why are you using Home Assistant?_"? Or am I missing something here?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [18 January 2023 21:03 UTC](https://discourse.nodered.org/t/requesterror-eproto-wrong-signature-type-ssl-t1-lib-c/73863/7 "2023-01-18T21:03:18Z")

</div>

Sorry, it's just that as soon as HA is involved, things seem to get complicated.

All I can really suggest is trying a stand-alone install of Node-RED and see if it works there.

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [19 January 2023 00:12 UTC](https://discourse.nodered.org/t/requesterror-eproto-wrong-signature-type-ssl-t1-lib-c/73863/8 "2023-01-19T00:12:30Z")

</div>

> I am received the following error message:  
> RequestError: write EPROTO 3801D2F14F7F0000:error:0A000172:SSL routines:tls12\_check\_peer\_sigalg:wrong signature type:ssl/t1\_lib.c:1572:  
> So what am I doing wrong?

You are not doing anything wrong. They use TLS1.2 instead of 1.3 and somehow the cipher they use is not compatible with 1.2 I suspect. Browsers tend to ignore these issues. Depending on your local setup, it might/might not work.

If you try this on the commandline, you will receive the same error:

```auto
echo | openssl s_client -servername klanten.bizzsms.nl -connect klanten.bizzsms.nl:443
...
verify return:1
58703D987F000000:error:0A000172:SSL routines:tls12_check_peer_sigalg:wrong signature type:ssl/t1_lib.c:1572:

```

Forcing the tls version (as the browser indicated):

```auto
echo | openssl s_client -tls1_2 -servername klanten.bizzsms.nl -connect klanten.bizzsms.nl:443

```

No errors.

I don't think there is an option available to add ciphers/force the tls version to the http request node, instead you could use an exec node that performs a curl, like:

```auto
curl --tlsv1.2 "https://klanten.bizzsms.nl/api/send?username=SOMEUSER&code=TEST&text=TESTNODERED&phonenumbers=0032123456&sendertitle=TITLE"

```

Output:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/b/a/ba3e2469e2196be94977071594f7ecb9b88552a4.png)

I think there is a way to set this up in a openssl config file, but never tried this.

---

<div class="post-metadata">

**Author:** ![Dries](https://avatars.discourse-cdn.com/v4/letter/d/8e8cbc/32.png) [@Dries](https://discourse.nodered.org/u/Dries)\
**Post date:** [19 January 2023 20:20 UTC](https://discourse.nodered.org/t/requesterror-eproto-wrong-signature-type-ssl-t1-lib-c/73863/9 "2023-01-19T20:20:14Z")

</div>

> [@bakman2](#):
>
> I don't think there is an option available to add ciphers/force the tls version to the http request node, instead you could use an exec node that performs a curl, like:
> 
> ```auto
> curl --tlsv1.2 "https://klanten.bizzsms.nl/api/send?username=SOMEUSER&code=TEST&text=TESTNODERED&phonenumbers=0032123456&sendertitle=TITLE"
> 
> ```

That works! Thanks for the workaround!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [2 February 2023 20:20 UTC](https://discourse.nodered.org/t/requesterror-eproto-wrong-signature-type-ssl-t1-lib-c/73863/10 "2023-02-02T20:20:58Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
