- Home
- Skills
- APIs & Backend
- Repair TLS, Certificate & Trust Failures
More screenshots
Works with the AI tools you already use
Repair TLS, Certificate & Trust Failures
Repair TLS, Certificate & Trust Failures is a bounded ToolForge Labs workflow.
$8.99
Repair TLS, Certificate & Trust Failures
Example session with this skill installed
Our Go service is failing to connect to a legacy internal API with 'x509: certificate signed by unknown authority'. Here is the connection snippet and the internal CA cert.
- Read your context and instructions
- Compiled the repair tls certificate
I have analyzed the Go connection logic and the provided CA certificate. The issue stems from the service using the system default trust store rather than a custom pool containing your internal CA, and a mismatch in the expected SNI for the legacy endpoint.
TLS Trust and SNI Repair
| Component | Status | Recommendation |
|---|---|---|
| Root CA | Valid | Found in provided snippet; must be injected into a custom x509.CertPool. |
| Chain | Incomplete | The legacy API is not sending intermediates; the client must explicitly trust the internal Root. |
| Hostname/SNI | Mismatch | The connection attempt uses the IP; the certificate requires the internal FQDN via ServerName. |
| Verification | Active | Keep InsecureSkipVerify: false to maintain security posture. |
Proposed Go Repair
// Create a custom cert pool for the internal CA
certPool, _ := x509.SystemCertPool()
if certPool == nil {
certPool = x509.NewCertPool()
}
// Append the internal CA provided in your logs
if ok := certPool.AppendCertsFromPEM(internalCACert); !ok {
log.Fatal("failed to append internal CA cert")
}
// Configure Transport with specific ServerName for SNI
tlsConfig := &tls.Config{
RootCAs: certPool,
ServerName: "legacy-api.internal.local", // Explicitly set for SNI match
InsecureSkipVerify: false, // Security preserved
MinVersion: tls.VersionTLS12,
}
client := &http.Client{
Transport: &http.Transport{TLSClientConfig: tlsConfig},
}
Deterministic Test Case
func TestLegacyConnection(t *testing.T) {
// Local test server simulating the legacy CA chain
server := httptest.NewUnstartedServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.T) {
w.WriteHeader(http.StatusOK)
}))
server.TLS = &tls.Config{Certificates: []tls.Certificate{internalCert}}
server.StartTLS()
defer server.Close()
// Test logic ensures the handshake completes without disabling verification
}
Next steps
- Verify the
internal-api.internal.localFQDN matches the SAN field in your certificate. - Deploy the updated
tls.Configto your staging environment to confirm the custom pool loads correctly. - Ensure the
internalCACertPEM is injected via a secure environment variable or secret mount.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Repair TLS, Certificate & Trust Failures is a bounded ToolForge Labs workflow. Repair TLS and certificate failures across chain building, hostname/SNI checks, trust stores, client certificates, rotation overlap, protocol compatibility, and environment drift. Works from repositories or partial handshake/config evidence. Produces secure bounded repairs and tests without disabling certificate or hostname verification. It works from a full repository or partial evidence such as snippets, logs, configuration, traces, tickets, and architecture notes. The skill preserves existing product and security policy, separates verified facts from assumptions, avoids invented execution claims, and produces concrete repair or review steps with focused deterministic validation or traceable evidence.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 21 days ago
- Passed all security checks, Safe to install