More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Repair TLS, Certificate & Trust Failures

    1

    Repair TLS, Certificate & Trust Failures is a bounded ToolForge Labs workflow.

    $8.99

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    Repair TLS, Certificate & Trust Failures

    Repair TLS, Certificate & Trust Failures

    Example session with this skill installed

    Our Go service is failing to connect to a legacy internal API with 'x509: certificate signed by unknown authority'. Here is the connection snippet and the internal CA cert.

    • Read your context and instructions
    • Compiled the repair tls certificate

    I have analyzed the Go connection logic and the provided CA certificate. The issue stems from the service using the system default trust store rather than a custom pool containing your internal CA, and a mismatch in the expected SNI for the legacy endpoint.

    TLS Trust and SNI Repair

    ComponentStatusRecommendation
    Root CAValidFound in provided snippet; must be injected into a custom x509.CertPool.
    ChainIncompleteThe legacy API is not sending intermediates; the client must explicitly trust the internal Root.
    Hostname/SNIMismatchThe connection attempt uses the IP; the certificate requires the internal FQDN via ServerName.
    VerificationActiveKeep InsecureSkipVerify: false to maintain security posture.

    Proposed Go Repair

    // Create a custom cert pool for the internal CA
    certPool, _ := x509.SystemCertPool()
    if certPool == nil {
        certPool = x509.NewCertPool()
    }
    
    // Append the internal CA provided in your logs
    if ok := certPool.AppendCertsFromPEM(internalCACert); !ok {
        log.Fatal("failed to append internal CA cert")
    }
    
    // Configure Transport with specific ServerName for SNI
    tlsConfig := &tls.Config{
        RootCAs:            certPool,
        ServerName:         "legacy-api.internal.local", // Explicitly set for SNI match
        InsecureSkipVerify: false,                     // Security preserved
        MinVersion:         tls.VersionTLS12,
    }
    
    client := &http.Client{
        Transport: &http.Transport{TLSClientConfig: tlsConfig},
    }
    

    Deterministic Test Case

    func TestLegacyConnection(t *testing.T) {
        // Local test server simulating the legacy CA chain
        server := httptest.NewUnstartedServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.T) {
            w.WriteHeader(http.StatusOK)
        }))
        server.TLS = &tls.Config{Certificates: []tls.Certificate{internalCert}}
        server.StartTLS()
        defer server.Close()
    
        // Test logic ensures the handshake completes without disabling verification
    }
    

    Next steps

    1. Verify the internal-api.internal.local FQDN matches the SAN field in your certificate.
    2. Deploy the updated tls.Config to your staging environment to confirm the custom pool loads correctly.
    3. Ensure the internalCACert PEM is injected via a secure environment variable or secret mount.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Resolve 'certificate signed by unknown authority' errors securely.Fix mTLS handshake failures between microservices.Correct SNI and hostname validation mismatches in client code.Audit and repair incomplete certificate chains in legacy integrations.

    About this skill

    Repair TLS, Certificate & Trust Failures is a bounded ToolForge Labs workflow. Repair TLS and certificate failures across chain building, hostname/SNI checks, trust stores, client certificates, rotation overlap, protocol compatibility, and environment drift. Works from repositories or partial handshake/config evidence. Produces secure bounded repairs and tests without disabling certificate or hostname verification. It works from a full repository or partial evidence such as snippets, logs, configuration, traces, tickets, and architecture notes. The skill preserves existing product and security policy, separates verified facts from assumptions, avoids invented execution claims, and produces concrete repair or review steps with focused deterministic validation or traceable evidence.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 21 days ago

    • Passed all security checks, Safe to install

    Listed21 days ago

    What's inside

    Frequently Asked Questions