Relationships
#2761 Docs: worker-fleets TLS one-liner fails with KeyMismatch on macOS LibreSSL
Opened by stack72 · 9/30/2026
Following content/manual/how-to/worker-fleets/docker.md on macOS (LibreSSL 3.3.6, the system openssl): the documented one-liner
openssl req -x509 -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -keyout key.pem -out cert.pem -days 30 -nodes -subj /CN=localhost -addext subjectAltName=... -addext basicConstraints=CA:FALSE
produces a pair that swamp serve --cert-file/--key-file rejects at startup with: Error: keys may not be consistent: KeyMismatch.
What worked: generate the key separately and sign the certificate from it, with the extensions in a config file (LibreSSL 3.3 has no -ext for inspection either):
openssl ecparam -name prime256v1 -genkey -noout -out ec.pem openssl pkcs8 -topk8 -nocrypt -in ec.pem -out key.pem openssl req -x509 -new -key key.pem -out cert.pem -days 30 -config san.cnf (san.cnf sets subjectAltName and basicConstraints=CA:FALSE under x509_extensions)
Suggest documenting the macOS variant or recommending Homebrew OpenSSL 3.
Closed
No activity in this phase yet.
stack72 commented 10/1/2026, 6:02:20 AM
Fixed in swamp-club PR #1274 (https://github.com/swamp-club/swamp-club/pull/1274, merged 8cb2788). Root cause: LibreSSL 3.3.6 writes the EC key and cert with explicit curve parameters instead of the named curve, so the pair no longer matches byte-for-byte and serve reports KeyMismatch. Adding '-pkeyopt ec_param_enc:named_curve' to the existing one-liner fixes it. Applied to how-to/worker-fleets/docker.md, worker-fleets/kubernetes.md and set-up-tls-for-swamp-serve.md, with a note naming the error. Verified on /usr/bin/openssl (LibreSSL) and Homebrew OpenSSL 3: swamp serve started and answered HTTPS for every page's command.
Sign in to post a ripple.