######################################################################## # PROVA BRUTA - DICT GetEntry via relay Cecresa, sem certificado cliente # Origem: ip-192-168-40-10 / 192.168.40.10 (monetarie-rsfn-egress-homolog) # Data UTC: 2026-06-21T17:40:26Z # Alvo: https://dict-h.pi.rsfn.net.br:16522/api/v2/entries/62188010000150 # Captura: AWS SSM Run Command, sem SSH e sem bastion # Leitura: DNS resolveu para 172.16.70.51, TCP abriu, BACEN solicitou # certificado cliente mTLS e encerrou o handshake sem certificado vĂ¡lido. ######################################################################## $ curl -v -H "Accept: application/xml" -H "Content-Type: application/xml" -H "PI-Requesting-Participant: 46026562" -H "PI-PayerId: 32189410835" https://dict-h.pi.rsfn.net.br:16522/api/v2/entries/62188010000150 % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0* Host dict-h.pi.rsfn.net.br:16522 was resolved. * IPv6: (none) * IPv4: 172.16.70.51 * Trying 172.16.70.51:16522... * Connected to dict-h.pi.rsfn.net.br (172.16.70.51) port 16522 * ALPN: curl offers h2,http/1.1 } [5 bytes data] * TLSv1.3 (OUT), TLS handshake, Client hello (1): } [512 bytes data] * CAfile: /etc/ssl/certs/ca-certificates.crt * CApath: /etc/ssl/certs { [5 bytes data] * TLSv1.3 (IN), TLS handshake, Server hello (2): { [63 bytes data] * TLSv1.2 (IN), TLS handshake, Certificate (11): { [3520 bytes data] * TLSv1.2 (OUT), TLS alert, unknown CA (560): } [2 bytes data] * SSL certificate problem: unable to get local issuer certificate 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 * Closing connection curl: (60) SSL certificate problem: unable to get local issuer certificate More details here: https://curl.se/docs/sslcerts.html curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it. To learn more about this situation and how to fix it, please visit the web page mentioned above. $ curl -k -v -H "Accept: application/xml" -H "Content-Type: application/xml" -H "PI-Requesting-Participant: 46026562" -H "PI-PayerId: 32189410835" https://dict-h.pi.rsfn.net.br:16522/api/v2/entries/62188010000150 % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0* Host dict-h.pi.rsfn.net.br:16522 was resolved. * IPv6: (none) * IPv4: 172.16.70.51 * Trying 172.16.70.51:16522... * Connected to dict-h.pi.rsfn.net.br (172.16.70.51) port 16522 * ALPN: curl offers h2,http/1.1 } [5 bytes data] * TLSv1.3 (OUT), TLS handshake, Client hello (1): } [512 bytes data] * TLSv1.3 (IN), TLS handshake, Server hello (2): { [63 bytes data] * TLSv1.2 (IN), TLS handshake, Certificate (11): { [3520 bytes data] * TLSv1.2 (IN), TLS handshake, Server key exchange (12): { [333 bytes data] * TLSv1.2 (IN), TLS handshake, Request CERT (13): { [36 bytes data] * TLSv1.2 (IN), TLS handshake, Server finished (14): { [4 bytes data] * TLSv1.2 (OUT), TLS handshake, Certificate (11): } [7 bytes data] * TLSv1.2 (OUT), TLS handshake, Client key exchange (16): } [70 bytes data] * TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1): } [1 bytes data] * TLSv1.2 (OUT), TLS handshake, Finished (20): } [16 bytes data] * TLSv1.2 (IN), TLS alert, handshake failure (552): { [2 bytes data] * OpenSSL/3.0.13: error:0A000410:SSL routines::sslv3 alert handshake failure 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 * Closing connection curl: (35) OpenSSL/3.0.13: error:0A000410:SSL routines::sslv3 alert handshake failure