Files
cpp-httplib/docs-src/pages/en/cookbook/c18-ssl-errors.md
yhirose bef278e0d2 Fix docs pages that no longer match the code
Samples that did not compile or run as shown:
- res.user_data.get<T>() inside a generic lambda needs the `template`
  keyword; use explicit parameter types (tour 09, cookbook s15).
- listen() on a Unix domain socket fails with port 0 (tour 09, s22).
- "*.dev.local" is not a NO_PROXY pattern (c16).
- ssl_backend_error() holds a verify result, not an ERR_get_error()
  value, after a verification failure; decode each with the matching
  OpenSSL function (c18).
- The content provider's `length` is everything that remains, so the
  sample read the whole file in one call (s05).

Statements corrected:
- Client keep-alive is off by default; c14 is rewritten around
  set_keep_alive(true).
- Mounted files are looked up before GET handlers (tour 04, s04).
- Params keep insertion order, and to_string(Error::Connection) reads
  "Could not establish connection" (tour 02).
- A chunked provider ends with sink.done(), and post_routing_handler
  runs before the response is sent (tour 09).
- Timeouts surface as Error::Read; Error::Timeout comes from the stream
  API (c17). The max timeout cuts off the wait for the response only
  (c13). The progress callback needs Content-Length (c11).
- Encoding selection follows q-values, then Brotli, gzip, Zstd (s08),
  and the client compresses with the first of those it was built with
  (c15).
- stop() cuts a provider-driven response short (s19); a rejected
  content_reader already gets 400 or 413 (s07); user_data values must be
  copyable (s12); Client accepts a client certificate too (t04);
  on_message() is the fallback for every unhandled event and 204/403/404
  end reconnection (e04); the pong timeout takes two to three intervals
  and ends a waiting read() (w02).

In the LLM app tutorial, an uncaught exception does not crash the
server, so say what it does instead. Drop the server and client timeout
settings whose stated purpose, covering inference and download time,
they do not serve: those timeouts bound a single socket wait. Update
the llama.cpp server layout in chapter 7.
2026-10-08 20:39:13 -04:00

2.2 KiB

title, order, status
title order status
C18. Handle SSL Errors 18 draft

When an HTTPS request fails, res.error() returns values like Error::SSLConnection or Error::SSLServerVerification. Sometimes that's not enough to pinpoint the cause. That's where Result::ssl_error() and Result::ssl_backend_error() help.

Get the SSL error details

httplib::Client cli("https://api.example.com");
auto res = cli.Get("/");

if (!res) {
  auto err = res.error();
  std::cerr << "error: " << httplib::to_string(err) << std::endl;

  if (err == httplib::Error::SSLConnection ||
      err == httplib::Error::SSLServerVerification) {
    std::cerr << "ssl_error: " << res.ssl_error() << std::endl;
    std::cerr << "ssl_backend_error: " << res.ssl_backend_error() << std::endl;
  }
}

ssl_error() is a backend-independent TLS error category: an httplib::tls::ErrorCode cast to int. ssl_backend_error() gives you the backend's own error value. With OpenSSL that is ERR_get_error() when the handshake failed, and the verify result (X509_V_ERR_*) when certificate verification failed.

Format OpenSSL errors as strings

When you have a value from ssl_backend_error(), pass it to the OpenSSL function that matches the kind of failure to get a readable message.

#include <openssl/err.h>
#include <openssl/x509.h>

if (res.error() == httplib::Error::SSLConnection) {
  char buf[256];
  ERR_error_string_n(res.ssl_backend_error(), buf, sizeof(buf));
  std::cerr << "openssl: " << buf << std::endl;
} else if (res.error() == httplib::Error::SSLServerVerification ||
           res.error() == httplib::Error::SSLServerHostnameVerification) {
  auto code = static_cast<long>(res.ssl_backend_error());
  std::cerr << "openssl: " << X509_verify_cert_error_string(code) << std::endl;
}

Common causes

Symptom Usual suspect
SSLServerVerification CA certificate path isn't configured, or the cert is self-signed
SSLServerHostnameVerification The cert's CN/SAN doesn't match the host
SSLConnection TLS version mismatch, no shared cipher suite

To change certificate verification settings, see T02. Control SSL certificate verification.