# /etc/pki/tls/cert.pem symlink missing in EC2 AMIs? (breaks wget)

**URL:** <https://community.wowza.com/t/etc-pki-tls-cert-pem-symlink-missing-in-ec2-amis-breaks-wget/41434>\
**Category:** Wowza Streaming Engine\
**Created:** [October 16, 2013, 1:38pm UTC](https://community.wowza.com/t/etc-pki-tls-cert-pem-symlink-missing-in-ec2-amis-breaks-wget/41434 "2013-10-16T13:38:30Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andrew\_Leonard](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Andrew\_Leonard](https://community.wowza.com/u/Andrew_Leonard)\
**Post date:** [October 16, 2013, 1:38pm UTC](https://community.wowza.com/t/etc-pki-tls-cert-pem-symlink-missing-in-ec2-amis-breaks-wget/41434/1 "2013-10-16T13:38:30Z")

</div>

In at least instances launched from ami-4aff667a in us-west-2, /etc/pki/tls/cert.pem is missing:

[ec2-user@ip-10-x-y-z tls]$ rpm -V ca-certificates-2010.63-3.7.amzn1.noarch

missing /etc/pki/tls/cert.pem

This breaks “wget” connecting to HTTPS sites, which breaks our initial automated provisioning. Could this get fixed?

Thanks,

Andy

---

<div class="post-metadata">

**Author:** ![Tim\_Dougherty](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/tim_dougherty/32/596_2.png) [@Tim\_Dougherty](https://community.wowza.com/u/Tim_Dougherty)\
**Post date:** [October 16, 2013, 3:57pm UTC](https://community.wowza.com/t/etc-pki-tls-cert-pem-symlink-missing-in-ec2-amis-breaks-wget/41434/2 "2013-10-16T15:57:54Z")

</div>

You may be encountering a recent issue that has developed in EC2.

([From the Pre Built AMI’s launch page](https://www.wowza.com/docs/wowza-streaming-engine-for-amazon-ec2-amis)…)

An update to the EC2 Management Console prevents the Wowza Media Server AMIs from launching properly. The workaround is to specify the default startup package using the **User data** field as part of the AMI launch process. To do this:

In the **Configure Instance Details** step, open the **Advanced Details** section.

In the **User data** field, enter the following user data and then select the **As text** option.

```auto
WZA_startupPackageURL=http://s3.amazonaws.com/wowzamediasystems/com/wowza/startup/default_3.6.0.zip

```

You may replace your startup package (if applicable) using the same approach from your download source.

-Tim

---

<div class="post-metadata">

**Author:** ![Tim\_Dougherty](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/tim_dougherty/32/596_2.png) [@Tim\_Dougherty](https://community.wowza.com/u/Tim_Dougherty)\
**Post date:** [October 17, 2013, 10:44am UTC](https://community.wowza.com/t/etc-pki-tls-cert-pem-symlink-missing-in-ec2-amis-breaks-wget/41434/3 "2013-10-17T10:44:31Z")

</div>

I checked our current and recently replaced AMI’s. The folder **/etc/pki/tls** is certainly present, however, **cert.pem** is evidently not a default file (I didn’t see it). I don’t expect this file missing on your end is the result of a Wowza issue.

-Tim

---

<div class="post-metadata">

**Author:** ![Roger\_Littin1](https://avatars.discourse-cdn.com/v4/letter/r/c89c15/32.png) [@Roger\_Littin1](https://community.wowza.com/u/Roger_Littin1)\
**Post date:** [October 18, 2013, 1:15pm UTC](https://community.wowza.com/t/etc-pki-tls-cert-pem-symlink-missing-in-ec2-amis-breaks-wget/41434/4 "2013-10-18T13:15:27Z")

</div>

Hi Andy,

We have worked out what is happening.

It is actually the EC2 tools supplied by Amazon that are removing the symlink when the ami is created. It looks like they added a script to the tool that removes all \*.pem files when the new image is built.

We have found a workaround and will most likely be raising it as a bug with Amazon but we feel does not warrant a complete rebuild of all AMIs at this stage.

For the current AMIs, the symlink can be reinstated with the following commands.

```auto
cd /etc/pki/tls/
sudo ln -s certs/ca-bundle.crt cert.pem

```

Regards,

Roger.

---

<div class="post-metadata">

**Author:** ![Andrew\_Leonard](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Andrew\_Leonard](https://community.wowza.com/u/Andrew_Leonard)\
**Post date:** [October 17, 2013, 9:30am UTC](https://community.wowza.com/t/etc-pki-tls-cert-pem-symlink-missing-in-ec2-amis-breaks-wget/41434/5 "2013-10-17T09:30:02Z")

</div>

I’m running on a “﻿3.6.2.16 build7566 (October 14, 2013)” AMI (and launching via the EC2 API not the console), so I don’t think that’s related here.

(When I wrote it breaks provisioning, I was talking about the in-house tools we use to manage all of our EC2 instances. Right now, I’m manually fixing this, but I figured it best to report the issue upstream.)

My guess would be that /etc/pki/tls/cert.pem was inadvertently removed prior to bundling when the AMI was built?

Thanks,

Andy

---

<div class="post-metadata">

**Author:** ![Andrew\_Leonard](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Andrew\_Leonard](https://community.wowza.com/u/Andrew_Leonard)\
**Post date:** [October 17, 2013, 10:59am UTC](https://community.wowza.com/t/etc-pki-tls-cert-pem-symlink-missing-in-ec2-amis-breaks-wget/41434/6 "2013-10-17T10:59:46Z")

</div>

Hi Tim,

Thanks for continuing to look into this.

If it’s missing in current and recently replaced AMIs, it most definitely _is_ a Wowza issue: the AMIs as packaged are broken, because SSL client connections cannot validate against the installed CA certificates. That’s been my point all along.

rpm -V reports that it was removed from the RPM as distributed by Amazon:

```auto
[ec2-user@ip-10-x-y-z tls]$ rpm -V ca-certificates-2010.63-3.7.amzn1.noarch
missing /etc/pki/tls/cert.pem

```

It’s also present in the (presumably) upstream Amazon Linux 2013.09 AMI. You can test the difference by doing the following on a Wowza AMI and an Amazon Linux AMI:

Wowza, before /etc/pki/tls/cert.pem is fixed:

```auto
$ wget [url]https://www.google.com/[/url]
--2013-10-17 18:55:23-- [url]https://www.google.com/[/url]
Resolving [url]www.google.com[/url] ([url]www.google.com[/url])... 74.125.20.103, 74.125.20.104, 74.125.20.105, ...
Connecting to [url]www.google.com[/url] ([url]www.google.com)|74.125.20.103|:443[/url]... connected.
ERROR: cannot verify [url]www.google.com's[/url] certificate, issued by ‘/C=US/O=Google Inc/CN=Google Internet Authority G2’:
  Unable to locally verify the issuer's authority.
To connect to [url]www.google.com[/url] insecurely, use `--no-check-certificate'.

```

Amazon Linux, or Wowza with proper /etc/pki/tls/cert.pem:

```auto
$ wget [url]https://www.google.com/[/url]
--2013-10-17 18:57:31-- [url]https://www.google.com/[/url]
Resolving [url]www.google.com[/url] ([url]www.google.com[/url])... 173.194.33.179, 173.194.33.180, 173.194.33.176, ...
Connecting to [url]www.google.com[/url] ([url]www.google.com)|173.194.33.179|:443[/url]... connected.
HTTP request sent, awaiting response... 200 OK
Length: unspecified [text/html]
Saving to: ‘index.html’
    [<=>] 18,626 --.-K/s in 0.006s
2013-10-17 18:57:31 (2.86 MB/s) - ‘index.html’ saved [18626]

```

Thanks,

Andy

---

<div class="post-metadata">

**Author:** ![Andrew\_Leonard](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Andrew\_Leonard](https://community.wowza.com/u/Andrew_Leonard)\
**Post date:** [October 18, 2013, 9:21am UTC](https://community.wowza.com/t/etc-pki-tls-cert-pem-symlink-missing-in-ec2-amis-breaks-wget/41434/7 "2013-10-18T09:21:18Z")

</div>

Thanks for the follow through, much appreciated. Looking forward to when you will be able to spin your workaround into a new AMI.

-Andy
