TT Lab
Get started
Learn Learning paths Courses

Integration and Deployment

401, 403 and Certificates

Continue in TT Lab

Goal

You narrow the layer of an authentication problem using 401 and 403 as clues, and confirm certificate failure modes directly from files.

Why it matters

A 401 is an authentication failure — "I cannot verify who you are." A 403 is an authorization failure — "I know who you are, but you are not allowed to do this." This distinction splits the investigation in opposite directions. For a 401 you look at the credentials themselves, and for a 403 you look at permission settings without needing to touch the credentials. If you lump them together as a "permission error," you dig in the wrong place for hours.

And within 401 too, the reasons split. A missing token, an unknown token, and an expired token are all 401, but the response differs, so you must look at the reason string in the response body as well.

On the certificate side you check two things. Expiry is read from notAfter, and here you must also print the current time — because quite often a perfectly good certificate looks expired on a client with a wrong clock. For a name mismatch you should look at the SAN, not the CN, but the certificates in this lab have only a CN, so you check with the subject name.

Four tokens — (헤더 없음) (no header), expired-token-2025, readonly-token, fde-prod-2026 Two certificates — /opt/data/tls/expired.pem, /opt/data/tls/wronghost.pem (the name you were trying to connect to is api.customer.example)

Steps

  1. Run /opt/app/authapi.py so that 127.0.0.1:8003/public returns 200.
  2. Write the status code of calling /private without an Authorization header to /root/auth/no_token.txt.
  3. Save the response body of the call made with expired-token-2025 to /private into /root/auth/expired_reason.txt.
  4. Write the status code of the call made with readonly-token to /private into /root/auth/readonly.txt.
  5. Write the status code of the call made with fde-prod-2026 to /private into /root/auth/ok.txt.
  6. Save the expiry date of expired.pem to /root/auth/cert_expiry.txt.
  7. Save the subject name of wronghost.pem to /root/auth/cert_cn.txt.
  8. In /root/auth/report.md, summarize the difference between 401 and 403 and the problem of the two certificates. It must contain the two status codes, api.other.example, and the expiry year.

Notes

Start the authentication gateway

Run /opt/app/authapi.py so that 127.0.0.1:8003/public returns 200.

When you run /opt/app/authapi.py, it waits on 127.0.0.1:8003. /public is open without authentication.

Call without a token

Write the status code of calling /private without an Authorization header to /root/auth/no_token.txt.

Record which code comes back when you call /private without an Authorization header.

Obtain the expiry reason

Save the response body of the call made with expired-token-2025 to /private into /root/auth/expired_reason.txt.

An expired token is also a 401. The status code alone does not tell you the reason, so save the response body.

Confirm insufficient permissions

Write the status code of the call made with readonly-token to /private into /root/auth/readonly.txt.

readonly-token passes identity verification. See how the code that comes back differs from a 401.

Confirm normal authentication

Write the status code of the call made with fde-prod-2026 to /private into /root/auth/ok.txt.

With the fde-prod-2026 token it passes. Record the success code.

Check the expired certificate

Save the expiry date of expired.pem to /root/auth/cert_expiry.txt.

You can see a certificate's validity period with openssl x509. Save when the expiry date is.

Check the certificate with a different name

Save the subject name of wronghost.pem to /root/auth/cert_cn.txt.

Extract the subject name of wronghost.pem. It differs from the name you were trying to connect to.

Write the diagnostic report

In /root/auth/report.md, summarize the difference between 401 and 403 and the problem of the two certificates. It must contain the two status codes, api.other.example, and the expiry year.

Summarize what each of 401 and 403 is a failure of, and what the problem of each of the two certificates is.