401, 403 and Certificates
Goal
You narrow the layer of an authentication problem using 401 and 403 as clues, and confirm certificate failure modes directly from files.
Why it matters
A 401 is an authentication failure — "I cannot verify who you are." A 403 is an authorization failure — "I know who you are, but you are not allowed to do this." This distinction splits the investigation in opposite directions. For a 401 you look at the credentials themselves, and for a 403 you look at permission settings without needing to touch the credentials. If you lump them together as a "permission error," you dig in the wrong place for hours.
And within 401 too, the reasons split. A missing token, an unknown token, and an expired token are all 401, but the response differs, so you must look at the reason string in the response body as well.
On the certificate side you check two things. Expiry is read from notAfter, and here you must also print the current time — because quite often a perfectly good certificate looks expired on a client with a wrong clock. For a name mismatch you should look at the SAN, not the CN, but the certificates in this lab have only a CN, so you check with the subject name.
Four tokens — (헤더 없음) (no header), expired-token-2025, readonly-token, fde-prod-2026
Two certificates — /opt/data/tls/expired.pem, /opt/data/tls/wronghost.pem (the name you were trying to connect to is api.customer.example)
Steps
- Run
/opt/app/authapi.pyso that127.0.0.1:8003/publicreturns 200. - Write the status code of calling
/privatewithout an Authorization header to/root/auth/no_token.txt. - Save the response body of the call made with
expired-token-2025to/privateinto/root/auth/expired_reason.txt. - Write the status code of the call made with
readonly-tokento/privateinto/root/auth/readonly.txt. - Write the status code of the call made with
fde-prod-2026to/privateinto/root/auth/ok.txt. - Save the expiry date of
expired.pemto/root/auth/cert_expiry.txt. - Save the subject name of
wronghost.pemto/root/auth/cert_cn.txt. - In
/root/auth/report.md, summarize the difference between 401 and 403 and the problem of the two certificates. It must contain the two status codes,api.other.example, and the expiry year.
Notes
curl -s -o /dev/null -w '%{http_code}' -H 'Authorization: Bearer 토큰' http://127.0.0.1:8003/private(the placeholder is the token)openssl x509 -in 파일 -noout -enddate -subject(the placeholder is the file)- To compare with the current time, also print
date -u. - Common mistake 1: saving only the status code in step 3. You need the reason for the 401.
- Common mistake 2: sending just the token without
Bearerin the header format. Then the token is not recognized at all.
Start the authentication gateway
Run /opt/app/authapi.py so that 127.0.0.1:8003/public returns 200.
When you run /opt/app/authapi.py, it waits on 127.0.0.1:8003. /public is open without authentication.
Call without a token
Write the status code of calling /private without an Authorization header to /root/auth/no_token.txt.
Record which code comes back when you call /private without an Authorization header.
Obtain the expiry reason
Save the response body of the call made with expired-token-2025 to /private into /root/auth/expired_reason.txt.
An expired token is also a 401. The status code alone does not tell you the reason, so save the response body.
Confirm insufficient permissions
Write the status code of the call made with readonly-token to /private into /root/auth/readonly.txt.
readonly-token passes identity verification. See how the code that comes back differs from a 401.
Confirm normal authentication
Write the status code of the call made with fde-prod-2026 to /private into /root/auth/ok.txt.
With the fde-prod-2026 token it passes. Record the success code.
Check the expired certificate
Save the expiry date of expired.pem to /root/auth/cert_expiry.txt.
You can see a certificate's validity period with openssl x509. Save when the expiry date is.
Check the certificate with a different name
Save the subject name of wronghost.pem to /root/auth/cert_cn.txt.
Extract the subject name of wronghost.pem. It differs from the name you were trying to connect to.
Write the diagnostic report
In /root/auth/report.md, summarize the difference between 401 and 403 and the problem of the two certificates. It must contain the two status codes, api.other.example, and the expiry year.
Summarize what each of 401 and 403 is a failure of, and what the problem of each of the two certificates is.