# Sync errors with both Dropbox and OneDrive (self signed certificate)

**URL:** <https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269>\
**Category:** Support\
**Created:** [1 May 2019 13:57 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269 "2019-05-01T13:57:53Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![decavolt](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/decavolt/32/876_2.png) [@decavolt](https://discourse.joplinapp.org/u/decavolt)\
**Post date:** [1 May 2019 13:57 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/1 "2019-05-01T13:57:53Z")

</div>

With a new install of Joplin on MacOS (Mojave 10.14.4), I continually get sync errors and sync never completes. The same issue exists with both Dropbox and OneDrive with the same error message:

> failed, reason: self signed certificate in certificate chain

Any suggestions?

---

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [1 May 2019 14:11 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/2 "2019-05-01T14:11:09Z")

</div>

Can you provide more context for the log (the lines before and after the one you’ve posted)?

---

<div class="post-metadata">

**Author:** ![decavolt](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/decavolt/32/876_2.png) [@decavolt](https://discourse.joplinapp.org/u/decavolt)\
**Post date:** [1 May 2019 14:44 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/3 "2019-05-01T14:44:34Z")

</div>

Sure, here’s what I’m seeing:

**DropBox:**

```auto
created remote items: 1.
Completed: 01/05/2019 09:30
Last error: FetchError: request to https://content.dropboxapi.com/2/files/upload failed, reason: self signed certificate in certificate chain

```

**OneDrive** - this is after I have successfully signed in to my Office365 account via Joplin:

```auto
Could not login to OneDrive. Please try again.
request to https://login.microsoftonline.com/common/oauth2/v2.0/token failed, reason: self signed certificate in certificate chain

```

There is another very long URL after the OneDrive error above, but since I’m new to this forum it’ll only let me add 2 links to a post.

---

<div class="post-metadata">

**Author:** ![tessus](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/tessus/32/13_2.png) [@tessus](https://discourse.joplinapp.org/u/tessus)\
**Post date:** [1 May 2019 17:45 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/4 "2019-05-01T17:45:07Z")

</div>

You should use codeblocks to post log or any data that is code. In that case links are not counted as links either. I’ll change your post and you can see what I mean.

---

<div class="post-metadata">

**Author:** ![tessus](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/tessus/32/13_2.png) [@tessus](https://discourse.joplinapp.org/u/tessus)\
**Post date:** [1 May 2019 17:49 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/5 "2019-05-01T17:49:09Z")

</div>

When I come to think of it. How can there be a self-signed cert in the chain when you connect to a valid TLS cert?  
Are you using some sort of a proxy, or trying to use mitm-proxy or Charles Proxy? Something doesn’t smell right here.

---

<div class="post-metadata">

**Author:** ![heviiguy](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/heviiguy/32/841_2.png) [@heviiguy](https://discourse.joplinapp.org/u/heviiguy)\
**Post date:** [1 May 2019 17:50 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/6 "2019-05-01T17:50:07Z")

</div>

Seems that this is yet another case where self-signed certificates are causing issues. Fortunately, the desktop app allows this to be resolved by providing a choice to avoid TLS errors as well as a choice of where the app should reference the certs. Unfortunately, the same can’t be said of the Android app…

[Android client: Network connection error](https://discourse.joplinapp.org/t/android-client-network-connection-error/2049/12)

---

<div class="post-metadata">

**Author:** ![tessus](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/tessus/32/13_2.png) [@tessus](https://discourse.joplinapp.org/u/tessus)\
**Post date:** [1 May 2019 17:58 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/7 "2019-05-01T17:58:14Z")

</div>

> [@heviiguy](#):
>
> Seems that this is yet another case where self-signed certificates are causing issues

If you connect to Google or Dropbox where is there a self-signed certificate? Also, did you see that the OP was talking about the desktop version?

---

<div class="post-metadata">

**Author:** ![decavolt](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/decavolt/32/876_2.png) [@decavolt](https://discourse.joplinapp.org/u/decavolt)\
**Post date:** [1 May 2019 18:02 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/8 "2019-05-01T18:02:35Z")

</div>

> [@tessus](#):
>
> You should use codeblocks...

Good to know. Thank you 🙂

---

<div class="post-metadata">

**Author:** ![decavolt](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/decavolt/32/876_2.png) [@decavolt](https://discourse.joplinapp.org/u/decavolt)\
**Post date:** [1 May 2019 18:04 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/9 "2019-05-01T18:04:28Z")

</div>

> [@tessus](#):
>
> Are you using some sort of a proxy, or trying to use mitm-proxy or Charles Proxy? Something doesn’t smell right here.

No proxy. I'll try from my home network later tonight to see if I get a different result.

---

<div class="post-metadata">

**Author:** ![decavolt](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/decavolt/32/876_2.png) [@decavolt](https://discourse.joplinapp.org/u/decavolt)\
**Post date:** [2 May 2019 13:58 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/10 "2019-05-02T13:58:29Z")

</div>

I tried again on my home network, and confirmed that I’m getting the same errors with both Dropbox and OneDrive.

---

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [2 May 2019 14:13 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/11 "2019-05-02T14:13:48Z")

</div>

In the config screen, in your Nextcloud or WebDAV settings, do you have something set for “Custom TLS certificates”?

---

<div class="post-metadata">

**Author:** ![decavolt](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/decavolt/32/876_2.png) [@decavolt](https://discourse.joplinapp.org/u/decavolt)\
**Post date:** [2 May 2019 15:38 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/12 "2019-05-02T15:38:25Z")

</div>

No, the Nextcloud and WebDAV settings were blank.  
But, in WebDAV, I enabled "Ignore TLS certificate errors", and then changed the target back to Dropbox. And that worked - it's syncing properly now.

I'd suggest moving that "Ignore TLS..." option outside of the targets, since it's currently only visible under WebDAV and Nextcloud.

Anyway, that was a huge help - thank you! 😃

 ![07%20AM](https://canada1.discourse-cdn.com/flex028/uploads/cozic/original/1X/226cb836059743784da284d17f453b1df49bedbe.png)

---

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [2 May 2019 23:02 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/13 "2019-05-02T23:02:43Z")

</div>

This is quite strange though. If it’s not a bug in Joplin then there’s something not right with your internet connection. If someone was MITM your connection, it would give this kind of error, but even if it’s not malicious there’s something weird going on, so you probably should try to find the root of the problem.

---

<div class="post-metadata">

**Author:** ![tessus](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/tessus/32/13_2.png) [@tessus](https://discourse.joplinapp.org/u/tessus)\
**Post date:** [2 May 2019 23:28 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/14 "2019-05-02T23:28:40Z")

</div>

I agree. For me this looks like a a MITM attack.

---

<div class="post-metadata">

**Author:** ![decavolt](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/decavolt/32/876_2.png) [@decavolt](https://discourse.joplinapp.org/u/decavolt)\
**Post date:** [3 May 2019 13:52 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/15 "2019-05-03T13:52:35Z")

</div>

This is all happening on a work-issued laptop that has some anti-virus network software running. So maybe that is causing this to act like a MITM issue, since it happens on both my home and office networks.  
I’ll try installing Joplin on another machine and see if it behaves the same way on both networks.

---

<div class="post-metadata">

**Author:** ![Marcos](https://avatars.discourse-cdn.com/v4/letter/m/9de0a6/32.png) [@Marcos](https://discourse.joplinapp.org/u/Marcos)\
**Post date:** [23 August 2019 17:43 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/16 "2019-08-23T17:43:53Z")

</div>

I’d like to report that the same thing is happening to me. I tried to synchronize the Joplin installed on my USB stick with Dropbox and the same error message appeared.  
The error also repeats when I try to check for Joplin version updates.  
Joplin is only synchronizing with Dropbox if I enable the “Ignore TLS certificate errors” dialog in WebDAV. However, Joplin still gives the same error when I try to check for updates…  
I use Joplin on my USB stick when I’m at work…

---

<div class="post-metadata">

**Author:** ![Spiff](https://avatars.discourse-cdn.com/v4/letter/s/b782af/32.png) [@Spiff](https://discourse.joplinapp.org/u/Spiff)\
**Post date:** [23 August 2019 19:19 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/17 "2019-08-23T19:19:26Z")

</div>

This is common on business-issued machines. Lots of places use a proxy (like a Barracuda or various cisco appliances) to intercept https traffic so they have visibility into employee usage and/or for data exfil protection, etc… For brevity in the reply, see, e.g., [https://www.grc.com/fingerprints.htm](https://www.grc.com/fingerprints.htm) . If you examine your browser or OS certificate store, you will most likely find a custom root cert so your browsers don’t throw an error on every https connection.

You can also test this yourself with openssl. You can see the whole certificate chain with this, think of it like tracert for certs.

```
$ echo -n | openssl s_client -connect content.dropboxapi.com:443
CONNECTED(00000004)
depth=2 C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert High Assurance EV Root CA
verify return:1
depth=1 C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert SHA2 High Assurance Server CA
verify return:1
depth=0 C = US, ST = California, L = San Francisco, O = "Dropbox, Inc", OU = Dropbox Ops, CN = content.dropboxapi.com
verify return:1
---
Certificate chain
 0 s:C = US, ST = California, L = San Francisco, O = "Dropbox, Inc", OU = Dropbox Ops, CN = content.dropboxapi.com
   i:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert SHA2 High Assurance Server CA
 1 s:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert SHA2 High Assurance Server CA
   i:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert High Assurance EV Root CA
---
Server certificate
-----BEGIN CERTIFICATE-----
..snipped..
-----END CERTIFICATE-----
subject=C = US, ST = California, L = San Francisco, O = "Dropbox, Inc", OU = Dropbox Ops, CN = content.dropboxapi.com

issuer=C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert SHA2 High Assurance Server CA

---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: RSA-PSS
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 3943 bytes and written 419 bytes
Verification: OK
---
New, TLSv1.2, Cipher is ECDHE-RSA-CHACHA20-POLY1305
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
..snipped..
---
DONE

```

or

```
$ echo -n | openssl s_client -connect joplinapp.org:443
CONNECTED(00000004)
depth=2 O = Digital Signature Trust Co., CN = DST Root CA X3
verify return:1
depth=1 C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
verify return:1
depth=0 CN = joplinapp.org
verify return:1
---
Certificate chain
 0 s:CN = joplinapp.org
   i:C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
 1 s:C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
   i:O = Digital Signature Trust Co., CN = DST Root CA X3
---
Server certificate
-----BEGIN CERTIFICATE-----
..snipped..
-----END CERTIFICATE-----
subject=CN = joplinapp.org

issuer=C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3

---
No client certificate CA names sent
Peer signing digest: SHA512
Peer signature type: RSA
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 3206 bytes and written 418 bytes
Verification: OK
---
New, TLSv1.2, Cipher is ECDHE-RSA-AES128-GCM-SHA256
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    ..snipped..
---
DONE
```

---

<div class="post-metadata">

**Author:** ![mrtoddf](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@mrtoddf](https://discourse.joplinapp.org/u/mrtoddf)\
**Post date:** [24 January 2020 19:49 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/18 "2020-01-24T19:49:00Z")

</div>

I submit that there is a bug somewhere. I have seen multiple posts on this where the solution in the end is to "ignore TLS certificate errors". And yes this works for me as well, but this is not ideal when using my device off of the corporate network. A bug was submitted through github, but they were directed to post here.

> <https://github.com/laurent22/joplin/issues/2023>
>
> \## Environment
> 
> Joplin version: 1.0.170
> Platform: Windows
> OS specifcs: Windo…ws 10 1903
> 
> 
> \## Steps To Reproduce
> 
> 1. Setup a WebDAV server using certificate signed by a private CA
> 2. On a windows machine, in Joplin, set Custom TLS Certificates to a path containing the private CA certificate
> 3. Check Synchronization Configuration
> 
> 
> Describe what you expected to happen:
> unable to verify the first certificate (Code UNABLE\_TO\_VERIFY\_LEAF\_SIGNATURE)
> 
> 
> \## Comments
> 
> Another post reporting the same issue is \[here\](https://discourse.joplinapp.org/t/desktop-cant-get-custom-tls-certificates-to-work/2365)
> 
> Furthermore, the private CA was installed on my Windows system certificate store, but Joplin seems to ignore that.
> 
> It seems that the problem is with using \`syswide-ca\` module to resolve certificates, which, from my perspective of view, does not mention any Windows support in its main page and documentations.

> [@Desktop: Can't get "Custom TLS Certificates" to work](https://discourse.joplinapp.org/t/desktop-cant-get-custom-tls-certificates-to-work/2365):
>
> I am syncing Joplin with a private NextCloud instance. The NextCloud server has a TLS certificate signed by a private CA. I have installed the certificate for the private CA in Firefox and can connect to NextCloud over HTTPS from Firefox without problem (both Windows and Linux). I have installed the certificate for the private CA in Thunderbird and can sync from Thunderbird to CALDAV and CARDDAV over HTTPS without problem (both Windows and Linux). I have installed the certificate for the pri…

While some users might be having issues due to Mitm or self signed certs out of ignorance. I am definitely MiTM my connection due to enterprise requirements and I am familiar with this process.

To recreate:  
I open my webdav url in a browser and export both crt, cer certificates in the chain to a location on my computer, Then convert them to public pem files, because that is what it appears to handle. (yes i know that they are technically the same file contents, but I used openssl just to be certain)

In the settings I then pointed "Custom TLS certificates" to the location on my computer c:\certs that houses both certificates. I have also tried using a comma separated list to the pem files, but to no avail.

It appears that it is just not applying the "Custom TLS certificates" setting.

---

<div class="post-metadata">

**Author:** ![zoltix](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/zoltix/32/2091_2.png) [@zoltix](https://discourse.joplinapp.org/u/zoltix)\
**Post date:** [31 January 2020 10:29 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/19 "2020-01-31T10:29:05Z")

</div>

I have same problem than you with Joplin.  
In my company, we have ssl inspection, it’s a “Men in the middle” which been installed by “checkpoint company.” To avoid this problem, we have to add our “CA certificate” in our Linux (openssl) or our Windows (automatically by GPO).  
For example, for git, we have to export certificate(certmgr.msc) and import them in local repository of openssl.  
This link will be more clear to explain you how it works for it.  
[https://mattferderer.com/fix-git-self-signed-certificate-in-certificate-chain-on-windows](https://mattferderer.com/fix-git-self-signed-certificate-in-certificate-chain-on-windows)

For my Windows(certmgr.msc), the CA root certificate is already present in my local session(Trusted root Certification Authorities -\> Certificates). But not considered by Joplin.

But for Joplin, I don’t know how to add “Trusted Root certificate” under Linux and Windows.

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![bedwardly-down](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/bedwardly-down/32/3236_2.png) [@bedwardly-down](https://discourse.joplinapp.org/u/bedwardly-down)\
**Post date:** [31 January 2020 10:49 UTC](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269/20 "2020-01-31T10:49:57Z")

</div>

![2020-01-31-044752_1920x1080_scrot](https://canada1.discourse-cdn.com/flex028/uploads/cozic/original/2X/4/430a843f98b8dadcdcc108b946d59ed4d45ce4a0.png)

Would ‘Custom TLS certificates’ under the Advanced Options section of the Synchronization tab be what you’re looking for?

[Next page](https://discourse.joplinapp.org/t/sync-errors-with-both-dropbox-and-onedrive-self-signed-certificate/2269.md?page=2)
