AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Shared Pooler Certificate Chain Fails Strict TLS Verification: Intermediate CA Missing Key Usage

The Supabase hosted shared transaction pooler at aws-1-eu-west-2.pooler.supabase.com:6543 presents a certificate chain where the intermediate CA ('Supabase Intermediate 2021 CA') lacks a Key Usage extension. Python 3.13 enables VERIFY_X509_STRICT by default in ssl.create_default_context(), causing certificate verification to fail with error 92 at depth 1. This prevents database connections using asyncpg 0.31.0 and OpenSSL 3.6.3, even when the correct root CA is trusted. The issue is reproducible without credentials and occurs before authentication.

highConfidence 92%PythonAffected VPython 3.13.5Affected Vasyncpg 0.31.0Affected VOpenSSL 3.6.3

Origin Analysis

The intermediate CA certificate, issued by 'Supabase Root 2021 CA', has Basic Constraints CA:TRUE but is missing the required Key Usage extension. Python 3.13's default SSL context enables VERIFY_X509_STRICT, which enforces RFC 5280 conformance and rejects CAs without a Key Usage extension.
1. Download prod-ca-2021.crt from the Supabase dashboard. 2. Ensure OpenSSL 3.6.3 and Python 3.13 with asyncpg 0.31.0 are installed. 3. Run: openssl s_client -starttls postgres -connect aws-1-eu-west-2.pooler.supabase.com:6543 -servername aws-1-eu-west-2.pooler.supabase.com -verify_hostname aws-1-eu-west-2.pooler.supabase.com -CAfile ./prod-ca-2021.crt -no-CApath -no-CAstore -x509_strict -trusted_first -partial_chain -purpose sslserver -auth_level 2 -min_protocol TLSv1.2 -verify_return_error -showcerts </dev/null 4. Observe verification error 92 at depth 1: 'CA cert does not include key usage extension'. 5. Alternatively, use Python asyncpg with default SSL context to reproduce CERTIFICATE_VERIFY_FAILED.

Fixing Code Block

Edge Case Audit

Disabling VERIFY_X509_STRICT relaxes multiple certificate-conformance checks, not just the missing Key Usage condition. It may mask other certificate issues (e.g., malformed extensions, invalid policies). This workaround should be temporary; the proper fix is for Supabase to reissue the intermediate CA with appropriate Key Usage. Rollback: remove the verify_flags modification to restore strict verification; if the server certificate is later fixed, this code remains harmless but unnecessary.

Ecosystem Topology