error in SSLv2/v3 read client hello A
Jean-Christophe Baptiste <[email protected]> Mon, 23 Nov 2009 01:29:29 +0100
| Newsgroups | gmane.comp.apache.mod-ssl.user |
|---|---|
| Message-ID | <[email protected]> |
--=-GqA1f0IobZ3N8TL07EHH Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi all, I have been using client certificate for a while (more than 2 years) successfuly. But now, after migrating a server, I am stuck with a problem that I have no idea how to handle. I just spent 10 hours googling around and reading the doc without finding any clue. On my new set-up, the web browser seems to reject the negociation : [Sun Nov 22 22:51:36 2009] [info] [client ::1] Connection to child 2 established (server www.***.net:443) [Sun Nov 22 22:51:36 2009] [info] Seeding PRNG with 656 bytes of entropy [Sun Nov 22 22:51:36 2009] [debug] ssl_engine_kernel.c(1875): OpenSSL: Handshake: start [Sun Nov 22 22:51:36 2009] [debug] ssl_engine_kernel.c(1883): OpenSSL: Loop: before/accept initialization [Sun Nov 22 22:51:36 2009] [debug] ssl_engine_io.c(1858): OpenSSL: read 11/11 bytes from BIO#7f35d1213840 [mem: 7f35d1218f00] (BIO dump follows) [Sun Nov 22 22:51:36 2009] [debug] ssl_engine_io.c(1791): +-------------------------------------------------------------------------+ [Sun Nov 22 22:51:36 2009] [debug] ssl_engine_io.c(1830): | 0000: 4f 50 54 49 4f 4e 53 20-2a 20 48 OPTIONS * H | [Sun Nov 22 22:51:36 2009] [debug] ssl_engine_io.c(1836): +-------------------------------------------------------------------------+ [Sun Nov 22 22:51:36 2009] [debug] ssl_engine_kernel.c(1912): OpenSSL: Exit: error in SSLv2/v3 read client hello A [Sun Nov 22 22:51:36 2009] [info] [client ::1] SSL library error 1 in handshake (server www.***.net:443) [Sun Nov 22 22:51:36 2009] [info] SSL Library Error: 336027900 error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol speaking not SSL to HTTPS port!? [Sun Nov 22 22:51:36 2009] [info] [client ::1] Connection closed to child 2 with abortive shutdown (server www.***.net:443) I have tried a bund of different settings. Of course, I re-generated several times all the certificates, from the CA to the client. Both the CA and the client were imported into the web browser. The mod-ssl settings are in no point different from the previous machine, so am I missing ? So any help, any hint would be greatly appreciated. Thank you in advance, Regards, Jean-Christophe --=-GqA1f0IobZ3N8TL07EHH Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Ceci est une partie de message =?ISO-8859-1?Q?num=E9riquement?= =?ISO-8859-1?Q?_sign=E9e?= -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.12 (GNU/Linux) iQIcBAABAgAGBQJLCddpAAoJEEElXOw26xO+4CgP/ieQEHn269sdyTMaKIrqVYHN 9bIYJedzekLrt1DhrToUOA3aE0diqWxLIDnKN5NYdlPcMjRPSsdI+HvflwIHqK7c mUjSUyzcD5uDVUzE1KQBPf0MGtwlW/QjtNTC7VSUeDlLlElM5EecPFbsA2lCU7CO cLGf1ubnGIVwtdSv0mmo19OmIJ/UBnNAQVhNjj35faA8yaG8SXZDGum3RGNEbzac bteV0nY3vyEx2zfjdKi1C4JWFKDqOApx+dj/tPIacYdBaC2fqlKpPk03/4f4usDz tiHHNNFBVf542oSJgx30Uhi7twl+L1hEtZPadgsqQ4WS/mM5LTIIG8422Qw8SmqU fiQIAYy1LUgzKTI55A1aZ9XH9xfRLAHHyUEVKTbkTKnfisy26sG3uXVKffqunmgr gg4guhdyNJT55Ee4oOJMn+GRgxsIcFcNF7ovTwfi+nyFIO0yQfu5mGL6EVpXPV4u jsuQ9bzwZ8jlbTMGxltZ3OmYRqHFmgYzodA++HnCH+XPXzOYoqnKg90HQY85tiiK 5htLBheW0k9/TWLdTKmeGjZ8pc8i0Tja44m1fUTzAddwW9SELeUzZBYtiI16gibv OmPDgKRG3Rcxb7NeNVz8LiSAAPs4ec93PdKqeHCAwh4no6+Ha6pH924pnO4+tFgZ sEOz+zKDY5c80LnuueGJ =Wsw8 -----END PGP SIGNATURE----- --=-GqA1f0IobZ3N8TL07EHH-- ______________________________________________________________________ Apache Interface to OpenSSL (mod_ssl) www.modssl.org User Support Mailing List [email protected] Automated List Manager [email protected]