error in SSLv2/v3 read client hello A

Jean-Christophe Baptiste <[email protected]> Mon, 23 Nov 2009 01:29:29 +0100
Newsgroups gmane.comp.apache.mod-ssl.user
Message-ID <[email protected]>
--=-GqA1f0IobZ3N8TL07EHH
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi all,

I have been using client certificate for a while (more than 2 years)
successfuly.

But now, after migrating a server, I am stuck with a problem that I have
no idea how to handle.
I just spent 10 hours googling around and reading the doc without
finding any clue.

On my new set-up, the web browser seems to reject the negociation :

[Sun Nov 22 22:51:36 2009] [info] [client ::1] Connection to child 2
established (server www.***.net:443)
[Sun Nov 22 22:51:36 2009] [info] Seeding PRNG with 656 bytes of entropy
[Sun Nov 22 22:51:36 2009] [debug] ssl_engine_kernel.c(1875): OpenSSL:
Handshake: start
[Sun Nov 22 22:51:36 2009] [debug] ssl_engine_kernel.c(1883): OpenSSL:
Loop: before/accept initialization
[Sun Nov 22 22:51:36 2009] [debug] ssl_engine_io.c(1858): OpenSSL: read
11/11 bytes from BIO#7f35d1213840 [mem: 7f35d1218f00] (BIO dump follows)
[Sun Nov 22 22:51:36 2009] [debug] ssl_engine_io.c(1791):
+-------------------------------------------------------------------------+
[Sun Nov 22 22:51:36 2009] [debug] ssl_engine_io.c(1830): | 0000: 4f 50
54 49 4f 4e 53 20-2a 20 48                 OPTIONS * H      |
[Sun Nov 22 22:51:36 2009] [debug] ssl_engine_io.c(1836):
+-------------------------------------------------------------------------+
[Sun Nov 22 22:51:36 2009] [debug] ssl_engine_kernel.c(1912): OpenSSL:
Exit: error in SSLv2/v3 read client hello A
[Sun Nov 22 22:51:36 2009] [info] [client ::1] SSL library error 1 in
handshake (server www.***.net:443)
[Sun Nov 22 22:51:36 2009] [info] SSL Library Error: 336027900
error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol
speaking not SSL to HTTPS port!?
[Sun Nov 22 22:51:36 2009] [info] [client ::1] Connection closed to
child 2 with abortive shutdown (server www.***.net:443)

I have tried a bund of different settings. Of course, I re-generated
several times all the certificates, from the CA to the client.
Both the CA and the client were imported into the web browser.

The mod-ssl settings are in no point different from the previous
machine, so am I missing ?

So any help, any hint would be greatly appreciated.

Thank you in advance,

Regards,
Jean-Christophe





--=-GqA1f0IobZ3N8TL07EHH
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Ceci est une partie de message
 =?ISO-8859-1?Q?num=E9riquement?= =?ISO-8859-1?Q?_sign=E9e?=

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.12 (GNU/Linux)

iQIcBAABAgAGBQJLCddpAAoJEEElXOw26xO+4CgP/ieQEHn269sdyTMaKIrqVYHN
9bIYJedzekLrt1DhrToUOA3aE0diqWxLIDnKN5NYdlPcMjRPSsdI+HvflwIHqK7c
mUjSUyzcD5uDVUzE1KQBPf0MGtwlW/QjtNTC7VSUeDlLlElM5EecPFbsA2lCU7CO
cLGf1ubnGIVwtdSv0mmo19OmIJ/UBnNAQVhNjj35faA8yaG8SXZDGum3RGNEbzac
bteV0nY3vyEx2zfjdKi1C4JWFKDqOApx+dj/tPIacYdBaC2fqlKpPk03/4f4usDz
tiHHNNFBVf542oSJgx30Uhi7twl+L1hEtZPadgsqQ4WS/mM5LTIIG8422Qw8SmqU
fiQIAYy1LUgzKTI55A1aZ9XH9xfRLAHHyUEVKTbkTKnfisy26sG3uXVKffqunmgr
gg4guhdyNJT55Ee4oOJMn+GRgxsIcFcNF7ovTwfi+nyFIO0yQfu5mGL6EVpXPV4u
jsuQ9bzwZ8jlbTMGxltZ3OmYRqHFmgYzodA++HnCH+XPXzOYoqnKg90HQY85tiiK
5htLBheW0k9/TWLdTKmeGjZ8pc8i0Tja44m1fUTzAddwW9SELeUzZBYtiI16gibv
OmPDgKRG3Rcxb7NeNVz8LiSAAPs4ec93PdKqeHCAwh4no6+Ha6pH924pnO4+tFgZ
sEOz+zKDY5c80LnuueGJ
=Wsw8
-----END PGP SIGNATURE-----

--=-GqA1f0IobZ3N8TL07EHH--

______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [email protected]
Automated List Manager                            [email protected]