RE: Error with Kannel 1.5.0
Piotr Galecki <[email protected]>
| Newsgroups | gmane.comp.mobile.kannel.devel |
|---|---|
| Message-ID | <2C515BE8694C6F4B9B6A578BCAC32E2F0252937A@MBX021-W3-CA-1.exch021.domain.local> |
Hi, My understanding is that kannel only supports RSA_anon (anonymous RSA) as a key exchange algorithm. It looks like OpenWave did not offer RSA_anon as a choice. You could confirm that from wireshark trace. Wapbox rejects creation of secure session since both sides could not agree on a common key exchange algorithm. Piotr From: [email protected] [mailto:[email protected]] On Behalf Of Rocio Santiago Sanchez Sent: Monday, April 08, 2013 4:25 PM To: [email protected] Subject: Error with Kannel 1.5.0 Hi all, I'm using Development Kannel release 1.5.0 compiled with openssl-1.0.1e on linux RH ES 6.0 compiled with gcc (GCC) 4.4.6 20110731 (Red Hat 4.4.6-3). Then I'm trying to establish a secure WTLS connection with OpenWave Browser version 4.1 and version 7.0. 1. When I use the Openwave 7.0, the connection works fine (Attachment wapbox-Openwave-7.0.log and bearerbox-Openwave-7.0.log): DEBUG: Octet string dump ends. DEBUG: wtls_choose_ciphersuite ~> Accepted cipher: RC5_CBC, mac: SHA_NOLIMIT (#1/12) DEBUG: wtls_choose_clientkeyid ~> Accepted key algorithm: rsa_anon (#2/4) DEBUG: Key Exchange Id: 0x0x7fd97c000f00 DEBUG: Key Exch Suite: 5 DEBUG: ParameterSpecifier: DEBUG: Parameter Index: 0 DEBUG: Identifier: 0x0x7fd97c005970 DEBUG: Ident type: 2 DEBUG: Identifier: 0x0x7fd97c0059a0 DEBUG: Octet string at 0x7fd97c0059a0: DEBUG: len: 11 DEBUG: size: 12 2. But when I use the Openwave 4.1, I get the following error (Attachment wapbox-Openwave-4.1.log and bearerbox-Openwave-4.1.log): DEBUG: Offset is now : 0 DEBUG: Finished, found 1 PDUs INFO: Datagram unpacked! DEBUG: event->type = 0 DEBUG: WTLS: Created WTLSMachine 41 (0x0x7fd97c0008c0) DEBUG: WTLS: wtls_machine 41, state NULL_STATE, event T-Unitdata.ind. DEBUG: wtls_choose_ciphersuite ~> Accepted cipher: RC5_CBC, mac: SHA_NOLIMIT (#1/12) ERROR: Couldn't agree on key exchange protocol. Aborting INFO: Mutex gwlib/list.c:136: 10 locks, 0 collisions. INFO: Mutex gwlib/list.c:136: 1 locks, 0 collisions. INFO: Mutex gwlib/list.c:136: 39 locks, 0 collisions. In unit testing (Motorola I415, technology IDEN) appears: Unrecoverable security error and in Verify Key: No key. Why this error is happening with Openwave 4.1? 1. Am I creating bad certificates?. I used to generate certificates: openssl genrsa -des3 -out server.key 1024 openssl req -new -key server.key -out server.csr cp server.key server.key.org<http://server.key.org> openssl rsa -in server.key.org<http://server.key.org> -out server.key rm server.key.org<http://server.key.org> openssl x509 -req -days 365 -in server.csr -signkey server.key -out server.crt 2. Or is something wrong with the configuration parameters of Kannel. (Attachment compile_line_program.txt and enviroment_SO_kannel.txt). In Kannel.conf file, I put: group = wtls certificate-file = /opt/fuenteskannel/1.5.0/server.crt privatekey-file = /opt/fuenteskannel/1.5.0/server.key #privatekey-password = "libertad1" I really appreciate your help. Regards, -- Rocio Santiago Sanchez Ingeniero Desarrollador de Software AVANTEL S.A.S Comunicación Inmediata: 9863 Conexión Telefónica: 350 5580948 Bogotá, Colombia <http://www.avantel.co> [https://3849987313389227310-a-avantel-com-co-s-sites.googlegroups.com/a/avantel.com.co/capacitaciones-google-apps/firma-digital.gif]<http://www.avantel.co>