RE: Error with Kannel 1.5.0

Piotr Galecki <[email protected]>
Newsgroups gmane.comp.mobile.kannel.devel
Message-ID <2C515BE8694C6F4B9B6A578BCAC32E2F0252937A@MBX021-W3-CA-1.exch021.domain.local>
Hi,

My understanding is that kannel only supports RSA_anon (anonymous RSA) as a key exchange algorithm.
It looks like OpenWave did not offer RSA_anon as a choice.
You could confirm that from wireshark trace.
Wapbox rejects creation of secure session since both sides could not agree on a common key exchange algorithm.

Piotr

From: [email protected] [mailto:[email protected]] On Behalf Of Rocio Santiago Sanchez
Sent: Monday, April 08, 2013 4:25 PM
To: [email protected]
Subject: Error with Kannel 1.5.0

Hi all,

I'm using Development Kannel release 1.5.0 compiled with openssl-1.0.1e on linux RH ES 6.0 compiled with gcc (GCC) 4.4.6 20110731 (Red Hat 4.4.6-3). Then I'm trying  to establish a secure WTLS connection with OpenWave Browser version 4.1 and version 7.0.

1. When I use the Openwave 7.0, the connection works fine (Attachment wapbox-Openwave-7.0.log and bearerbox-Openwave-7.0.log):

DEBUG:   Octet string dump ends.
DEBUG: wtls_choose_ciphersuite ~> Accepted cipher: RC5_CBC, mac: SHA_NOLIMIT (#1/12)
DEBUG: wtls_choose_clientkeyid ~> Accepted key algorithm: rsa_anon (#2/4)
DEBUG: Key Exchange Id: 0x0x7fd97c000f00
DEBUG:  Key Exch Suite: 5
DEBUG:  ParameterSpecifier:
DEBUG:   Parameter Index: 0
DEBUG:  Identifier: 0x0x7fd97c005970
DEBUG:   Ident type: 2
DEBUG:   Identifier: 0x0x7fd97c0059a0
DEBUG: Octet string at 0x7fd97c0059a0:
DEBUG:   len:  11
DEBUG:   size: 12

2. But when I use the Openwave 4.1, I get the following error (Attachment wapbox-Openwave-4.1.log and bearerbox-Openwave-4.1.log):

DEBUG: Offset is now : 0
DEBUG: Finished, found 1 PDUs
INFO: Datagram unpacked!
DEBUG: event->type = 0
DEBUG: WTLS: Created WTLSMachine 41 (0x0x7fd97c0008c0)
DEBUG: WTLS: wtls_machine 41, state NULL_STATE, event T-Unitdata.ind.
DEBUG: wtls_choose_ciphersuite ~> Accepted cipher: RC5_CBC, mac: SHA_NOLIMIT (#1/12)
ERROR: Couldn't agree on key exchange protocol. Aborting
INFO: Mutex gwlib/list.c:136: 10 locks, 0 collisions.
INFO: Mutex gwlib/list.c:136: 1 locks, 0 collisions.
INFO: Mutex gwlib/list.c:136: 39 locks, 0 collisions.

In unit testing (Motorola I415, technology IDEN) appears: Unrecoverable security error and in Verify Key: No key.

Why this error is happening with Openwave 4.1?

1. Am I creating bad certificates?. I used to generate certificates:

openssl genrsa -des3 -out server.key 1024
openssl req -new -key server.key -out server.csr
cp server.key server.key.org<http://server.key.org>
openssl rsa -in server.key.org<http://server.key.org> -out server.key
rm server.key.org<http://server.key.org>
openssl x509 -req -days 365 -in server.csr -signkey server.key -out server.crt

2. Or is something wrong with the configuration parameters of Kannel. (Attachment compile_line_program.txt and enviroment_SO_kannel.txt). In Kannel.conf file, I put:

group = wtls
certificate-file = /opt/fuenteskannel/1.5.0/server.crt
privatekey-file = /opt/fuenteskannel/1.5.0/server.key
#privatekey-password = "libertad1"

I really appreciate your help.

Regards,






--
Rocio Santiago Sanchez
Ingeniero Desarrollador de Software
AVANTEL S.A.S
Comunicación Inmediata: 9863
Conexión Telefónica: 350 5580948
Bogotá, Colombia

<http://www.avantel.co>

[https://3849987313389227310-a-avantel-com-co-s-sites.googlegroups.com/a/avantel.com.co/capacitaciones-google-apps/firma-digital.gif]<http://www.avantel.co>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.