mod_ssl upgrade
<[email protected]> Tue, 27 May 2003 10:07:15 +0300
| Newsgroups | gmane.linux.redhat.stronghold |
|---|---|
| Message-ID | <D024CC41D183304D96EE1C2378BDA602015C4847@TCEXH3402.turkcell.entp.tgc> |
> > > Dear Sir(s)/Madam(s), > We're using Stronghold 3.22 with the configuration below: > Server Version: Stronghold/3.0 Apache/1.3.22 RedHat/3022 (Unix) PHP/3.0.18 mod_ssl/2.8.7 OpenSSL/0.9.6b mod_perl/1.25 > > We were using AEP ssl acc. cards but last week we've started get such an error messages below. > > Thu May 22 11:05:16 2003] [error] OpenSSL: error:2609D084:engine routines:AEP_INIT:aep init failure > [Thu May 22 11:05:16 2003] [error] OpenSSL: error:260A006B:engine routines:AEP_MOD_EXP_CRT:could not obtain hardware handle > [Thu May 22 11:05:16 2003] [error] OpenSSL: error:1408B076:SSL routines:SSL3_GET_CLIENT_KEY_EXCHANGE:bad rsa decrypt > [Thu May 22 11:05:16 2003] [error] CONNECTION_REFUSED [os error=146, line 1653 of ap_proxy.cpp]: > [Thu May 22 11:05:16 2003] [error] mod_ssl: SSL handshake failed (server secure2.turkcell.com.tr:443, client 195.174.195.135) > (OpenSSL library error follows) > > When we sent these messages to AEP support, they suggest us to fo the following things. Here is the answer that we've received: > "From the answers it seems that the AEP card is not faulty as the aeptest indicates it is functioning ok. Could you ask them to run the Openssl "speed" test with the -engine aep option. Incidently I notice that they are using mod_ssl 2.8.7. We think there is a problem with versions 2.8.6 to 2.8.9 These versions have a bug which causes a major performance drop. It is caused by the way the software seeds the random number generator. Versions 2.8.10 onwards fixed this bug. When we get them operational suggest that they upgrade to version 2.8.10 In the meantime I will discuss this further with our engineers to see if they can figure out what the problem is." > > So, in this point of view, we're trying to upgrade mod_ssl version 2.8.10 or above but we couldn't able to do it yet. > Could not find any mod_ssl source at www.modssl.org for our distribution of apache (1.3.22) version. > > Do you have any idea what might be the problem is? Also, do you have any mod_ssl 2.8.10 or above version > for apache 1.3.22 version to be upgrade and try our ssl accelerator cards? > > Looking forward for hearing from you, > > Kind regards, > *********************************************************************** Bu elektronik posta ve onunla iletilen bütün dosyalar sadece göndericisi tarafından alması amaçlanan yetkili gerçek ya da tüzel kişinin kullanımı içindir.Eğer söz konusu yetkili alıcı değilseniz bu elektronik postanın içeriğini açıklamanız,kopyalamanız, yönlendirmeniz ve kullanmanız kesinlikle yasaktır ve bu elektronik postayı derhal silmeniz gerekmektedir TURKCELL bu mesajın içerdiği bilgilerin doğruluğu veya eksiksiz olduğu konusunda herhangi bir garanti vermemektedir. Bu nedenle bu bilgilerin ne şekilde olursa olsun içeriğinden, iletilmesinden, alınmasından ve saklanmasından sorumlu değildir. Bu mesajdaki görüşler yalnızca gönderen kişiye aittir ve TURKCELL'in görüşlerini yansıtmayabilir Bu e-posta bilinen bütün bilgisayar virüslerine karşı taranmıştır. *********************************************************************** This e-mail and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you are not the intended recipient you are hereby notified that any dissemination, forwarding, copying or use of any of the information is strictly prohibited, and the e-mail should immediately be deleted. TURKCELL makes no warranty as to the accuracy or completeness of any information contained in this message and hereby excludes any liability of any kind for the information contained therein or for the information transmission, reception, storage or use of such in any way whatsoever.The opinions expressed in this message belong to sender alone and may not necessarily reflect the opinions of TURKCELL. This e-mail has been scanned for all known computer viruses. ***********************************************************************