RE: SSL Handshake error

"PRUCHA,CHAD (HP-Corvallis,ex1)" <[email protected]> Tue, 19 Nov 2002 14:05:51 -0800
Newsgroups gmane.network.up2date.current.devel
Message-ID <[email protected]>
There is another project with the same goals as Current and the fellow in
charge over there has some pretty comprehensive documentation.  He
specifically states that SSL certs generated on a 7.3 machine tend to fail
with pre-7.3 clients.  He suggests generating a cert on a 7.1 machine and
moving it to the 7.3 machine.

I did just that with cadmin.

Worked for me.


--Chad

A Haiku on the Zen of Computing:

Chaos reigns within.
Reflect, repent, and reboot.
Order shall return.

> -----Original Message-----
> From: Alex Kramarov [mailto:[email protected]] 
> Sent: Tuesday, November 19, 2002 12:27 PM
> To: [email protected]
> Subject: Re: [Current-server] SSL Handshake error
> 
> 
> I have actually seen on several occasions that a certificate 
> generated on RH 7.3 didn't work with RH 7.1 clients, In this 
> case the client is 6.2, which puts the version difference in 
> the openssl versions even farther - openssl is not always 
> completely backwards compatible - i have seen these problems 
> more then once. 
> 
> 
> 
> in that case, i generated the certificate on the 7.1 machine, 
> and copied it to the server - this fixed the problem for both 
> 7.3 and 7.1  - it's is worth to try to generate the 
> certificate on the 6.2
> 
> 
> 
> Alex.
> 
>  
> 
> -------Original Message-------
> 
>  
> 
> From: [email protected]
> 
> Date: éåí ùìéùé 19 ðåáîáø 2002 22:15:40
> 
> To: Current Server Mailing List
> 
> Subject: Re: [Current-server] SSL Handshake error
> 
>  
> 
> 99% of the time, this is due to the client having an incorrect
> 
> RHNS-CA-CERT file.
> 
>  
> 
> Can you confirm that the 6.2 machines RHNS-CA-CERT is the one you
> 
> generated, and not red hat's?
> 
>  
> 
>  
> 
> On Tue, 2002-11-19 at 14:06, Andrew Hamlin wrote:
> 
> > I've setup a current server on a Red Hat 7.3 machine. I can run
> 
> > rhn_register and up2date on that box with the configuration files 
> > pointing
> 
> > to both, localhost/XMLRPC and <ipaddress>/XMLRPC.
> 
> > 
> 
> > Now I've setup a second channel for a Red Hat 6.2 machine. 
> Edited the
> config
> 
> > files to point to <ipaddress>/XMLRPC and tried to run rhn_register.
> However,
> 
> > I keep getting an SSL_connect error.
> 
> > 
> 
> > The apache log contains the following error:
> 
> > [19/Nov/2002 13:44:38 14932] [error] OpenSSL: error:14094418:SSL
> 
> > routines:SSL3_READ_BYTES:tlsv1 alert unknown ca
> 
> > 
> 
> > I've tried reading through and updating the apache ssl settings as 
> > best I
> 
> > can but to no avail!
> 
> > 
> 
> > The apache configuration changes I've tried:
> 
> > 
> 
> > Listed only the server.crt (as generated by cadmin 
> create_certificate) 
> > as
> 
> > the SSLCertificateChainFile
> 
> > # Server Certificate Chain:
> 
> > SSLCertificateChainFile /etc/httpd/conf/ssl.crt/server.crt
> 
> > #SSLCertificateChainFile /etc/httpd/conf/ssl.crt/ca.crt
> 
> > 
> 
> > Rebuilt the ssl.crt hash files using the
> 
> > /etc/httpd/conf/ssl.crt/Makefile.crt and changed apache's
> CACertificatePath
> 
> > appropriately.
> 
> > # Certificate Authority (CA):
> 
> > SSLCACertificatePath /etc/httpd/conf/ssl.crt
> 
> > 
> 
> > Updated the ca-bundle.crt file and changed apache's 
> CACertificateFile
> 
> > #SSLCACertificateFile /etc/httpd/conf/ssl.crt/ca-bundle.crt
> 
> > 
> 
> > Tried to ask apache not to check with a CA at all...
> 
> > # Client Authentication (Type):
> 
> > #SSLVerifyClient require
> 
> > #SSLVerifyDepth 10
> 
> > SSLVerifyClient optional_no_ca
> 
> > 
> 
> > I'm no Apache/SSL expert so reading the comments in httpd.conf and 
> > trying
> 
> > each of the settings has been the best I can do. Before 
> going to off 
> > to
> 
> > explore the web for posts about apache/ssl configuration I 
> thought I'd 
> > ask
> 
> > if anyone on the list has run into an SSL connection 
> problem like this
> 
> > before?
> 
> > 
> 
> > The Red Hat 6.2 machine I'm trying to use has all recently available
> patches
> 
> > from Red Hat. The ones that I think may impact the running 
> of the SSL
> 
> > Connection are:
> 
> > 
> 
> > openssl-0.9.5a-29
> 
> > up2date-2.7.61-6.x.1
> 
> > rhn_register-2.7.9-6.x.1
> 
> > 
> 
> > Any thoughts?
> 
> > 
> 
> > Thanks,
> 
> > Andrew
> 
> > 
> 
> > 
> 
> > 
> 
> -- 
> 
> Hunter Matthews Unix / Network Administrator
> 
> Office: BioScience 145/244 Duke Univ. Biology Department
> 
> Key: F0F88438 / FFB5 34C0 B350 99A4 BB02 9779 A5DB 8B09 F0F8 8438
> 
> Never take candy from strangers. Especially on the internet.
> 
>  
> 
> _______________________________________________
> 
> Current-server mailing list
> 
> [email protected]
> 
http://lists.dulug.duke.edu/mailman/listinfo/current-server

 

. 
_______________________________________________
Current-server mailing list
[email protected]
http://lists.dulug.duke.edu/mailman/listinfo/current-server