RE: SSL Handshake error

"Andrew Hamlin" <[email protected]> Tue, 19 Nov 2002 18:44:35 -0500
Newsgroups gmane.network.up2date.current.devel
Message-ID <[email protected]>
I answered my own question while exploring some other strange behaviour...

I have installed my server's certificate as /usr/share/rhn/CURRENT-CA-CERT
so the /etc/sysconfig/rhn/rhn_register file must have the sslCACert entry
updated to point to CURRENT-CA-CERT. If this entry doesn't exist the
rhn_register program defaults to using the /usr/share/rhn/RHNS-CA-CERT!

Andrew
  -----Original Message-----
  From: Andrew Hamlin [mailto:[email protected]]
  Sent: Tuesday, November 19, 2002 2:07 PM
  To: Current
  Subject: SSL Handshake error


  I've setup a current server on a Red Hat 7.3 machine.  I can run
rhn_register and up2date on that box with the configuration files pointing
to both, localhost/XMLRPC and <ipaddress>/XMLRPC.

  Now I've setup a second channel for a Red Hat 6.2 machine. Edited the
config files to point to <ipaddress>/XMLRPC and tried to run rhn_register.
However, I keep getting an SSL_connect error.

  The apache log contains the following error:
  [19/Nov/2002 13:44:38 14932] [error] OpenSSL: error:14094418:SSL
routines:SSL3_READ_BYTES:tlsv1 alert unknown ca

  I've tried reading through and updating the apache ssl settings as best I
can but to no avail!

  The apache configuration changes I've tried:

  Listed only the server.crt (as generated by cadmin create_certificate) as
the SSLCertificateChainFile
  #   Server Certificate Chain:
  SSLCertificateChainFile /etc/httpd/conf/ssl.crt/server.crt
  #SSLCertificateChainFile /etc/httpd/conf/ssl.crt/ca.crt

  Rebuilt the ssl.crt hash files using the
/etc/httpd/conf/ssl.crt/Makefile.crt and changed apache's CACertificatePath
appropriately.
  #   Certificate Authority (CA):
  SSLCACertificatePath /etc/httpd/conf/ssl.crt

  Updated the ca-bundle.crt file and changed apache's CACertificateFile
  #SSLCACertificateFile /etc/httpd/conf/ssl.crt/ca-bundle.crt

  Tried to ask apache not to check with a CA at all...
  #   Client Authentication (Type):
  #SSLVerifyClient require
  #SSLVerifyDepth  10
  SSLVerifyClient optional_no_ca

  I'm no Apache/SSL expert so reading the comments in httpd.conf and trying
each of the settings has been the best I can do.  Before going to off to
explore the web for posts about apache/ssl configuration I thought I'd ask
if anyone on the list has run into an SSL connection problem like this
before?

  The Red Hat 6.2 machine I'm trying to use has all recently available
patches from Red Hat. The ones that I think may impact the running of the
SSL Connection are:

  openssl-0.9.5a-29
  up2date-2.7.61-6.x.1
  rhn_register-2.7.9-6.x.1

  Any thoughts?

  Thanks,
  Andrew