gnutls 2.10.5-2 and 2.12.7-1 on ARM are failing with PSK

Andreas Metzler ametzler at downhill.at.eu.org
Thu Jul 7 17:41:39 UTC 2011


On 2011-07-07 Hardy Griech <ntbox at mardys.de> wrote:
> my ARM hardware is a NAS with a Marvell Kirkwood processor.  I'm
> using a modified version of libapache2-mod-gnutls to allow
> PSK_SHA_AES_128_CBC_SHA1 for TLS.

> After updating gnutls from 2.10.5-1 to 2.10.5-2 PSK stopped working.
> It stated in the log "GnuTLS: Handshake Failed (-24) 'Decryption has
> failed.'".

> Upgrading to 2.12.7-1 also did not help.

> 2.12.7-1 works with the modified libapache2-mod-gnutls on an i386 box.
[...]

I assume the last paragraph should read "2.10.5-1 works ...". Correct?

2.10.5-1 and 2.10.5-2 are source-identical, the only difference is
that we stopped shipping a libtool la file. Afaiui
libapache2-mod-gnutls does not rely on the la-file (it does not depend
libgnutls-dev), which only leaves a broken comilation, due to toolchain
breakage or hardware failure.

Does rebuilding the gnutls26 2.10.5-1 debian source package work for
you?

cu andreas

-- 
`What a good friend you are to him, Dr. Maturin. His other friends are
so grateful to you.'
`I sew his ears on from time to time, sure'



More information about the Pkg-gnutls-maint mailing list