[Pkg-openssl-devel] Bug#694696: OpenSSL: TLS 1.1 and 1.2 client - invalid Client Hello during renegotiation

von Wittich, Christoph vonWittich.Christoph at hentschke-bau.de
Thu Nov 29 09:50:27 UTC 2012


Package: openssl
Version: 1.0.1c-4

http://rt.openssl.org/Ticket/Display.html?id=2828

TLSv1.2 with OpenSSL:

Client:

Content Type: Handshake (22)
Version: TLS 1.0 (0x0301)
Handshake Protocol: Client Hello
Handshake Type: Client Hello (1)
Version: TLS 1.1 (0x0302)

Server responds with:

Content Type: Handshake (22)
Version: TLS 1.0 (0x0301)
Handshake Protocol: Server Hello
Handshake Type: Server Hello (2)
Version: TLS 1.0 (0x0301)


è 3073415368:error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number:s3_pkt.c:340:


TLS 1.2 with Internet Explorer 9 on Windows 7 behaves different:

Client:

Content Type: Handshake (22)
Version: TLS 1.1 (0x0302)
Handshake Protocol: Client Hello
Handshake Type: Client Hello (1)
Version: TLS 1.1 (0x0302)

Server responds with:

Content Type: Handshake (22)
Version: TLS 1.1 (0x0302)
Handshake Protocol: Server Hello
Handshake Type: Server Hello (2)
Version: TLS 1.1 (0x0302)


è No Error

Mit freundlichen Grüßen
i.A. Christoph von Wittich

--
Christoph von Wittich                   Büro Bautzen
EDV-Verantwortlicher                  Zeppelinstraße 15
Tel. +49 3591 67 03-56                   02625 Bautzen
                                                               Fax +49 3591 6703 918

Hentschke Bau GmbH                  Geschäftsführer
Zeppelinstraße 15                          Jörg Drews
02625 Bautzen                                 Thomas Alscher
www.hentschke-bau.de<http://www.hentschke-bau.de>             HRB 6535 Dresden

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/pkg-openssl-devel/attachments/20121129/4a3d2df8/attachment.html>


More information about the Pkg-openssl-devel mailing list