[Pkg-openssl-devel] Bug#853730: handshake failure alert number 40

Sebastian Andrzej Siewior sebastian at breakpoint.cc
Tue Jan 31 12:45:51 UTC 2017


On 2017-01-31 07:05:46 [-0500], Leand wrote:
> After a recent upgrade of debian testing Kmail failes to nogotiate
> SSL with two accounts. In fact openssl gives handshake failure
> alert if I test with imap:
> 
> openssl s_client -connect imap.fastwebnet.it:993 or
> openssl s_client -connect mail.postecert.it:993
…
> With Icedove these two accounts (fastweb and postecert) work ok,
> but Icedove does not use openssl. I tested the same openssl
> command with debian live and it works, gives the certificates and
> the message "OK IMAP4 PROXY server ready".

both server seem to only support TLS1.0 with 3DES-CBC + SHA1 or this is
what I get once I tried with an older version. 3DES has been disabled
because it is considered insecure.
	https://sweet32.info/

Sebastian



More information about the Pkg-openssl-devel mailing list