[Pkg-openssl-devel] Bug#1131904: libssl3t64: "LS alert, bad record mac (532)" / "decryption failed or bad record mac" since 3.6.1 on ppc64

John Paul Adrian Glaubitz glaubitz at physik.fu-berlin.de
Sat Mar 28 22:07:06 GMT 2026


Hi Philipp,

On Thu, 2026-03-26 at 08:33 +0100, Philipp Klaus Krause wrote:
> about a week ago, I upgraded libssl3t64 on my ppc64 system to 3.6.1-3. This resulted in failures (see below). After downgrading to 3.6.0-2, the failures disappeared. An amd64 system on the same network was not affected (there 3.6.1 works).
> 
> Failure example:
> 
> philipp at nemesis:/tmp$ curl --verbose https://www.google.com
> * Host www.google.com:443 was resolved.
> * IPv6: 2001:4860:482d:7700::, 2001:4860:4829:7700::, 2001:4860:4827:7700::, 2001:4860:482c:7700::, 2001:4860:4828:7700::, 2001:4860:482a:7700::, 2001:4860:482b:7700::, 2001:4860:4826:7700::
> * IPv4: 142.251.156.119, 142.251.154.119, 142.251.152.119, 142.251.150.119, 142.251.155.119, 142.251.153.119, 142.251.157.119, 142.251.151.119
> *   Trying [2001:4860:482d:7700::]:443...
> * ALPN: curl offers h2,http/1.1
> * TLSv1.3 (OUT), TLS handshake, Client hello (1):
> * SSL Trust Anchors:
> *   CAfile: /etc/ssl/certs/ca-certificates.crt
> *   CApath: /etc/ssl/certs
> * TLSv1.3 (IN), TLS handshake, Server hello (2):
> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):
> * TLSv1.3 (OUT), TLS alert, bad record mac (532):
> * TLS connect error: error:0A000119:SSL routines::decryption failed or bad record mac
> * closing connection #0
> curl: (35) TLS connect error: error:0A000119:SSL routines::decryption failed or bad record mac

I suggest reporting this issue upstream: https://github.com/openssl/openssl/issues

Adrian

-- 
 .''`.  John Paul Adrian Glaubitz
: :' :  Debian Developer
`. `'   Physicist
  `-    GPG: 62FF 8A75 84E0 2956 9546  0006 7426 3B37 F5B5 F913



More information about the Pkg-openssl-devel mailing list