Welcome! Log In Create A New Profile

Advanced

Re: Issue with VirtualHost definition order and SNI SSL

October 29, 2009 03:02AM
On Wed, Oct 28, 2009 at 11:59:44PM +0200, Iantcho Vassilev wrote:

> Here is the debug on the host when only one site listens to 443
>
> 2009/10/29 00:55:11 [debug] 9171#0: *195388 http check ssl handshake
> 2009/10/29 00:55:11 [debug] 9171#0: *195388 https ssl handshake: 0x16
> 2009/10/29 00:55:11 [debug] 9171#0: *195388 SSL_do_handshake: -1
> 2009/10/29 00:55:11 [debug] 9171#0: *195388 SSL_get_error: 2

SNI handshake looks like this:

2009/10/29 09:53:05 [debug] 73997#0: *1 http check ssl handshake
2009/10/29 09:53:05 [debug] 73997#0: *1 https ssl handshake: 0x16
2009/10/29 09:53:05 [debug] 73997#0: *1 SSL server name: "www.example.com"
2009/10/29 09:53:05 [debug] 73997#0: *1 SSL_do_handshake: -1
2009/10/29 09:53:05 [debug] 73997#0: *1 SSL_get_error: 2

> 2009/10/29 00:55:11 [debug] 9171#0: *195388 post event 0000000001DD95A0
> 2009/10/29 00:55:11 [debug] 9171#0: *195388 delete posted event
> 0000000001DD95A0
> 2009/10/29 00:55:11 [debug] 9171#0: *195388 SSL handshake handler: 0
> 2009/10/29 00:55:11 [debug] 9171#0: *195388 SSL_do_handshake: 1
> 2009/10/29 00:55:11 [debug] 9171#0: *195388 SSL: SSLv3, cipher:
> "DHE-RSA-AES256-SHA SSLv3 Kx=DH Au=RSA Enc=AES(256) Mac=SHA1"

For some reason only SSLv3 has been negotiated.
Either server has no enabled TLSv1 in ssl_protocols, or browser.


--
Igor Sysoev
http://sysoev.ru/en/
Subject Author Posted

Issue with VirtualHost definition order and SNI SSL

Linmiao Xu October 09, 2009 02:28PM

Re: Issue with VirtualHost definition order and SNI SSL

Igor Sysoev October 09, 2009 03:18PM

Re: Issue with VirtualHost definition order and SNI SSL

Linmiao Xu October 09, 2009 08:50PM

Re: Issue with VirtualHost definition order and SNI SSL

Igor Sysoev October 19, 2009 06:14AM

Re: Issue with VirtualHost definition order and SNI SSL

ianchov October 22, 2009 09:30AM

Re: Issue with VirtualHost definition order and SNI SSL

Igor Sysoev October 27, 2009 01:54AM

Re: Issue with VirtualHost definition order and SNI SSL

ianchov October 27, 2009 02:26AM

Re: Issue with VirtualHost definition order and SNI SSL

Igor Sysoev October 27, 2009 03:28AM

Re: Issue with VirtualHost definition order and SNI SSL

Iantcho Vassilev October 27, 2009 07:00AM

Re: Issue with VirtualHost definition order and SNI SSL

Igor Sysoev October 27, 2009 12:30PM

Re: Issue with VirtualHost definition order and SNI SSL

Iantcho Vassilev October 27, 2009 01:50PM

Re: Issue with VirtualHost definition order and SNI SSL

Igor Sysoev October 27, 2009 03:48PM

Re: Issue with VirtualHost definition order and SNI SSL

Iantcho Vassilev October 28, 2009 03:36AM

Re: Issue with VirtualHost definition order and SNI SSL

Igor Sysoev October 28, 2009 04:30AM

Re: Issue with VirtualHost definition order and SNI SSL

Iantcho Vassilev October 28, 2009 06:10PM

Re: Issue with VirtualHost definition order and SNI SSL

Igor Sysoev October 29, 2009 03:02AM

Re: Issue with VirtualHost definition order and SNI SSL

Iantcho Vassilev October 29, 2009 03:40AM

Re: Issue with VirtualHost definition order and SNI SSL

Igor Sysoev October 29, 2009 04:14AM

Re: Issue with VirtualHost definition order and SNI SSL

Iantcho Vassilev October 29, 2009 04:38AM

Re: Issue with VirtualHost definition order and SNI SSL

Igor Sysoev October 29, 2009 04:48AM

Re: Issue with VirtualHost definition order and SNI SSL

ianchov October 27, 2009 02:30AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 90
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready