Sergey Kandaurov
July 10, 2018 01:44PM
> On 7 Jul 2018, at 18:38, shiz <nginx-forum@forum.nginx.org> wrote:
>
> Hi,
>
> I see those messages in my error logs daily.
>
> ```
> 2018/07/07 08:01:32 [crit] 31935#31935: *342781 SSL_do_handshake() failed
> (SSL: error:14209102:SSL
> routines:tls_early_post_process_client_hello:unsupported protocol) while SSL
> handshaking, client: 173.208.91.177, server: 0.0.0.0:443
> 2018/07/07 08:06:24 [crit] 31939#31939: *343099 SSL_do_handshake() failed
> (SSL: error:1420918C:SSL
> routines:tls_early_post_process_client_hello:version too low) while SSL
> handshaking, client: 141.212.122.16, server: 0.0.0.0:443
> ```
>
> Is there a way to increase verbosity, i.e. which protocol is unsupported?
> which version is too low?
>
> Nginx 1.15.1, supporting TLSv1.2, TLSv1.3 draft 23, OpenSSL-1.1.1-pre2
>
> Not sure if it could be done within nginx, maybe OpenSSL source has to be
> edited?

This may be caused by TLSv1.3 version draft mismatch as found
in CH supported_versions. You may want to update OpenSSL.

--
Sergey Kandaurov

_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

SSL errors, verbosity level

shiz July 07, 2018 11:38AM

Re: SSL errors, verbosity level

Sergey Kandaurov July 10, 2018 01:44PM

Re: SSL errors, verbosity level

shiz July 10, 2018 02:09PM

Re: SSL errors, verbosity level

Frank Liu July 10, 2018 08:12PM

Re: SSL errors, verbosity level

shiz July 11, 2018 09:18AM

Re: SSL errors, verbosity level

Frank Liu July 11, 2018 12:24PM

Re: SSL errors, verbosity level

shiz July 11, 2018 03:03PM

Re: SSL errors, verbosity level

Richard Stanway July 13, 2018 07:16AM

Re: SSL errors, verbosity level

Frank Liu July 16, 2018 07:02PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 244
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready