> > > With "export NSS_DISABLE_HW_AES=1" there are no crashes.
> > > 
> > 
> Hello,
> 
> the certificate is there (in the "-----BEGIN CERTIFICATE-----")
> section, I just edited it. Here is the certificate without some
> internal information like the DN:
> 

Ahhh okay. I see what happened now. 

> 
> I have tried
> openssl s_client -connect ldap:636 -tls1_2 - it crashes the server
> -tls1 / -tls1_1 is OK
> 

The server is crashing before it can complete the negotiation which is
why there is the weird openssl s_client output.


So I think that Noriko is onto the correct work around here. I would
advise that you leave NSS_DISABLE_HW_GCM=1 set to prevent the crash.



-- 
Sincerely,

William Brown
Software Engineer
Red Hat, Brisbane

Attachment: signature.asc
Description: This is a digitally signed message part

--
389 users mailing list
389-users@%(host_name)s
http://lists.fedoraproject.org/admin/lists/389-users@lists.fedoraproject.org

Reply via email to