Hello,
I have installed the Apache server SSL-enabled and I've got errors in handshake
I have tested the server with the openssl s_client command
 
The following output shows the error
 
> openssl s_client -connect localhost:443
CONNECTED(00000003)
depth=0 /C=IT/ST=Italia/L=Palermo/O=Italtel/OU=Tpd/CN=IPAHU016/Email=resolver@IP
AHU016
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 /C=IT/ST=Italia/L=Palermo/O=Italtel/OU=Tpd/CN=IPAHU016/Email=resolver@IP
AHU016
verify error:num=27:certificate not trusted
verify return:1
depth=0 /C=IT/ST=Italia/L=Palermo/O=Italtel/OU=Tpd/CN=IPAHU016/Email=resolver@IP
AHU016
verify error:num=21:unable to verify the first certificate
verify return:1
24479:error:1409441A:SSL routines:SSL3_READ_BYTES:tlsv1 alert decode error:s3_pkt.c:956:SSL alert number 50
24479:error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure:s23_lib.c:216:
 
The following is the corresponding ssl_engine_log (trace level)
 
04/Dec/2001 11:18:22 23423] [info]  Connection to child 0 established (server I
PAHU016:443, client 127.0.0.1)
[04/Dec/2001 11:18:22 23423] [info]  Seeding PRNG with 0 bytes of entropy
[04/Dec/2001 11:18:22 23423] [trace] OpenSSL: Handshake: start
[04/Dec/2001 11:18:22 23423] [trace] OpenSSL: Loop: before/accept initialization
[04/Dec/2001 11:18:22 23423] [trace] OpenSSL: Loop: SSLv3 read client hello A
[04/Dec/2001 11:18:22 23423] [trace] OpenSSL: Loop: SSLv3 write server hello A
[04/Dec/2001 11:18:22 23423] [trace] OpenSSL: Loop: SSLv3 write certificate A
[04/Dec/2001 11:18:22 23423] [trace] OpenSSL: Loop: SSLv3 write server done A
[04/Dec/2001 11:18:22 23423] [trace] OpenSSL: Loop: SSLv3 flush data
[04/Dec/2001 11:18:22 23423] [trace] OpenSSL: Write: SSLv3 read client key excha
nge A
[04/Dec/2001 11:18:22 23423] [trace] OpenSSL: Exit: error in SSLv3 read client k
ey exchange A
[04/Dec/2001 11:18:22 23423] [trace] OpenSSL: Exit: error in SSLv3 read client k
ey exchange A
[04/Dec/2001 11:18:22 23423] [error] SSL handshake failed (server IPAHU016:443,
client 127.0.0.1) (OpenSSL library error follows)
[04/Dec/2001 11:18:22 23423] [error] OpenSSL: error:2706D212::lib(39) :func(109)
 :reason(530)
[04/Dec/2001 11:18:22 23423] [error] OpenSSL: error:1408B076:SSL routines:SSL3_G
ET_CLIENT_KEY_EXCHANGE:bad rsa decrypt
 
I have installed the server on HP-UX 11.00 host. The version of Apache is 1.3.19
The version of mod_ssl is 2.8.3-1.3.19
The version of OpenSSL is 0.9.5a 1 Apr 2000
 
Thanks for your help
 
Dario Prester
P&T-TPD PA
ITALTEL SPA
Localit� Bivio Foresta  SS. 113
Carini (PA) - ITALY
tel. +39 091 8615 577
fax. +39 091 8615 288
e-mail: [EMAIL PROTECTED]
 

Reply via email to