Ok, I managed to work around the problem by installing Win2k SP4 on the server. When I ssldump the session now, I see that the selected ciphersuite is now DES-CBC3-SHA instead of EXP1024-DES-CBC-SHA.
I still wonder: was the selection of EXP1024-DES-CBC-SHA by the server illegal? i.e. is it an implementation problem in the server or is openssl too selective about the server certificate? Tal. ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]
