Ok, I managed to work around the problem by installing Win2k SP4 on the 
server. When I ssldump the session now, I see that the selected 
ciphersuite is now DES-CBC3-SHA instead of EXP1024-DES-CBC-SHA.

I still wonder: was the selection of EXP1024-DES-CBC-SHA by the server 
illegal? i.e. is it an implementation problem in the server or is 
openssl too selective about the server certificate?

Tal.
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to