On Thu, Apr 03, 2014 at 02:33:17PM +0300, Costas Stasimos wrote:
[ I think this thread belongs on openss-users, not openssl-dev, setting
Reply-To: accordingly. ]
> I use openssl-1.0.1e in a debian system and i try to make some scenarios
> with TLSv1.2 using the applications s_server and s_client.
> >>> TLS 1.2 Alert [length 0002], fatal bad_record_mac
> 02 14
> ERROR
> 1208113256:error:1408F119:SSL routines:SSL3_GET_RECORD:decryption failed or
> bad record mac:s3_pkt.c:484:
> shutting down SSL
>
Have you tried 1.0.1f? Are you using the latest Debian package?
Are these Intel machines with AES-NI support? What happens if
you try CAMELLIA? There was a fix for AES-NI in 1.0.1f IIRC.
http://archives.neohapsis.com/archives/postfix/2014-03/0027.html
--
Viktor.
______________________________________________________________________
OpenSSL Project http://www.openssl.org
Development Mailing List [email protected]
Automated List Manager [email protected]