On Thu, Apr 03, 2014 at 02:33:17PM +0300, Costas Stasimos wrote: [ I think this thread belongs on openss-users, not openssl-dev, setting Reply-To: accordingly. ]
> I use openssl-1.0.1e in a debian system and i try to make some scenarios > with TLSv1.2 using the applications s_server and s_client. > >>> TLS 1.2 Alert [length 0002], fatal bad_record_mac > 02 14 > ERROR > 1208113256:error:1408F119:SSL routines:SSL3_GET_RECORD:decryption failed or > bad record mac:s3_pkt.c:484: > shutting down SSL > Have you tried 1.0.1f? Are you using the latest Debian package? Are these Intel machines with AES-NI support? What happens if you try CAMELLIA? There was a fix for AES-NI in 1.0.1f IIRC. http://archives.neohapsis.com/archives/postfix/2014-03/0027.html -- Viktor. ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager majord...@openssl.org