On Thu, Apr 03, 2014 at 02:33:17PM +0300, Costas Stasimos wrote:

[ I think this thread belongs on openss-users, not openssl-dev, setting
  Reply-To: accordingly. ]

> I use openssl-1.0.1e in a debian system and i try to make some scenarios
> with TLSv1.2 using the applications s_server and s_client.

> >>> TLS 1.2 Alert [length 0002], fatal bad_record_mac
>     02 14
> ERROR
> 1208113256:error:1408F119:SSL routines:SSL3_GET_RECORD:decryption failed or
> bad record mac:s3_pkt.c:484:
> shutting down SSL
> 

Have you tried 1.0.1f?  Are you using the latest Debian package?
Are these Intel machines with AES-NI support?  What happens if
you try CAMELLIA?  There was a fix for AES-NI in 1.0.1f IIRC.

    http://archives.neohapsis.com/archives/postfix/2014-03/0027.html

-- 
        Viktor.
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       openssl-dev@openssl.org
Automated List Manager                           majord...@openssl.org

Reply via email to