One way to distinguish between the two is to use openSSL's BIO_pairs. The
idea is to separate the SSL data en/decryption and the transport, so
whatever goes down (the transport or the ssl) you can easily diffrentiate,
and using BIO_pairs will let you use OpenSSL for the SSL part and then you
can the trasport of data part whichever way you want.
Hope this helps,
Regards,
Usman.
From: "Prabhu.S" <[EMAIL PROTECTED]>
Reply-To: [email protected]
To: [email protected]
Subject: TCP socket persistence and SSL Connect
Date: Fri, 19 Jan 2007 20:21:29 +0530
MIME-Version: 1.0
X-Sender: "Prabhu.S" <[EMAIL PROTECTED]>
Received: from mmx1.engelschall.com ([195.30.6.154]) by
bay0-mc8-f1.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.2444); Fri, 19
Jan 2007 06:55:11 -0800
Received: by mmx1.engelschall.com (Postfix)id C4ED256428; Fri, 19 Jan 2007
15:53:18 +0100 (CET)
Received: from master.openssl.org (master.openssl.org [195.30.6.166])by
mmx1.engelschall.com (Postfix) with ESMTP id A46B15641Afor
<[EMAIL PROTECTED]>; Fri, 19 Jan 2007 15:53:18 +0100
(CET)
Received: by master.openssl.org (Postfix)id 83ACE1AC6222; Fri, 19 Jan 2007
15:53:18 +0100 (CET)
Received: by master.openssl.org (Postfix, from userid 29101)id
7F4631AC6200; Fri, 19 Jan 2007 15:53:18 +0100 (CET)
Received: from basura.san2.attens.com (basura.san2.attens.net
[192.215.81.86])by master.openssl.org (Postfix) with ESMTP id
610011AC6050for <[email protected]>; Fri, 19 Jan 2007 15:53:05
+0100 (CET)
Received: from relay1.nyc2.attens.net (relay1.nyc2.attens.net
[63.240.1.42])by basura.san2.attens.com (8.13.1/8.13.6) with ESMTP id
l0JEqafi023763for <[email protected]>; Fri, 19 Jan 2007 14:52:37
GMT
Received: from mailhub.masconit.com (email.masconit.com [12.107.104.100])by
relay1.nyc2.attens.net (8.13.6/8.13.6) with ESMTP id l0JEqM4A007738for
<[email protected]>; Fri, 19 Jan 2007 14:52:23 GMT
Received: by MAILHUB with Internet Mail Service (5.5.2653.19)id <D131CK00>;
Fri, 19 Jan 2007 08:52:01 -0600
Received: from prabhus (61.95.163.2 [61.95.163.2]) by mailhub.masconit.com
with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2653.13)id
D131CK0D; Fri, 19 Jan 2007 08:51:50 -0600
X-Message-Info: txF49lGdW41r1VBA/DqqHr6CvyxubbaGblPOqmtM/nQ=
Delivered-To: [email protected]
X-Original-To: [email protected]
Delivered-To: [email protected]
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1506
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1506
Precedence: bulk
X-List-Manager: OpenSSL Majordomo [version 1.94.5]
X-List-Name: openssl-users
Return-Path: [EMAIL PROTECTED]
X-OriginalArrivalTime: 19 Jan 2007 14:55:11.0794 (UTC)
FILETIME=[D1D8D920:01C73BD9]
Hi All:
I have a SSL client and a server application.The client connects to a
SSL server in a TCP socket persistence mode, i.e, it does a data
exchange with the server through a SSL connection , tears down the SSL
connection but again sends out a client_hello in the same TCP socket
connection it had earlier established with the server to perform another
cycle of data exchange.
But consider the case where the server is not running in a persistent
mode but my client is. After the first cycle of data exchange the server
closes the SSL connection as well as the underlying TCP. When the client
in persistent mode tries for the second cycle of data exchange, it
tries SSL_connect(ssl) in the broken TCP socket connection .
SSL_get_error method returns SSL_ERROR_SSL. And SSL_get_error method
returns SSL_ERROR_SSL even for SSL handshake failures such as cipher
suite mismatch between client and server. As such the client application
is not able to distinguish between the SSL handshake failure(cipher
suite mismatch) in valid TCP connection and loss of TCP connection with
the server in the first place.
Is their any way to make out for broken TCP connection, so that the
client can create socket and connect to server for next round of data
exchange.
Thanks and Regards,
Prabhu. S
_________________________________________________________________
Express yourself instantly with MSN Messenger! Download today it's FREE!
http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List [email protected]
Automated List Manager [EMAIL PROTECTED]