>From: [email protected] On Behalf Of Dongcai Shen / Xiaoli
Shen
>Sent: Thursday, 04 October, 2012 04:57
>I am a newbie of using openssl and would like to seek help from you.
>Thank you very much.
>A common error message printed out by openssl is:
>140770FC:SSL routines:SSL23_GET_SERVER_HELLO:unknown protocol
(Well, common if you try to start SSL/TLS handshake with something
that isn't actually an SSL/TLS server. <G>)
>"SSL23_GET_SERVER_HELLO" indicates the function name: (in fact,
>in lower case) ssl23_get_server_hello.
>But how can openssl know the string of capitalized function name?
>I look into openssl's source code and actually there is no constant
>string "SSL23_GET_SERVER_HELLO".
>It seems mysterious. I guess I am missing a C feature.
>Can anyone help me or give me some hints about how it actually works?
>Many thanks.
Look again. Try ssl/ssl_err.c .
Error strings are mapped by the ERR_* module in crypto/err/.
Each module exports a routine that loads its strings into ERR_:
ERR_load_PEM_strings for PEM, ERR_load_SSL_strings for ssl, etc.
The ERR module also provides ERR_load_crypto_strings which loads
all of the modules in libcrypto (which excludes SSL), and the SSL
module has SSL_load_error_strings which does libcrypto plus SSL.
People generally use one of the latter two for convenience.
The actual error codes in the error queue are numeric bitfields,
set using #define's like SSL_F_blah and SSL_R_blah.
ERR_{lib,func,reason_}error_string maps them to the loaded strings,
and ERR_print_errors or similar outputs the results.
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List [email protected]
Automated List Manager [email protected]