Bug#907631: [Pkg-openssl-devel] Bug#907631: Problème de connexion avec OpenSSL v1.1.1~~pre9-1 / connection problem with OpenSSL v1.1.1~~pre9-1

2018-10-29 Thread David BERCOT
Hi,

I have the same problem with 1.1.1.2 but the workaround is OK.
I have to update to TLS 1.2.

Thank you.

David.

Le 28/10/2018 à 15:08, Sebastian Andrzej Siewior a écrit :
> On 2018-08-30 13:35:27 [+0200], David BERCOT wrote:
>> With OpenSSL vv1.1.1~~pre9-1, I can't connect to my entreprise network 
>> (Wifi, PEAP\MSCHAPv2).
>>
>> The connection attempt arrives at the Radius server but, obviously, the 
>> exchange is "disturbed" and raises the following error:
>> wlp60s0: deauthenticating from c0:62:6b:e4:c4:e1 by local choice (Reason: 
>> 3=DEAUTH_LEAVING)
>>
>> If I come back to OpenSSL v1.1.0h-4 (from testing), everything returns in 
>> order.
>>
>> So, I've added a pinning to keep the testing version of OpenSSL.
> 
> I'm sorry, this slipped my mind. Could you please try using `iwd'
> instead of wpa_supplicant and reporting if this works or not?.
> 
> As a workaround with wpa_supplicant you could try
>   https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=912067#20
> 
> and please let the remote side know to update their radius server.
> 
>> David BERCOT.
> 
> Sebastian



Bug#907631: [Pkg-openssl-devel] Bug#907631: Problème de connexion avec OpenSSL v1.1.1~~pre9-1 / connection problem with OpenSSL v1.1.1~~pre9-1

2018-10-28 Thread Sebastian Andrzej Siewior
On 2018-08-30 13:35:27 [+0200], David BERCOT wrote:
> With OpenSSL vv1.1.1~~pre9-1, I can't connect to my entreprise network (Wifi, 
> PEAP\MSCHAPv2).
> 
> The connection attempt arrives at the Radius server but, obviously, the 
> exchange is "disturbed" and raises the following error:
> wlp60s0: deauthenticating from c0:62:6b:e4:c4:e1 by local choice (Reason: 
> 3=DEAUTH_LEAVING)
> 
> If I come back to OpenSSL v1.1.0h-4 (from testing), everything returns in 
> order.
> 
> So, I've added a pinning to keep the testing version of OpenSSL.

I'm sorry, this slipped my mind. Could you please try using `iwd'
instead of wpa_supplicant and reporting if this works or not?.

As a workaround with wpa_supplicant you could try
  https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=912067#20

and please let the remote side know to update their radius server.

> David BERCOT.

Sebastian