Re: FF52 beta send SSL record layer with min=1 and max=3or4

2017-02-21 Thread Eric Rescorla via dev-security-policy
This was filed as: https://bugzilla.mozilla.org/show_bug.cgi?id=1341375 For those following at home: 1. This is conformant behavior, though apparently it makes some servers sad. 2. I can't repro it in FF 52, so I'm going to need more detail to work on it -Ekr On Tue, Feb 21, 2017 at 8:10 AM,

FF52 beta send SSL record layer with min=1 and max=3or4

2017-02-21 Thread Nick Lamb via dev-security-policy
Richard's advice is worth following. m.d.s.policy is not about bugs in web servers on the whole (and that's what you've got here most likely) However, a quick Google suggests that "SSL record layer" is a term one popular tool uses to describe any SSL or TLS Hello message that goes unanswered,

Re: FF52 beta send SSL record layer with min=1 and max=3or4

2017-02-21 Thread Richard Barnes via dev-security-policy
Hi Phil, Sorry to redirect again, but this mailing list probably isn't the right place either (it's mainly about certificates, not TLS). The best thing to do is probably to file a bug on this. That will get the attention of the folks who can diagnose and fix this issue.

FF52 beta send SSL record layer with min=1 and max=3or4

2017-02-21 Thread Phil Raptor via dev-security-policy
Hello Experts, We have a server that supports TLS1.0/1.1/1.2 and restricts SSL. FF 52 beta's tls config is min=1 and max=4 by default. Upon trying to access our server with FF 52, we are getting the below error - Secure Connection Failed The connection to xx.xx.xx.xx was interrupted while the