Hiya Jim Thanks for the reply.
> If not already included, you could include %{SSL_PROTOCOL}x %{SSL_CIPHER}x in your request log and see if there is any commonality in requests assuming the communication is open long enough for the logging to occur or if the client's desired protocol and cipher might get listed.
Yeah we actually already have that enabled in our access logs and we can see that the clients in question are using TLS1.2 when successful (i.e. on the next connection). However these connections that result in the plaintext response actually aren't logged in either the access or error log at all.
However we can see from the packet captures that they are a TLS 1.2 handshake and everything "looks fine" there when compared to a successful handshake.
Thanks Rob -- --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscr...@httpd.apache.org For additional commands, e-mail: users-h...@httpd.apache.org