Re: OpenSSL reports wrong TLS version to FreeRADIUS

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi,

I'd like to understand, how does OpenSSL get to the idea of "0304" version, if there is no such a
byte sequence in the packet...
My question is: how OpenSSL determines the TLS version? How to debug it?

I don't see any TLS 1.3 in the capture as well, but I see that your client is using only outdated (if not to say: historic) cryptographic algorithms: RC4, RC2 (never seen that in practice!), 3DES and DES. And those even combined with export options to weaken key strength. Many modern servers are configured to disallow such outdated crypto: make your client use at least

- AES128/256 (either in CBC or GCM mode)
- TLS 1.2
- no export cipher suites

Then you might get a more positive reply from the server...

Best regards

Alfred Arnold

--
Alfred Arnold                   E-Mail: alfred@xxxxxxxxxxxxxxxxxxx
Computer Club at the            http://john.ccac.rwth-aachen.de:8000/alf/
Technical University            Phone: +49-241-406526
of Aachen




[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux