On Fri, Dec 27, 2013 at 04:11:40PM -0600, Bobber wrote:

> > > TLS started w/ cipher DES-CBC3-SHA
> >
> >There's your problem!  This server (likely Exchange 2003) has a
> >broken implementation of 3DES CBC padding (search Postfix users
> >archives for my posts on the subject), and your cipher list is
> >either long enough to cause it to not see RC4-SHA and RC4-MD5 or
> >you've disabled RC4 (directly, or by only enabling HIGH grade
> >ciphers).
>
> Does Micro$oft have a fix for this?

They did, in 2007, but the software in question is no longer
supported and AFAIK the hotfix is no longer available.  The domain
in question is running "abandon-ware".

-- 
        Viktor.
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           majord...@openssl.org

Reply via email to