What
version of OpenSSL are you using ?
I have
experienced problems with OpenSSL 0.9.5a but having back stepped to OpenSSL
0.9.4 my problems have gone, despite this solving the problem it appears to step
from a Microsoft Bug ...
See
Knowledge Base Q247367
This
problem however is not restricted to 128bit Certificates as the problem occured
before I upgraded to a 128bit Cert.
I to
would be interested in any further information regarding this
problem.
Regards,
Phil
Ellett,
Cyberspace Web Services / Technimode /
BritishInformation.com
-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Asser Moustafa
Sent: 05 June 2000 16:19
To: [EMAIL PROTECTED]
Subject: Apache+mod_ssl+openssl and different versions of IE...Yello!I am running an Apache+mod_ssl+openssl webserver that uses a Verisign Global ID (128 bit/128 bit secret key). Some Internet Explorer users with low cipher strengths (i.e. 40 bit or 56 bit) are having trouble using the secured version of the website. Internet Explorer displays the "friendly" error page that states the web page cannot be viewed. Once the user downloads the high encryption pack from Microsoft's website, however, they can view the secured version of the website to their heart's content. According to what I have read in several places, Apache and the browser are suppose to negotiate the cipher strength (referred to as Server Gated Cruptography by Microsoft or "stepping up" by Netscape), but I view the Apache logs and no such negotiation takes place. I have Apache setup to allow all forms of cipher strengths with the SSLCipherSuite directive.Any help or guesses anyone might be able to provide would be greatly appreciated. I have also posted this email and any responses received to deja.com.Thanks in advance,Asser
