What version of OpenSSL are you using ?
 
 
I have experienced problems with OpenSSL 0.9.5a but having back stepped to OpenSSL 0.9.4 my problems have gone, despite this solving the problem it appears to step from a Microsoft Bug ...
 
See Knowledge Base Q247367
 
http://support.microsoft.com/support/kb/articles/Q247/3/67.ASP?LN=EN-US&SD=gn&FR=0
 
This problem however is not restricted to 128bit Certificates as the problem occured before I upgraded to a 128bit Cert.
 
I to would be interested in any further information regarding this problem.
 
Regards,
 
Phil Ellett,
 
Cyberspace Web Services / Technimode / BritishInformation.com
 
http://www.britishinformation.com/bclick.php3?BI0999
 
-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Asser Moustafa
Sent: 05 June 2000 16:19
To: [EMAIL PROTECTED]
Subject: Apache+mod_ssl+openssl and different versions of IE...

Yello!
 
I am running an Apache+mod_ssl+openssl webserver that uses a Verisign Global ID (128 bit/128 bit secret key).  Some Internet Explorer users with low cipher strengths (i.e. 40 bit or 56 bit) are having trouble using the secured version of the website.  Internet Explorer displays the "friendly" error page that states the web page cannot be viewed.  Once the user downloads the high encryption pack from Microsoft's website, however, they can view the secured version of the website to their heart's content.  According to what I have read in several places, Apache and the browser are suppose to negotiate the cipher strength (referred to as Server Gated Cruptography by Microsoft or "stepping up" by Netscape), but I view the Apache logs and no such negotiation takes place.  I have Apache setup to allow all forms of cipher strengths with the SSLCipherSuite directive.
 
Any help or guesses anyone might be able to provide would be greatly appreciated.  I have also posted this email and any responses received to deja.com.
 
Thanks in advance,
Asser

Reply via email to