|
Phil, Thanks for
your help. I am going to require
users to download the high encryption pack for IE if they wish to use the
secured version of the website. Thanks
again, Asser -----Original
Message----- What version of OpenSSL
are you using ? I have experienced
problems with OpenSSL 0.9.5a but having back stepped to OpenSSL 0.9.4 my
problems have gone, despite this solving the problem it appears to step from a
Microsoft Bug ... See Knowledge Base
Q247367 http://support.microsoft.com/support/kb/articles/Q247/3/67.ASP?LN=EN-US&SD=gn&FR=0 This problem however is
not restricted to 128bit Certificates as the problem occured before I upgraded
to a 128bit Cert. I to would be interested
in any further information regarding this problem. Regards, Phil Ellett, Cyberspace Web Services /
Technimode / BritishInformation.com http://www.britishinformation.com/bclick.php3?BI0999 -----Original Message----- Yello! I am running an Apache+mod_ssl+openssl webserver that uses a Verisign
Global ID (128 bit/128 bit secret key). Some Internet Explorer users with low cipher strengths
(i.e. 40 bit or 56 bit) are having trouble using the secured version of the
website. Internet Explorer displays the "friendly" error page
that states the web page cannot be viewed. Once the user downloads the
high encryption pack from Microsoft's website, however, they can view the
secured version of the website to their heart's content. According to what I have read in
several places, Apache and the browser are suppose to negotiate the cipher
strength (referred to as Server Gated Cruptography by Microsoft or "stepping up"
by Netscape), but I view the Apache logs and no such negotiation takes
place. I have Apache setup to allow all forms of cipher strengths with
the SSLCipherSuite directive. Any help
or guesses anyone might be able to provide would be greatly appreciated. I have also posted this email and any
responses received to deja.com. Thanks in advance, Asser |
- RE: Apache+mod_ssl+openssl and different versions of IE... Phil Ellett
- Asser Moustafa
