Hi  Charles,

I was under the assumption that I can turn of protocols using this options. 
Since I wanted to give a try, without turning off any protocol, did not give 
attention towards this call. Let me give a try.

Thank you
Jaya
From: owner-openssl-us...@openssl.org [mailto:owner-openssl-us...@openssl.org] 
On Behalf Of Charles Mills
Sent: Monday, October 29, 2012 8:47 PM
To: openssl-users@openssl.org
Subject: RE: Need inputs/suggestions on SSL/TLS protocol version fallback 
mechanism.

You should at least look into it. I am not sure what the defaults are without 
looking at the docs. Try setting SSL_OP_ALL (sounds good to me) | 
SSL_OP_NO_SSLv2 (SSL v2 is considered to be badly flawed). That should (IIRC) 
leave you able to accept SSL v3, TLS v1, and TLS v1.1.

Charles
From: owner-openssl-us...@openssl.org<mailto:owner-openssl-us...@openssl.org> 
[mailto:owner-openssl-us...@openssl.org]<mailto:[mailto:owner-openssl-us...@openssl.org]>
 On Behalf Of Bhat, Jayalakshmi Manjunath
Sent: Monday, October 29, 2012 7:28 AM
To: openssl-users@openssl.org<mailto:openssl-users@openssl.org>
Subject: RE: Need inputs/suggestions on SSL/TLS protocol version fallback 
mechanism.

Hi Charles,

Thank you for the reply.  I am not setting any option using 
SSL_CTX_set_options, should I indicate protocols using this function?.

Regards
Jaya
From: owner-openssl-us...@openssl.org<mailto:owner-openssl-us...@openssl.org> 
[mailto:owner-openssl-us...@openssl.org] On Behalf Of Charles Mills
Sent: Monday, October 29, 2012 7:40 PM
To: openssl-users@openssl.org<mailto:openssl-users@openssl.org>
Subject: RE: Need inputs/suggestions on SSL/TLS protocol version fallback 
mechanism.

Do you call SSL_CTX_set_options() with bit flags (SSL_OP_ALL, SSL_OP_NO_SSLv3, 
etc.) to indicate the protocols you are willing to accept?

BTW, openssl-users (not -dev) is the proper forum for this sort of questions.

Charles
From: owner-openssl-us...@openssl.org<mailto:owner-openssl-us...@openssl.org> 
[mailto:owner-openssl-us...@openssl.org]<mailto:[mailto:owner-openssl-us...@openssl.org]>
 On Behalf Of Bhat, Jayalakshmi Manjunath
Sent: Monday, October 29, 2012 5:27 AM
To: openssl-...@openssl.org<mailto:openssl-...@openssl.org>; 
openssl-users@openssl.org<mailto:openssl-users@openssl.org>
Subject: Need inputs/suggestions on SSL/TLS protocol version fallback mechanism.

Hi All,

I have a client application that uses SSL23_client_method(). When the client is 
getting connected to server that supports TLS 1.0 there are no issues. When the 
client is getting connected to server that supports only SSLv3.0, connection is 
getting aborted with protocol number error.

I have couple of question around this issue.


1.       If I like to support the fallback mechanism,  I need to implement the 
same in the client application. SSL client state machine in OpenSSL does not 
implement any fallback.

2.       I did not see any recommendation in SSL/TLS RFC to implement the 
fallback mechanism. I wanted to know are there any side effects in OpenSSL 
library if fallback mechanism is implemented.

Reply via email to