Please help solve problem SSL3_GET_CLIENT_HELLO:no shared cipher

2004-08-05 Thread Viacheslav N tararin
Hi,, all.
Please help me solve next problem.
Server with OpenSSL 0.9.7d can't accept pear connection. With very old 
version of OpenSSL (I think 0.9.6) work properly.
I am recompile OpenSSL with CIPHER_DEBUG flag.
So, fly on handshake server know only DES_CBC3_SHA suite, while OpenSSL 
know more suites, and clients DES_CBC_SHA too.

Thanks.
Next partial CHIPHER_DEBUG output:
skip 
Name: DES-CBC3-SHA:
Algo = 00502041 Algo_strength = 0081
Mask = 0fff Mask_strength 
ma = 0041 ma_s , maalgo=, ma_salgos=
Name: DES-CBC-SHA:
Algo = 00501041 Algo_strength = 0021
Mask = 0fff Mask_strength 
ma = 0041 ma_s , maalgo=, ma_salgos=
skip 
DHE-RSA-AES256-SHA
DHE-DSS-AES256-SHA
AES256-SHA
EDH-RSA-DES-CBC3-SHA
EDH-DSS-DES-CBC3-SHA
DES-CBC3-SHA
DHE-RSA-AES128-SHA
DHE-DSS-AES128-SHA
AES128-SHA
IDEA-CBC-SHA
DHE-DSS-RC4-SHA
RC4-SHA
RC4-MD5
EXP1024-DHE-DSS-DES-CBC-SHA
EXP1024-DES-CBC-SHA
EXP1024-RC2-CBC-MD5
EDH-RSA-DES-CBC-SHA
EDH-DSS-DES-CBC-SHA
DES-CBC-SHA
EXP1024-DHE-DSS-RC4-SHA
EXP1024-RC4-SHA
EXP1024-RC4-MD5
EXP-EDH-RSA-DES-CBC-SHA
EXP-EDH-DSS-DES-CBC-SHA
EXP-DES-CBC-SHA
EXP-RC2-CBC-MD5
EXP-RC4-MD5
skip 
Server has 1 from 01521638:
004F6B58:DES-CBC3-SHA
Client sent 2 from 01528050:
004F6B30:DES-CBC-SHA
004F6950:NULL-SHA
rt=0 rte=0 dht=1 re=1 ree=1 rs=0 ds=0 dhr=0 dhd=0
1:[0041:0251]004F6B30:DES-CBC-SHA
rt=0 rte=0 dht=1 re=1 ree=1 rs=0 ds=0 dhr=0 dhd=0
1:[0041:0251]004F6950:NULL-SHA
skip ---
__
OpenSSL Project http://www.openssl.org
User Support Mailing List[EMAIL PROTECTED]
Automated List Manager   [EMAIL PROTECTED]


Certification check.

2001-11-12 Thread Viacheslav N Tararin

Hi all,

I'm new with SSL.
I have one problem with certificate verification routines.

When I include next code in server

--
... ssl initialization ...

SSL_CTX_set_verify(*ctx,
SSL_VERIFY_PEER|SSL_VERIFY_FAIL_IF_NO_PEER_CERT|SSL_VERIFY_CLIENT_ONCE, NULL);

... continue ...
--

On handshake I've got next error:
error:140890B2:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned


On client side I perform:
SSL_CTX_use_certificate_file(*ctx, cert_file, SSL_FILETYPE_PEM);

What, I must perform additional on client side for return certificate
to server?
Any example, or guide?


Thanks.

-- 
Best regards,
 Viacheslav  mailto:[EMAIL PROTECTED]


__
OpenSSL Project http://www.openssl.org
User Support Mailing List[EMAIL PROTECTED]
Automated List Manager   [EMAIL PROTECTED]