Re: Sites which fail with tls 1.0

2014-02-05 Thread cloos
Brian Smith br...@briansmith.org writes: Thanks for replying. I am not sure about how SM works but I would expect it to work like Firefox in this aspect. So did I; but even with 2.24pre1 (same gecko as ff27) it does not. I'll grep thru the src for differences, and open a bugz. Understood.

Re: Sites which fail with tls 1.0

2014-02-05 Thread Brian Smith
On Wed, Feb 5, 2014 at 5:39 PM, cl...@jhcloos.com wrote: Is the retry logic in nss or in mozilla-central? And if the latter, can anyone help narrow the search? I didn't find anything relevant in comm-central. It is in mozilla-central, in security/manager/ssl/src/nsNSSIOLayer.cpp. See these

Re: Sites which fail with tls 1.0

2014-01-28 Thread Julien Vehent
On 2014-01-27 17:22, cl...@jhcloos.com wrote: In case anyone is keeping a list, while helping a relative I determined that timewarnercable.com's login server (wayfarer.timewarnercable.com) will not work with tls 1.1 or 1.2. The connection fails after the client right after the client hello.

Re: Sites which fail with tls 1.0

2014-01-28 Thread cloos
Julien Vehent jul...@linuxwall.info writes: I had to set security.tls.version.max to 1 to get ff (26) or sm (2.23) to get her (relevant) profile to log in to their site. Are you saying that the default settings were failing entirely, and you had to force tls1 for this site? I thought that

Re: Sites which fail with tls 1.0

2014-01-28 Thread Brian Smith
On Mon, Jan 27, 2014 at 2:22 PM, cl...@jhcloos.com wrote: In case anyone is keeping a list, while helping a relative I determined that timewarnercable.com's login server (wayfarer.timewarnercable.com) will not work with tls 1.1 or 1.2. The connection fails after the client right after the