Apache SSL3_ACCEPT:unsafe legacy renegotiation disabled?

2010-04-01 Thread Jason Haar
Hi there We have a CentOS-4.8 server that was upgraded to httpd-2.0.52-41.ent.7.centos4 this week - along with dependencies like openssl-0.9.7a and openssl096b At that moment our client-certificate based authentication Webapp broke :-( It's really weird. Users running Firefox-3.5+ or Chrome are

RE: Apache SSL3_ACCEPT:unsafe legacy renegotiation disabled?

2010-04-01 Thread Saju Paul
OptRenegotiate - enables avoidance of unnecessary handshakes by mod_ssl which also performs safe parameter checks. It is recommended to enable OptRenegotiate on a per directory basis. also performs safe parameter checks maybe the key. disable it and check if MSIE likes it. -Original

Re: Apache SSL3_ACCEPT:unsafe legacy renegotiation disabled?

2010-04-01 Thread Chris Clark
On Thu, Apr 1, 2010 at 3:11 AM, Jason Haar jason.h...@trimble.co.nz wrote: Hi there We have a CentOS-4.8 server that was upgraded to httpd-2.0.52-41.ent.7.centos4 this week - You need to upgrade Apache to httpd-2.2.15 (released March 6, 2010) Your version is years old. -Chris

Re: Apache SSL3_ACCEPT:unsafe legacy renegotiation disabled?

2010-04-01 Thread Jason Haar
On 04/01/2010 11:50 PM, Saju Paul wrote: OptRenegotiate - enables avoidance of unnecessary handshakes by mod_ssl which also performs safe parameter checks. It is recommended to enable OptRenegotiate on a per directory basis. also performs safe parameter checks maybe the key. disable it and

Re: Apache SSL3_ACCEPT:unsafe legacy renegotiation disabled?

2010-04-01 Thread Jason Haar
On 04/02/2010 02:21 AM, Chris Clark wrote: You need to upgrade Apache to httpd-2.2.15 (released March 6, 2010) Your version is years old. It is the official version released for CentOS-4.8 this week (which actually means Redhat too). It wouldn't surprise me if they never tested the client

Re: handshake failure / SSL3_GET_CLIENT_HELLO:no shared cipher s3_srvr

2010-04-01 Thread Konrads Smelkovs
Make sure that the client and the server can use same suite of ciphers. -- Konrads Smelkovs Applied IT sorcery. On Thu, Apr 1, 2010 at 3:34 PM, Götz Reinicke - IT-Koordinator goetz.reini...@filmakademie.de wrote: Hi, this drives my crazy for about two days: I do have two virtual Red Hat

Re: handshake failure / SSL3_GET_CLIENT_HELLO:no shared cipher s3_srvr

2010-04-01 Thread Götz Reinicke - IT Koordinator
Hi, how do I check this? On both servers I do have installed the same client and server software and performing a secured connection from both systems to the master server works; from both systems to the slave server fails. Regards, Götz Am 01.04.10 21:57, schrieb Konrads Smelkovs:

Re: handshake failure / SSL3_GET_CLIENT_HELLO:no shared cipher s3_srvr

2010-04-01 Thread Victor Duchovni
On Thu, Apr 01, 2010 at 10:48:56PM +0200, G??tz Reinicke - IT Koordinator wrote: Hi, how do I check this? On both servers I do have installed the same client and server software and performing a secured connection from both systems to the master server works; from both systems to the

Re: Apache SSL3_ACCEPT:unsafe legacy renegotiation disabled?

2010-04-01 Thread Jason Haar
On 04/02/2010 08:13 AM, Jason Haar wrote: On 04/02/2010 02:21 AM, Chris Clark wrote: You need to upgrade Apache to httpd-2.2.15 (released March 6, 2010) Your version is years old. OK, this is getting weird... I just created the same directory structure on a CentOS-5.3 server

Re: Apache SSL3_ACCEPT:unsafe legacy renegotiation disabled? [ANSWER]

2010-04-01 Thread Jason Haar
I found a fix. I'll be verbose to make this better for search engines :-) So after upgrading to httpd-2.0.52-41.ent.7.centos4 under CentOS-4.8 and/or httpd-2.2.3-31.el5.centos.4 under CentOS-5.3 our client-cert based authentication started failing for all versions of MSIE (Internet Explorer)

Invitation to connect on LinkedIn

2010-04-01 Thread Andre castanheira
LinkedIn Andre castanheira requested to add you as a connection on LinkedIn: -- Mark, I'd like to add you to my professional network on LinkedIn. - Andre Accept invitation from Andre castanheira