SSL handshake problems with xmlsectool
Wessel, Keith William
kwessel at illinois.edu
Wed Oct 17 16:00:50 EDT 2012
Scott, Peter,
First, sorry, I didn't mean ciphers! I meant SSL protocols. Oops.
Yes, what was turned off includes TLS. From our httpd.conf:
SSLProtocol All -SSLv2 -TLSv1
Pretty much leaves SSLv3.
Answering Peter's question, I'm trying to pull in metadata from one of our servers via https and the --inUrl parameter to xmlsectool. It's unsigned metadata that I want to consume, validate, sign, and write out to another file, in short.
Kinda hard if I can't even get it to come in.
Does tha explain my problem a bit better?
Should xmlsectool be trying SSLv3? In other words, is something else to blame here?
Keith
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Tuesday, October 16, 2012 11:58 AM
To: Shib Users
Subject: Re: SSL handshake problems with xmlsectool
On 10/16/12 12:13 PM, "Wessel, Keith William" <kwessel at illinois.edu> wrote:
>Our admins recently made a change to our Apache SSL cipher suite
>configuration to only support SSLv3.
I can't imagine that would be a change. Does that include TLS also?
>
>Now, xmlsectool¹s unhappy with SSL handshaking:
I can't imagine they'd change the suites such that Java's client would stop connecting. Something must be off in what they did.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list