Tryton 4.4 client on Windows refusing to use SSL

80 views
Skip to first unread message

Mark Shane Hayden

unread,
Jun 15, 2017, 1:42:20 AM6/15/17
to tryton
I am having a peculiar problem with the windows desktop client since upgrading our dev system to 4.4.

I can connect fine with my Debian machine however my colleague cannot connect on his Windows machine.  Upon further investigation it appears that his machine immediately sends HTTP to the server upon connecting and the server is configured to reject unencrypted connections to port 8000 (returns HTTP 400 unless it is encrypted). I even tried making the server send a 307 redirect to https but the Windows client ignores it.

Is this a new bug? Something we overlooked on client setup for Windows? Is there still no way to force the client to never attempt insecure connections?

Thanks in advance...

Cédric Krier

unread,
Jun 15, 2017, 4:10:08 AM6/15/17
to tryton
You have to clean the known_hosts configuration:
http://doc.tryton.org/4.4/tryton/doc/usage.html#configuration-file

This is were the client keep track of which servers use SSL or not.

--
Cédric Krier - B2CK SPRL
Email/Jabber: cedric...@b2ck.com
Tel: +32 472 54 46 59
Website: http://www.b2ck.com/

Mark Shane Hayden

unread,
Jun 15, 2017, 3:50:51 PM6/15/17
to tryton
Thanks for the tip, however this client had completely removed the entire contents of the configuration directory.  Is there anything else we can try--perhaps it is cached somewhere and Windows needs to be restarted? Logs indicate it doesn't even attempt SSL...

Cédric Krier

unread,
Jun 15, 2017, 4:15:07 PM6/15/17
to tryton
On 2017-06-15 12:50, Mark Shane Hayden wrote:
> Thanks for the tip, however this client had completely removed the entire
> contents of the configuration directory. Is there anything else we can
> try--perhaps it is cached somewhere and Windows needs to be restarted? Logs
> indicate it doesn't even attempt SSL...

For unknown host, the client always tries first with SSL and fallback to
clear if it fails. So if the client does not try with SSL, it means that
it has a empty fingerprint for this host in its configuration.
Reply all
Reply to author
Forward
0 new messages