[Cherokee-dev] Issue 1229 in cherokee: HTTPS connection in Chromium fallback to SSL 3.0

3 views
Skip to first unread message

cher...@googlecode.com

unread,
Jul 13, 2011, 12:31:19 AM7/13/11
to cherok...@cherokee-project.com
Status: New
Owner: ----

New issue 1229 by etienne....@gmail.com: HTTPS connection in Chromium
fallback to SSL 3.0
http://code.google.com/p/cherokee/issues/detail?id=1229

What steps will reproduce the problem?
1. Configure the server to use TLS/SSL, set the port (443), add the key &
certificate.
2. Visit a page of the site under HTTPS in Chromium.
3. Click the lock icon in the URL bar to see the site information

What is the expected output? What do you see instead?
No warning (use TLS). But I have this warning :
Your connection to 192.168.2.13 is encrypted with 256-bit encryption.

The connection uses SSL 3.0.

The connection is encrypted using AES_256_CBC, with SHA1 for message
authentication and DHE_RSA as the key exchange mechanism.

The connection is not compressed.

The connection had to be retried using SSL 3.0. This typically means that
the server is using very old software and may have other security issues.


What version of the product are you using? On what operating system?
0.99.39 AND 1.2.98 on Ubuntu 10.04 with OpenSSL 0.9.8k.

Please provide any additional information below.


_______________________________________________
Cherokee-dev mailing list
Cherok...@lists.octality.com
http://lists.octality.com/listinfo/cherokee-dev

cher...@googlecode.com

unread,
Jul 13, 2011, 10:23:52 AM7/13/11
to cherok...@cherokee-project.com

Comment #1 on issue 1229 by etienne....@gmail.com: HTTPS connection in

More info on possible cause in comment 4 here:
http://code.google.com/p/chromium/issues/detail?id=72716

cher...@googlecode.com

unread,
Sep 17, 2011, 3:52:29 PM9/17/11
to cherok...@cherokee-project.com
Updates:
Status: Fixed
Owner: alobbs
Labels: Type-Defect Priority-Medium OpSys-All Component-Logic

Comment #2 on issue 1229 by alobbs: HTTPS connection in Chromium fallback

Everything works as expected on Trunk now (1.2.99 plus a few patches).
Thank you very much for reporting!!

Attachments:
Cherokee-Chrome-TLS_1.png 13.2 KB

Reply all
Reply to author
Forward
0 new messages