[exim] GnuTLS / OpenSSL interop problems

Top Page
Delete this message
Reply to this message
Author: Tony Finch
Date:  
To: exim-users
Subject: [exim] GnuTLS / OpenSSL interop problems
I have receved a number of reports recently of TLS interop probblems
between Exim+OpenSSL and Exim+GnuTLS. Is anyone else seeing anything
similar?

My servers are running Exim 4.82 (git revision c0e5623) linked against
OpenSSL 1.0.1e.

GnuTLS clients connecting to send mail see something like:

2014-02-27 15:50:14 1WJ2vo-0004Gf-4W
    TLS error on connection to ppsw.cam.ac.uk [131.111.8.137] (recv):
    A TLS fatal alert has been received.: Bad record MAC


There are some suggestions online that this might be related to GnuTLS's
random record padding, but I thought the problems with that had been
fixed.

Tony.
--
<fanf@???> <dot@???> http://dotat.at/ ${sg{\N${sg{\
N\}{([^N]*)(.)(.)(.*)}{\$1\$3\$2\$1\$3\n\$2\$3\$4\$3\n\$3\$2\$4}}\
\N}{([^N]*)(.)(.)(.*)}{\$1\$3\$2\$1\$3\n\$2\$3\$4\$3\n\$3\$2\$4}}