Re: [exim] GnuTLS / OpenSSL interop problems

Page principale
Supprimer ce message
Répondre à ce message
Auteur: Jasen Betts
Date:  
À: exim-users
Sujet: Re: [exim] GnuTLS / OpenSSL interop problems
On 2014-03-03, Viktor Dukhovni <exim-users@???> wrote:
> On Mon, Mar 03, 2014 at 02:55:24PM +0000, Tony Finch wrote:
>
>> I have receved a number of reports recently of TLS interop probblems
>> between Exim+OpenSSL and Exim+GnuTLS. Is anyone else seeing anything
>> similar?
>>
>> My servers are running Exim 4.82 (git revision c0e5623) linked against
>> OpenSSL 1.0.1e.
>>
>> GnuTLS clients connecting to send mail see something like:
>>
>> 2014-02-27 15:50:14 1WJ2vo-0004Gf-4W
>>     TLS error on connection to ppsw.cam.ac.uk [131.111.8.137] (recv):
>>     A TLS fatal alert has been received.: Bad record MAC

>>
>> There are some suggestions online that this might be related to GnuTLS's
>> random record padding, but I thought the problems with that had been
>> fixed.
>
> Does this happen during data transmission, or during the handshake?


I'm seeing it after "MAIL FROM" or "RCPT TO"
and occasionally in later parts of the conversation.

It's basically exim and gnutls from debian stable.

As far as I can tell it's been happening sinve january,
if not before,

--
Neither the pheasant plucker, nor the pheasant plucker's son.