[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#238308: marked as done (apache-ssl: SSL23_GET_CLIENT_HELLO problem)



Your message dated Wed, 17 Mar 2004 21:02:30 +0100 (CET)
with message-id <Pine.LNX.4.58.0403172101490.18414@trider-g7.ext.fabbione.net>
and subject line Bug#238308: apache-ssl: SSL23_GET_CLIENT_HELLO problem
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 16 Mar 2004 12:33:11 +0000
>From rory.l@hopkins.co.uk Tue Mar 16 04:33:11 2004
Return-path: <rory.l@hopkins.co.uk>
Received: from mail.hopkins.co.uk (safe.hopkins.co.uk) [62.189.170.1] 
	by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 1B3Dkt-00031o-00; Tue, 16 Mar 2004 04:33:11 -0800
Received: from rory by safe.hopkins.co.uk with local (Exim 4.30)
	id 1B3Dkr-00036t-B8; Tue, 16 Mar 2004 12:33:09 +0000
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Rory Campbell-Lange <rory@campbell-lange.net>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: apache-ssl: SSL23_GET_CLIENT_HELLO problem
X-Mailer: reportbug 2.48
Date: Tue, 16 Mar 2004 12:33:09 +0000
Message-Id: <[🔎] E1B3Dkr-00036t-B8@safe.hopkins.co.uk>
Sender: Rory Campbell-Lange <rory.l@hopkins.co.uk>
Delivered-To: submit@bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_03_12 
	(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-7.0 required=4.0 tests=BAYES_00,HAS_PACKAGE 
	autolearn=no version=2.60-bugs.debian.org_2004_03_12
X-Spam-Level: 

Package: apache-ssl
Version: 1.3.29.0.1-3
Severity: important

I am getting the same problem as reported in bug 215011. Clients can
connect locally, but not through our firewall using port forwarding. The
error reported is "error:1407609C:SSL
routines:SSL23_GET_CLIENT_HELLO:http request", then "SSL_accept failed".

-- System Information:
Debian Release: testing/unstable
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.4.22
Locale: LANG=C, LC_CTYPE=C

Versions of packages apache-ssl depends on:
ii  apache-common               1.3.29.0.1-3 Support files for all Apache webse
ii  debconf                     1.4.11       Debian configuration management sy
ii  dpkg                        1.10.19      Package maintenance system for Deb
ii  libc6                       2.3.2.ds1-11 GNU C Library: Shared libraries an
ii  libdb4.1                    4.1.25-16    Berkeley v4.1 Database Libraries [
ii  libexpat1                   1.95.6-8     XML parsing C library - runtime li
ii  libkeynote0                 2.3-10       Decentralized Trust-Management sys
ii  libmagic1                   4.07-2       File type determination library us
ii  libpam0g                    0.76-15      Pluggable Authentication Modules l
ii  libssl0.9.7                 0.9.7c-5     SSL shared libraries
ii  logrotate                   3.6.5-2      Log rotation utility
ii  mime-support                3.26-1       MIME files 'mime.types' & 'mailcap
ii  openssl                     0.9.7c-5     Secure Socket Layer (SSL) binary a
ii  perl [perl5]                5.8.3-2      Larry Wall's Practical Extraction 
ii  ssl-cert                    1.0-7        Simple debconf wrapper for openssl

-- debconf information:
  apache-ssl/server-admin: it@hopkins.co.uk
* apache-ssl/enable-suexec: false
  apache-ssl/init: true
  apache-ssl/server-name: 10.0.0.23
  apache-ssl/document-root: /usr/share/squirrelmail


---------------------------------------
Received: (at 238308-done) by bugs.debian.org; 17 Mar 2004 20:02:39 +0000
>From fabbione@fabbione.net Wed Mar 17 12:02:39 2004
Return-path: <fabbione@fabbione.net>
Received: from port5.ds1-sby.adsl.cybercity.dk (trider-g7.fabbione.net) [212.242.169.198] 
	by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 1B3hFP-0005xX-00; Wed, 17 Mar 2004 12:02:39 -0800
Received: from trider-g7.ext.fabbione.net (port5.ds1-sby.adsl.cybercity.dk [212.242.169.198])
	by trider-g7.fabbione.net (Postfix) with ESMTP
	id EF6F717; Wed, 17 Mar 2004 21:02:32 +0100 (CET)
Date: Wed, 17 Mar 2004 21:02:30 +0100 (CET)
From: Fabio Massimo Di Nitto <fabbione@fabbione.net>
Sender: fabbione@trider-g7.ext.fabbione.net
To: Rory Campbell-Lange <rory@campbell-lange.net>
Cc: 238308-done@bugs.debian.org
Subject: Re: Bug#238308: apache-ssl: SSL23_GET_CLIENT_HELLO problem
In-Reply-To: <20040317184633.GA20979@campbell-lange.net>
Message-ID: <Pine.LNX.4.58.0403172101490.18414@trider-g7.ext.fabbione.net>
References: <[🔎] E1B3Dkr-00036t-B8@safe.hopkins.co.uk>
 <[🔎] Pine.LNX.4.58.0403161826240.7104@trider-g7.ext.fabbione.net>
 <20040317184633.GA20979@campbell-lange.net>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Delivered-To: 238308-done@bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_03_12 
	(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-5.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER 
	autolearn=no version=2.60-bugs.debian.org_2004_03_12
X-Spam-Level: 


Hi Rory,
	no problem, I am closing this bug.

thank
Fabio

On Wed, 17 Mar 2004, Rory Campbell-Lange wrote:

> Hi Fabio
>
> I'm very sorry to have wasted your time. For whatever reason, doing an
>
>     apt-get install --reinstall apache-ssl
>
> sorted the problem. I also checked to see my clients were using
> "https://"; instead of "http://";.
>
> My apologies; and thanks very much for your work on this package.
>
> Kind regards,
> Rory
>
> On 16/03/04, Fabio Massimo Di Nitto (fabbione@fabbione.net) wrote:
> >
> > Hi Rory,
> >
> > On Tue, 16 Mar 2004, Rory Campbell-Lange wrote:
> >
> > > Package: apache-ssl
> > > Version: 1.3.29.0.1-3
> > > Severity: important
> > >
> > > I am getting the same problem as reported in bug 215011.
> >
> > Did you check the configuration as explained in 215011? If so what is the
> > difference between your problem and 215011?
> >
> >
> > > Clients can
> > > connect locally, but not through our firewall using port forwarding.
> >
> > This is not an apache-ssl problem. Check your firewall/network setup.
> >
> > > The
> > > error reported is "error:1407609C:SSL
> > > routines:SSL23_GET_CLIENT_HELLO:http request", then "SSL_accept failed".
> >
> > Can we see the configuration files? Did you try to update apache since the
> > version you are using is farly old? Do you have any file in
> > /etc/apache-ssl/ called suggested_corrections? what does it contains?
> >
> > Fabio
> >
>
>

-- 
<user> fajita: step one
<fajita> Whatever the problem, step one is always to look in the error log.
<user> fajita: step two
<fajita> When in danger or in doubt, step two is to scream and shout.



Reply to: