[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[openssl-gost] Re: Bug#898823: does not work for cryptopro test servers



On 2018-05-16T12:29:34+0300, Dmitry Eremin-Solenikov wrote:

 > Package: libengine-gost-openssl1.1
 > Version: 1.1.0.1-1
 > Severity: normal

 > Connecting to CryptoPro test servers does not seem to work. No
 > additional configuration was done to openssl.cnf.

 > $ openssl s_client -engine gost -connect tlsgost-2001.cryptopro.ru:443
 > engine "gost" set.
 > CONNECTED(00000003)
 > 140418489987264:error:141710F8:SSL routines:tls_process_server_hello:unknown cipher returned:../ssl/statem/statem_clnt.c:1028:
 > ---
 > no peer certificate available
 > ---
 > No client certificate CA names sent
 > ---
 > SSL handshake has read 1009 bytes and written 183 bytes
 > Verification: OK
 > ---
 > New, (NONE), Cipher is (NONE)
 > Secure Renegotiation IS NOT supported
 > Compression: NONE
 > Expansion: NONE
 > No ALPN negotiated
 > SSL-Session:
 >     Protocol  : TLSv1
 >     Cipher    : 0000
 >     Session-ID: AF4AA192F4073C85D989B2FE353303F2E00540B6864EA67829931754CB631AF5
 >     Session-ID-ctx: 
 >     Master-Key: 
 >     PSK identity: None
 >     PSK identity hint: None
 >     SRP username: None
 >     Start Time: 1526462942
 >     Timeout   : 7200 (sec)
 >     Verify return code: 0 (ok)
 >     Extended master secret: no
 > ---


 > -- System Information:
 > Debian Release: buster/sid
 >   APT prefers testing
 >   APT policy: (500, 'testing')
 > Architecture: amd64 (x86_64)
 > Foreign Architectures: i386

 > Kernel: Linux 4.16.0-1-amd64 (SMP w/4 CPU cores)
 > Locale: LANG=en_GB.utf8, LC_CTYPE=en_GB.utf8 (charmap=UTF-8), LANGUAGE=en_GB:en (charmap=UTF-8)
 > Shell: /bin/sh linked to /bin/dash
 > Init: systemd (via /run/systemd/system)
 > LSM: AppArmor: enabled

 > Versions of packages libengine-gost-openssl1.1 depends on:
 > ii  libc6      2.27-3
 > ii  libssl1.1  1.1.0h-2

 > libengine-gost-openssl1.1 recommends no packages.

 > libengine-gost-openssl1.1 suggests no packages.

 > -- no debconf information


-- 
Regards, Wartan.