Koozali.org: home of the SME Server

Problems with ssl

Blake Heinemann

Problems with ssl
« on: June 05, 2001, 07:17:36 PM »
Just last night, I started having problems trying to login securely to webmail. The certificate is presented, I hit continue, and then Netscape says. "An I/O error occured during security authorization. Please try your connection again."

I tried the same thing in Opera, and I get "Error 554, the signatures of this certificate could not be verified."

Yet, when I try it in IE, it works?  What gives?

I checked the errorlog in /var/log/httpd and here's what I found:

[Tue Jun  5 08:56:56 2001] [error] mod_ssl: SSL handshake failed (server secure.
esmith.svr:443, client 192.168.0.9) (OpenSSL library error follows)
[Tue Jun  5 08:56:56 2001] [error] OpenSSL: error:0407106B:rsa routines:RSA_padd
ing_check_PKCS1_type_2:block type is not 02
[Tue Jun  5 08:56:56 2001] [error] OpenSSL: error:04065072:rsa routines:RSA_EAY_
PRIVATE_DECRYPT:padding check failed
[Tue Jun  5 08:56:56 2001] [error] OpenSSL: error:1408B076:SSL routines:SSL3_GET
_CLIENT_KEY_EXCHANGE:bad rsa decrypt
[Tue Jun  5 09:00:05 2001] [error] mod_ssl: SSL handshake failed (server secure.
esmith.svr:443, client 192.168.0.9) (OpenSSL library error follows)
[Tue Jun  5 09:00:05 2001] [error] OpenSSL: error:0407106B:rsa routines:RSA_padd
ing_check_PKCS1_type_2:block type is not 02
[Tue Jun  5 09:00:05 2001] [error] OpenSSL: error:04065072:rsa routines:RSA_EAY_
PRIVATE_DECRYPT:padding check failed
[Tue Jun  5 09:00:05 2001] [error] OpenSSL: error:1408B076:SSL routines:SSL3_GET
_CLIENT_KEY_EXCHANGE:bad rsa decrypt
[Tue Jun  5 09:00:31 2001] [error] mod_ssl: SSL handshake failed (server secure.
esmith.svr:443, client 192.168.0.9) (OpenSSL library error follows)
[Tue Jun  5 09:00:31 2001] [error] OpenSSL: error:0407106B:rsa routines:RSA_padd
ing_check_PKCS1_type_2:block type is not 02
[Tue Jun  5 09:00:31 2001] [error] OpenSSL: error:04065072:rsa routines:RSA_EAY_
PRIVATE_DECRYPT:padding check failed
[Tue Jun  5 09:00:31 2001] [error] OpenSSL: error:1408B076:SSL routines:SSL3_GET
_CLIENT_KEY_EXCHANGE:bad rsa decrypt
[Tue Jun  5 09:02:21 2001] [error] mod_ssl: SSL handshake failed (server secure.
esmith.svr:443, client 192.168.0.9) (OpenSSL library error follows)
[Tue Jun  5 09:02:21 2001] [error] OpenSSL: error:0407106B:rsa routines:RSA_padd
ing_check_PKCS1_type_2:block type is not 02
[Tue Jun  5 09:02:21 2001] [error] OpenSSL: error:04065072:rsa routines:RSA_EAY_
PRIVATE_DECRYPT:padding check failed
[Tue Jun  5 09:02:21 2001] [error] OpenSSL: error:1408B076:SSL routines:SSL3_GET
_CLIENT_KEY_EXCHANGE:bad rsa decrypt  

Why would this be a problem with anything but IE. I've been using this box for about a month now with no other issues that I haven't already found answers for.

Thanks.

bh

Blake Heinemann

Re: Problems with ssl
« Reply #1 on: June 05, 2001, 07:18:17 PM »
PS:  I've edited the log to change the host name to esmith.svr

bh

Michael Jung

Re: Problems with ssl
« Reply #2 on: August 03, 2001, 08:24:27 PM »
Did you solve the problem? I had the same since I updated the E-Smith Server last night. When I read your comment that it only affects Netscape and Opera I guess it is about stored certificates and bingo. To solve that do in Netscape 4.76:

Communicator --> Tools --> Security Info
Certificates --> Web Sites
There mark all saved certificates corresponding with your E-Smith Server and delete them.

Michael Jung