Arch Linux

Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#33759 - [loudmouth] mcabber does not connet with SSL

Attached to Project: Arch Linux
Opened by Alex Burlutsky (stosem) - Friday, 08 February 2013, 06:19 GMT
Last edited by Jan de Groot (JGC) - Monday, 22 July 2013, 21:45 GMT
Task Type Bug Report
Category Packages: Extra
Status Closed
Assigned To Jan de Groot (JGC)
Ionut Biru (wonder)
Architecture All
Severity Medium
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 2
Private No

Details

Description:

mcabber 0.10.2-1 does not connect to SSL server (talk.google.com for example), reports:
There was an error while connecting.

Any changes to mcabberrc (for example ssl=0/1 , tls=0/1, ssl_ignore_checks=0/1) doesn't help.

Log file says:
LM-VERBOSE: Could not begin SSL
or
GNUTLS handshake failed: The Diffie-Hellman prime sent by the server is not acceptable (not long enough).
or
Disconnected, reason: 2->'LM_DISCONNECT_REASON_HUP'


I fix this issue by recompile lib loudmouth 1.4.3-3 with
--with-ssl=openssl

See also:
https://bitbucket.org/McKael/mcabber-crew/issue/81/cant-establish-tls-ssl-connection-after
This task depends upon

Closed by  Jan de Groot (JGC)
Monday, 22 July 2013, 21:45 GMT
Reason for closing:  Fixed
Comment by David J. Haines (dhaines) - Friday, 08 February 2013, 16:24 GMT
This is related to the recent update of gnutls, which now requires longer DH keys. I've reported the issue to Google, so I'm hoping that they'll increase the size on their end. Loudmouth should be able to be patched with judicious use of the gnutls_dh_set_prime_bits function. Setting the minimum size to 768 should allow Google Talk to once again work.

Also, it looks like the pkgbuild needs to account for what appears to be an issue with configure.ac.
Comment by Jan de Groot (JGC) - Monday, 22 July 2013, 09:23 GMT
Is this still an issue? AFAIK the minimum DH key size in GNUTLS has been decreased to work with gtalk.
Comment by David J. Haines (dhaines) - Monday, 22 July 2013, 13:44 GMT
It is not. gnutls fixed it on their end soon after I made my comment, so in either 3.1.8 or 3.1.9. Either way, this is fixed (at least for me).

Loading...