FS#33900 - [openssl] 1.0.1.e-1 SSL3_GET_SERVER_HELLO:bad packet length [offlineimap]

Attached to Project: Arch Linux
Opened by Fabio Zanini (iosonofabio) - Sunday, 17 February 2013, 10:42 GMT
Last edited by Gaetan Bisson (vesath) - Sunday, 17 February 2013, 23:31 GMT
Task Type Bug Report
Category Packages: Core
Status Closed
Assigned To No-one
Architecture All
Severity Critical
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Description:
I connect to a mail server via offlineimap + openssl, and recently started getting this error:

OpenSSL responded: [Errno 1] _ssl.c:504: error:14092073:SSL routines:SSL3_GET_SERVER_HELLO:bad packet length

This seems to have been reported in the past, but I am not sure the patch was ever implemented:

http://gnupg.10057.n7.nabble.com/serverhello-refused-by-openssl-td25110.html

This breaks the SSL connection altogether, hence offlineimap (and SSL) are unusable.

Additional info:
* package version(s): openssl 1.0.1.e-1, offlineimap 6.5.4-1


   log (1.8 KiB)
This task depends upon

Closed by  Gaetan Bisson (vesath)
Sunday, 17 February 2013, 23:31 GMT
Reason for closing:  Fixed
Additional comments about closing:  openssl-1.0.1.e-2
Comment by Pierre Schmitz (Pierre) - Sunday, 17 February 2013, 10:52 GMT
Could you try openssl 1.0.1.e-2 from the testing repo? This disables TLS1.2 support entirely to workaround issues with broken servers.
Comment by Christian Neukirchen (chneukirchen) - Sunday, 17 February 2013, 15:30 GMT
openssl 1.0.1.e-2 fixes a similar bug with postfix and openssl 1.0.1.e-1 here, which produced

Feb 17 16:15:00 localhost postfix/smtp[2081]: SSL_connect error to smtp.gmail.com[173.194.69.109]:587: -1
Feb 17 16:15:00 localhost postfix/smtp[2081]: warning: TLS library problem: 2081:error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure:s23_clnt.c:741:
Comment by Fabio Zanini (iosonofabio) - Sunday, 17 February 2013, 20:52 GMT
Indeed now it works again, using openssl 1.0.1.e-2. You can close.

Loading...