[Bug 1020621] Re: TLS 1.1 and 1.2 renegotiation failure

Marc Deslauriers marc.deslauriers at canonical.com
Thu Jul 5 12:05:16 UTC 2012


test-openssl.py in qa-regression-testing will now test tls1.1
renegotiation.


SRU team:

This is a security update that has been copied to -proposed to get more
testing. This needs to be released by the security team.

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to openssl in Ubuntu.
https://bugs.launchpad.net/bugs/1020621

Title:
  TLS 1.1 and 1.2 renegotiation failure

Status in OpenSSL cryptography and SSL/TLS toolkit:
  Fix Released
Status in “openssl” package in Ubuntu:
  Fix Released
Status in “openssl” source package in Precise:
  Confirmed
Status in “openssl” source package in Quantal:
  Fix Released

Bug description:
  Openssl renegotiation is broken with tls 1.1 and 1.2:

  openssl s_server
  and s_client 

  press R
  the result is:

  RENEGOTIATING
  140543847671464:error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number:s3_pkt.c:340:

To manage notifications about this bug go to:
https://bugs.launchpad.net/openssl/+bug/1020621/+subscriptions




More information about the foundations-bugs mailing list