After an evaluation, GNOME has moved from Bugzilla to GitLab. Learn more about GitLab.
No new issues can be reported in GNOME Bugzilla anymore.
To report an issue in a GNOME project, go to GNOME GitLab.
Do not go to GNOME Gitlab for: Bluefish, Doxygen, GnuCash, GStreamer, java-gnome, LDTP, NetworkManager, Tomboy.
Bug 527633 - Unable to connect to https url with TLS 1.0
Unable to connect to https url with TLS 1.0
Status: RESOLVED DUPLICATE of bug 581342
Product: Evolution Exchange
Classification: Deprecated
Component: Connector
2.22.x
Other Linux
: Normal critical
: ---
Assigned To: Connector Maintainer
Ximian Connector QA
Depends on:
Blocks:
 
 
Reported: 2008-04-11 23:04 UTC by Russell Harrison
Modified: 2009-11-24 15:48 UTC
See Also:
GNOME target: ---
GNOME version: 2.21/2.22



Description Russell Harrison 2008-04-11 23:04:48 UTC
The SSL off loading appliance in front of our Exchange server currently can only do TLS 1.0.  When I attempt to connect to it using Evolution Exchange 2.22.x it instantly fails.  I've confirmed by sniffing the traffic that it attempts to make the connection using TLS1.1 and doesn't fall back to TLS1.0.
Comment 1 André Klapper 2008-04-18 19:43:55 UTC
which exact libsoup version is used, which distribution is this?
can you provide the sniffing output (please remove any confidential data) that shows the failure?
Comment 2 Russell Harrison 2008-04-20 23:03:07 UTC
(In reply to comment #1)
> which exact libsoup version is used, which distribution is this?
> can you provide the sniffing output (please remove any confidential data) that
> shows the failure?

I've reproduced the issue using the Fedora 9 beta releases (libsoup 2.4.1-1.fc9), but we have reports of  the problem from GenToo users and people testing the upcoming Ubuntu releases.

It might take me a little while to clean up the tcpdump.  Basically it just shows the connection from Evolution initiated as TLS1.1 and no further traffic after it fails.  I'll see if I can include the response from the SSL off loader here as that'll probably take less time anyway.
Comment 3 Milan Crha 2009-11-24 13:30:34 UTC
Dan, is this the same as bug #581342, please? It seems to me, but I'm not sure.
Comment 4 Dan Winship 2009-11-24 14:24:17 UTC
Yes, and it's fixed in libsoup 2.28. (We actually skip both TLS 1.1 and TLS 1.0 now, and go with just SSL 3.0, which everyone supports, because $@!#$! PayPal can't do anything more modern than that.)
Comment 5 Milan Crha 2009-11-24 15:48:28 UTC
Thanks, then I'm marking this as a duplicate.

*** This bug has been marked as a duplicate of bug 581342 ***