6.4.3 is released but appears to have eDirectory SSL issues

After upgrading AAuth server to 6.4.3 release, no ldap syncing or login can happen if repository is eDirectory

LDAP connect error: ("('socket ssl wrapping error: [SSL: SSLV3_ALERT_HANDSHAKE_FAILURE] sslv3 alert handshake failure (_ssl.c:1002)',)",); ['x.x.x.x.:636', 'x.x.x.x:636']

Rodney

If you found this post useful, give it a "Like" or click on "Verify Answer" under the "More" button.   This helps others.

Parents Reply
  • Verified Answer

    0   in reply to 

    Hello,

    Here is the formal recommendation from engineering:

    In the new release of AA 6.4.3.0-340, we now support/use the set of cipher-suites configured in the Policies > HTTPS Options > Advanced SSL Settings > Pre-defined SSL ciphersuite options.  

    We recommend that customers change to use an EC certificate if they can.  Once using an EC certificate,  we also recommend that the Policies > HTTPS Options > Advanced SSL Settings > Pre-defined SSL ciphersuite options should be set to SSL Labs score:90 (#1) or SSL Labs score: 100 

    If a customer cannot use an EC certificate, they will need to use the "Less restrictive ciphers for backward compatibility" Pre-defined SSL ciphersuite. 

    Thanks.

    Regards,

    Luciano Testa

Children
No Data