Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reenable unsafe renegotiation (cf. RFC 5746) and update openssl.conf for OpenSSL 3.x #565

Conversation

JustAnotherArchivist
Copy link
Contributor

Since OpenSSL 3.0, legacy renegotiation is disabled. This leads to 'Operation not permitted' errors e.g. on https://josour.unescwa.org/. With curl, it manifests as 'OpenSSL/3.0.11: error:0A000152:SSL routines::unsafe legacy renegotiation disabled'. Notably, browsers have no issues connecting there.

Further, the config file format apparently has to be more complicated now. It's still compatible with OpenSSL 1.1.1 though. I did not test older versions since they're irrelevant by now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
1 participant