[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: TLS Man-In-The-Middle Vulnerability



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Erwin Lam wrote:
> Nov 23 05:07:29.317 [notice] Tor 0.2.1.20 opening log file.
> Nov 23 05:07:29.352 [notice] Parsing GEOIP file.
> Nov 23 05:07:30.212 [notice] No current certificate known for authority urras; launching request.
> Nov 23 05:07:30.212 [notice] Bootstrapped 5%: Connecting to directory server.
> Nov 23 05:07:30.268 [notice] I learned some more directory information, but not enough to build a circuit: We have no network-status consensus.
> Nov 23 05:07:30.269 [notice] No current certificate known for authority urras; launching request.
> Nov 23 05:07:30.293 [notice] Bootstrapped 10%: Finishing handshake with directory server.
> Nov 23 05:07:30.363 [warn] TLS error: unexpected close while renegotiating
> Nov 23 05:07:30.421 [warn] TLS error: unexpected close while renegotiating
> Nov 23 05:07:30.866 [warn] TLS error: unexpected close while renegotiating
> Nov 23 05:08:31.090 [notice] No current certificate known for authority urras; launching request.
> Nov 23 05:08:31.182 [warn] TLS error: unexpected close while renegotiating
> Nov 23 05:08:31.446 [warn] TLS error: unexpected close while renegotiating
> Nov 23 05:13:36.219 [notice] No current certificate known for authority urras; launching request.
> Nov 23 05:13:36.344 [warn] TLS error: unexpected close while renegotiating
> Nov 23 05:13:36.752 [warn] TLS error: unexpected close while renegotiating
I can confirm these errors while trying to setup a lightning talk within
the network at the Deepsec afterparty at Metalab: those guys are nice,
but they were playing a bit bad with the TLS connections ;-)
The setup is Slackware64 13.0 with openssl-0.9.8k and tor-0.2.1.20.

ciao

- --
Marco Bonetti
Slackintosh Linux Project Developer: http://workaround.ch/
Linux-live for powerpc: http://workaround.ch/pub/rsync/mb/linux-live/

My GnuPG key id: 0x0B60BC5F
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAksKU/oACgkQTYvJ9gtgvF9HtQCg36Sic0gqsHczbUCZNAyH6XYg
rycAoMfGlzh1hjOH+AwbD8rThL/J3Ljk
=3OCI
-----END PGP SIGNATURE-----
***********************************************************************
To unsubscribe, send an e-mail to majordomo@xxxxxxxxxxxxxx with
unsubscribe or-talk    in the body. http://archives.seul.org/or/talk/