[openssl-dev] [openssl.org #3728] Question: does "sslv3" in log mean we're using SSLv3?

Richard C Paterson via RT rt at openssl.org
Thu Mar 5 16:42:49 UTC 2015


Apologies if this is the incorrect forum for this question.

We’re seeing error messages like SSL3_READ_BYTES and SSL3_GET_SERVER_CERTIFICATE for some reason;

-          SSL3_GET_SERVER_CERTIFICATE:certificate verify failed

-          SSL£_GET_BYTES:sslv3 alert handshake failure

However, we believe that we have disabled the use of SSLv3. Does the presence of “SSL3_” in the logs indicate that we are still using SSLv3 and not TLS like we think?

Richard C Paterson
Development Testing Manager
SAS R&D Scotland
Tel: +44 141 223 9100 ■ Mobile: +447977 477296 ■ richard.c.paterson at sas.com<mailto:richard.c.paterson at sas.com>
www.sas.com<http://www.sas.com/>
SAS®...  THE POWER TO KNOW
P Please consider the environment before printing this e-mail

The information in this e-mail and any attached files is confidential. It is intended solely for the use of the addressee. Any unauthorised disclosure or use is prohibited. If you are not the intended recipient of the message, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. The views of the author may not necessarily reflect those of the company.




More information about the openssl-dev mailing list