This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal


Jun 2, 2016, 9:26 PM
11 Posts
topic has been resolvedResolved

ERR_SSL_VERSION_OR_CIPHER_MISMATCH

  • Category: Domino Server
  • Platform: IBM i
  • Release: 9.0.1
  • Role: Administrator
  • Tags:
  • Replies: 3

Hi,

I recently had to recereate a self-signed internet certificate on a Domino 9.0.1 FP4 HF70 with Traveler following this document http://www-01.ibm.com/support/docview.wss?rs=463&uid=swg21193730

I used a SHA256 algorithm to create it with a 2048 key. Followed the document and all works fine (IBM Verse on phone an tablet using https to access the server).

My first test was to access the Traveler Domino server with Firefox from my PC : https://srvtrv/traveler and i had to log in. Just to check that access is possible.

 

I few days after i had to do the same on another Domino/Traveler server, also Windows 2008R2. Same Domino version; i followed the same document, used the same values, etc...

BUT, either FF or Chrome says that te server still use SSLv3 (error "ssl_error_unsupported_version") or "ERR_SSL_VERSION_OR_CIPHER_MISMATCH".

I added "DISABLE_SSLV3=1" to the notes.ini and IE11 which previously sent me also an error, now prompts to login !

I checked the two servers, no obvious difference.

So, my question is: appart from the .kyr et .sth file that are created, is there somewhere something else that could faultly indicate that the server is not using the internet certificate i want it to use ?

I red that aother tools are available to create the certificate (OpenSSL and KYRTool) but i wonder it should be the problem as my first server doesn't cause any trouble.

 

TIA for any advice/help,

Yan

Jun 3, 2016, 6:15 PM
94 Posts
Could you post the output of sslscan or an ssllabs run here?
9.0.1 FP4 is fairly old; you may have better luck with the default settings in FP6.
Jun 7, 2016, 3:18 AM
11 Posts
ERR_SSL_VERSION_OR_CIPHER_MISMATCH

Hi Dave,

Thx for your answer. I'll try to apply FP6 asap. And see if i can do a ssllabs test. Good idea.

I'll paste the result when i'm able to do it on customer site.

Regards,

Yan

Jun 17, 2016, 6:03 AM
11 Posts
SSL on Domino

Hi Dave,

Upgraded the Domino server to 9.0.1.6 and Traveler to 9.0.1.11.

I finally made all work following this IBM link   http://www-01.ibm.com/support/docview.wss?uid=swg21268695   and this one  https://turtleblog.info/2015/06/22/creating-sha-2-4096-ssl-certificates-for-domino/   and choosing to certify my certificate with a *real* one (=purchased) (tried a free *test* one but IBM Verse on iPhone with iOS 9.3.2 was complaining).

Now, no more messages on the smartphones.

Thank for your advices.

Yan


This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal