From: Joseph Jones Date: 2015-12-17T21:06:27-07:00 Subject: [ruby-core:72270] [Ruby trunk - Bug #11739] OpenSSL::SSL::SSLServer doesn't negotiate ECDHE-* ciphersuites --56738643_614fd4a1_16c Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Joseph Jones liked your message with Boxer. On December 7, 2015 at 00:33:= 50 MST, ko1=40atdot.net wrote:Issue =2311739 has been updated by Koichi S= asada.Assignee set to openssl----------------------------------------Bug = =2311739: OpenSSL::SSL::SSLServer doesn't negotiate ECDHE-* ciphersuitesh= ttps://bugs.ruby-lang.org/issues/11739=23change-55293* Author: Branodn We= eks* Status: Open* Priority: Normal* Assignee: openssl* ruby -v: * Backpo= rt: 2.0.0: UNKNOWN, 2.1: UNKNOWN, 2.2: UNKNOWN---------------------------= -------------I'm trying to configure an instance of OpenSSL::SSL::SSLServ= er that supports Elliptic curve Diffie=E2=80=93Hellman. No matter what co= mbination of Ruby and OpenSSL versions I try the negotiation with the cli= ent fails. Proof of concept:https://gist.github.com/brandonweeks/e26414cc= 1e9eea9453a8Then run:>openssl s=5Fclient -connect localhost:8443Also atta= ching a pcap file of the failed handshake.---=46iles---------------------= -----------tls=5Fhandshake.pcap (4.93 KB)-- https://bugs.ruby-lang.org/ = --56738643_614fd4a1_16c Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Joseph Jones liked your message with Boxer.


= On December 7, 2015 at 00:33:50 MST, ko1=40atdot.net wrote:
Issue =2311739 has been updated by = Koichi Sasada.

Assignee set to openssl

------------= ----------------------------
Bug =2311739: OpenSSL::SSL::SSLServer d= oesn't negotiate ECDHE-* ciphersuites
https://bugs.ruby-lang.org/iss= ues/11739=23change-55293

* Author: Branodn Weeks
* Status= : Open
* Priority: Normal
* Assignee: openssl
* ruby -v: <= br />* Backport: 2.0.0: UNKNOWN, 2.1: UNKNOWN, 2.2: UNKNOWN
--------= --------------------------------
I'm trying to configure an instance= of OpenSSL::SSL::SSLServer that supports Elliptic curve Diffie=E2=80=93H= ellman. No matter what combination of Ruby and OpenSSL versions I try the= negotiation with the client fails.

Proof of concept:
ht= tps://gist.github.com/brandonweeks/e26414cc1e9eea9453a8

Then r= un:
>openssl s=5Fclient -connect localhost:8443

Also atta= ching a pcap file of the failed handshake.


---=46iles---= -----------------------------
tls=5Fhandshake.pcap (4.93 KB)

--
https://bugs.ruby-lang.org/
--56738643_614fd4a1_16c--