LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 08-25-2015, 11:01 AM   #1
YankeePride13
Member
 
Registered: Aug 2012
Distribution: Ubuntu 10.04, CentOS 6.3, Windows 7
Posts: 262

Rep: Reputation: 55
Sendmail TLS Handshake Error


Hello,

I run a mail server that is running Centos 5, fully patched. There are a few domains that I have trouble sending to. The errors look like this :

Code:
STARTTLS=client: 814:error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure:s23_clnt.
I have updated my openssl package to the latest version in the Centos 5 repo. I have updated my DH keys, blocked SSLv2 and SSLv3. See my local config below for sendmail:

Code:
LOCAL_CONFIG
O CipherList=ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA
O DHParameters=/etc/pki/tls/certs/dhparams.pem
O ServerSSLOptions=+SSL_OP_NO_SSLv2 +SSL_OP_NO_SSLv3
O ClientSSLOptions=+SSL_OP_NO_SSLv2 +SSL_OP_NO_SSLv3
I am just not sure if the issue is on my end or theirs. They don't have an issue sending mail to me, so that makes me think the issue is on my end.

Google searching for the error "SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure" hasn't really yielded many results. Most of it was for web servers.

I am maybe thinking it's a cypher issue? In that both servers can't agree on a cipher? If anyone has any light they can shed or suggestions, I am all ears.

I was also wondering if I should update my CipherList to be just "HIGH". Thoughts? Thanks!
 
Old 08-26-2015, 10:03 AM   #2
YankeePride13
Member
 
Registered: Aug 2012
Distribution: Ubuntu 10.04, CentOS 6.3, Windows 7
Posts: 262

Original Poster
Rep: Reputation: 55
I was able to get some more info from one of the domains that I had trouble sending mail to. The error message on their side was :
Code:
error:1408A0C1:SSL routines:SSL3_GET_CLIENT_HELLO:no shared cipher
So it does sound like a cipher issue. I had grabbed the above cipherlist from https://weakdh.org/sysadmin.html. Does anyone know if this is no longer considered a recommended cipherlist?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] centos 6.4 openldap tls handshake negotiation CharlesMM Linux - Server 1 10-28-2013 10:39 PM
openvpn error: TLS Error: TLS key negotiation failed to occur within 60 seconds pendrive Linux - Networking 1 11-02-2011 08:39 AM
OpenVPN Setup: TLS Handshake Error njozwiak Linux - Networking 4 07-10-2009 11:50 PM
postfix gives me tls handshake failure kryptonite0110 Linux - Software 0 01-02-2006 10:05 PM
qpopper TLS/SSL Handshake failed: -1 frerotjs Linux - Software 0 07-15-2003 07:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 03:12 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration