LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 12-08-2023, 02:41 PM   #1
triplum.fm
Registered User
 
Registered: Mar 2023
Posts: 60

Rep: Reputation: 33
vsftpd - Faulty file transfer with TLSv1.3 & AES128


Hello everyone,

I have an issue with vsftpd and TLSv1.3, affecting both vsftpd-3.0.3 and vsftpd-3.0.5. I can easily establish a connection and transfer files over TLSv1.3 with TLS_AES_256_GCM_SHA384 using gFTP and lftp. The same applies to TLSv1.2 with ECDHE-RSA-AES256-GCM-SHA384.

However, the problem arises as my Android smartphones or apps establish the connection (when configured to TLSv1.3) only with TLS_AES_128_GCM_SHA256. Although they can successfully log in to the server, it is not possible to transfer files completely. In particular, images are only partially transferred, displaying only parts of the image.

This issue affects all tested Android FTP clients, and I've tested it on both a Samsung M52 (Android 13) and a Xiaomi 9T Pro (LineageOS 20). The server is running on Debian Bookworm.

Does anyone know exactly where the problem lies?

Last edited by triplum.fm; 12-08-2023 at 03:25 PM.
 
Old 12-09-2023, 11:16 PM   #2
Turbocapitalist
LQ Guru
 
Registered: Apr 2005
Distribution: Linux Mint, Devuan, OpenBSD
Posts: 7,310
Blog Entries: 3

Rep: Reputation: 3722Reputation: 3722Reputation: 3722Reputation: 3722Reputation: 3722Reputation: 3722Reputation: 3722Reputation: 3722Reputation: 3722Reputation: 3722Reputation: 3722
Quote:
Originally Posted by triplum.fm View Post
Does anyone know exactly where the problem lies?
Exactly? No.

However, there are quality SFTP clients for the platforms you list. What about your work flow seems to indicate a need for deprecated FTP/FTPS instead of SFTP? That is the big question in 2023, almost 2024.

While there are a few edge cases where FTP/FTPS might make sense, they are very rare nowadays.
 
1 members found this post helpful.
Old 12-10-2023, 09:58 AM   #3
triplum.fm
Registered User
 
Registered: Mar 2023
Posts: 60

Original Poster
Rep: Reputation: 33
Quote:
Originally Posted by Turbocapitalist View Post
Exactly? No.
I can't really pinpoint what was up with vsftpd. The issue only caught my attention when I activated TLSv1.3. I asked around in a bunch of forums, but no one could really tell me what was off with vsftpd. This morning, I uninstalled vsftpd and installed proFTPd. And guess what, it's working perfectly now. TLSv1.3 - TLS_AES_256_GCM_SHA384 (256 bits) is running as the standard on all devices.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SSL/TLS Server supports TLSv1.0 ==> disable TLSv1.0 in postfix mariach Linux - Server 1 05-30-2019 10:08 PM
How to disable TLSv1.0/TLSv1.1 and CBC ciphers in Redhat surroor Red Hat 2 12-03-2015 04:44 PM
RAID1: can't replace faulty spare (marked again as 'faulty spare' within seconds) Thambry Linux - General 2 11-14-2013 07:31 AM
Faulty card or faulty config? svar Linux - Networking 4 09-02-2009 09:39 AM
Cannot setup aes128 loopback device? binarybob0001 Linux - Security 2 04-19-2006 05:00 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 05:36 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration