Error code: ssl_error_renegotiation_not_allowed

Post your questions about Web Server usage and Apache + PHP + MySQL/SQLite web applications.

Error code: ssl_error_renegotiation_not_allowed

Postby River Trent » Thu May 12, 2011 2:00 pm

QNAP 239 Firmware 3.4.2 Build 0331T

I've just upgraded by desktop machine to Ubuntu 11.04 which has firefox 4.
On my QNAP i run 2 web sites which are only accessible through SSL, (Port 443) one site is a Virtual Host.
The site which is a Virtual Host (https://teambetamax.dnsalias.com/ receives this error

Secure Connection Failed

An error occurred during a connection to teambetamax.dnsalias.com.

Renegotiation is not allowed on this SSL socket.

(Error code: ssl_error_renegotiation_not_allowed)

Please contact the web site owners to inform them of this problem. Alternatively, use the command found in the help menu to report this broken site.


I've tried this on a couple of machines and this always happens with firefox 4, site is fine on firefox 3 and safari browsers.

any ideas?
User avatar
River Trent
Getting the hang of things
 
Posts: 80
Joined: Wed Dec 02, 2009 10:24 pm
NAS Model: TS-419U

Re: Error code: ssl_error_renegotiation_not_allowed

Postby Moogs » Fri May 13, 2011 6:21 am

This was a change made by Mozilla to address a security issue:

To enable SSL renegotiation you need to point your browser to about:config.

Find this:

security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref

and set it to true. After this you should be able to access the site.
--------------

Synology DS-209 (Retired)
Synology DS-1010+ (Retired)
ESXi 4.1 Host
Time Machine, Ruby, Squeezebox Duet, MySQL
User avatar
Moogs
Starting out
 
Posts: 25
Joined: Thu May 12, 2011 8:52 am
Location: In the Hood
NAS Model: TS-559 Pro II

Re: Error code: ssl_error_renegotiation_not_allowed

Postby schumaku » Fri May 13, 2011 3:32 pm

Yes - however there is a good reason _not_ to enable this insecure behaviour, because a men in the middle has the option to triger a re-negotiation i.e. to plain http.

QNAP must update the OpenSSL so the new secure re-negotiation becomes available.
User avatar
schumaku
Guru
 
Posts: 22586
Joined: Mon Jan 21, 2008 4:41 pm
Location: Kloten (Zurich), Switzerland -- Skype: schumaku
NAS Model: TS-x79 Pro

Re: Error code: ssl_error_renegotiation_not_allowed

Postby River Trent » Fri May 13, 2011 4:23 pm

So it is a QNAP issue.

I agree with schumaku.
User avatar
River Trent
Getting the hang of things
 
Posts: 80
Joined: Wed Dec 02, 2009 10:24 pm
NAS Model: TS-419U

Re: Error code: ssl_error_renegotiation_not_allowed

Postby River Trent » Mon May 16, 2011 5:51 pm

Has anyone any idea if this will be done soon as it's a major problem for me???
User avatar
River Trent
Getting the hang of things
 
Posts: 80
Joined: Wed Dec 02, 2009 10:24 pm
NAS Model: TS-419U

Re: Error code: ssl_error_renegotiation_not_allowed

Postby River Trent » Wed May 18, 2011 1:44 am

Bump
User avatar
River Trent
Getting the hang of things
 
Posts: 80
Joined: Wed Dec 02, 2009 10:24 pm
NAS Model: TS-419U

Re: Error code: ssl_error_renegotiation_not_allowed

Postby schumaku » Wed May 18, 2011 3:50 am

River Trent wrote:Has anyone any idea if this will be done soon as it's a major problem for me???
If it's just your own browser I hardly see a major problem, as the workaround is well known.

What do you expect from bumping?
User avatar
schumaku
Guru
 
Posts: 22586
Joined: Mon Jan 21, 2008 4:41 pm
Location: Kloten (Zurich), Switzerland -- Skype: schumaku
NAS Model: TS-x79 Pro

Re: Error code: ssl_error_renegotiation_not_allowed

Postby River Trent » Wed May 18, 2011 7:07 pm

Fair comment for "bumping",

But it's not just my own browser, I have a lot of members to the site and a few of them are using firefox 4, and hence get the " Error code: ssl_error_renegotiation_not_allowed".
User avatar
River Trent
Getting the hang of things
 
Posts: 80
Joined: Wed Dec 02, 2009 10:24 pm
NAS Model: TS-419U

Re: Error code: ssl_error_renegotiation_not_allowed

Postby schumaku » Fri May 20, 2011 1:31 am

About what I guessed anyway, was not difficult.
User avatar
schumaku
Guru
 
Posts: 22586
Joined: Mon Jan 21, 2008 4:41 pm
Location: Kloten (Zurich), Switzerland -- Skype: schumaku
NAS Model: TS-x79 Pro

Re: Error code: ssl_error_renegotiation_not_allowed

Postby River Trent » Tue May 24, 2011 5:38 pm

Firmware version: 3.4.3 Build 0520T has not fixed the problem.
User avatar
River Trent
Getting the hang of things
 
Posts: 80
Joined: Wed Dec 02, 2009 10:24 pm
NAS Model: TS-419U

Re: Error code: ssl_error_renegotiation_not_allowed

Postby River Trent » Thu Jun 16, 2011 4:30 pm

Any news anyone, really could do with this fixing
User avatar
River Trent
Getting the hang of things
 
Posts: 80
Joined: Wed Dec 02, 2009 10:24 pm
NAS Model: TS-419U

Re: Error code: ssl_error_renegotiation_not_allowed

Postby AlexKe » Mon Jun 20, 2011 6:19 pm

Hi River Trent,

The OpenSSL version is not that old to cause the https connection issue with Firefox 4.x.
Below is the setting on my test NAS. Can you how us your setting or you can PM me your NAS link for remote checking.

Web server setting.png

Virtual host setting.png

https connection on virtual host.png
You do not have the required permissions to view the files attached to this post.
AlexKe
Experience counts
 
Posts: 1829
Joined: Wed Jan 06, 2010 2:49 pm
NAS Model: Not Selected

Re: Error code: ssl_error_renegotiation_not_allowed

Postby schumaku » Mon Jun 20, 2011 6:25 pm

Alex, try to use the SAME PORT (8081) for all SSL Web servers in place ... it is a common agreed standard using 443 for ALL SSL Web connections. And you will find QNAP PM and RD lazyiness is guilty.
User avatar
schumaku
Guru
 
Posts: 22586
Joined: Mon Jan 21, 2008 4:41 pm
Location: Kloten (Zurich), Switzerland -- Skype: schumaku
NAS Model: TS-x79 Pro

Re: Error code: ssl_error_renegotiation_not_allowed

Postby schumaku » Mon Jun 20, 2011 6:39 pm

1. configure multiple DNS names pointing to the same cname, and some to the same IP address (both is correct) to your test NAS TCP/IP address.
2. Create multiple virtual hosts on these hostnames for SSL and the same ports - start ewith all on 8081, like the base Web server.
User avatar
schumaku
Guru
 
Posts: 22586
Joined: Mon Jan 21, 2008 4:41 pm
Location: Kloten (Zurich), Switzerland -- Skype: schumaku
NAS Model: TS-x79 Pro

Re: Error code: ssl_error_renegotiation_not_allowed

Postby AlexKe » Thu Jun 23, 2011 12:20 pm

Hi Folks,

https://wiki.mozilla.org/Security:Reneg ... lable_pref

security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref
Current default value: DEPENDS, see end of section

It's not desirable to set this to true, as it completely disables the new protection mechanisms. However, in controlled environments where many old new server must be accessed, this may be used.

It's highly recommended to leave this at the default value “false”, and instead populate preference security.ssl.renego_unrestricted_hosts with a list of hosts that require the exception.

The preference carries “temporarily_available_pref” in its name, as it's supposed to go away later.

Regarding default values:

current development versions (including Firefox 4 beta) use “false”.
The stable releases 3.5.9 and 3.6.2 use “true”.
It's not yet decided which default value will be used for the stable Firefox 4 release.

Advice: just try the way which Moogs mentioned about.
You do not have the required permissions to view the files attached to this post.
AlexKe
Experience counts
 
Posts: 1829
Joined: Wed Jan 06, 2010 2:49 pm
NAS Model: Not Selected

Next

Return to Web Server & Applications (Apache + PHP + MySQL / SQLite)

Who is online

Users browsing this forum: No registered users and 5 guests