Error code: ssl_error_renegotiation_not_allowed

Post your questions about Web Server usage and Apache + PHP + MySQL/SQLite web applications.

Re: Error code: ssl_error_renegotiation_not_allowed

Postby doktornotor » Thu May 17, 2012 5:22 am

forkless wrote:Hello QNAP,


Hello, it has only been one year, not enough time to recompile with non-fscked openssl! :roll: :lol:
QNAP, why is your homework still not done?
3.8.2 Build0301 - Codename "Titanic" - Dear customer, GTFO! NOT acceptable once again!
QTS 4.0 - Codename "Leaky Snail" - Slower than ever. Yes, we can!
QNAP's new logo competition
User avatar
doktornotor
Experience counts
 
Posts: 2651
Joined: Tue Apr 24, 2012 5:44 am
NAS Model: Not Selected

Re: Error code: ssl_error_renegotiation_not_allowed

Postby schumaku » Thu May 17, 2012 5:09 pm

doktornotor wrote:Hello, it has only been one year, not enough time to recompile with non-fscked openssl! :roll: :lol:

What's a year in a human life? :shock:
Whats a year in the earth history? :evil:
User avatar
schumaku
Guru
 
Posts: 22283
Joined: Mon Jan 21, 2008 4:41 pm
Location: Kloten (Zurich), Switzerland -- Skype: schumaku
NAS Model: TS-x79 Pro

Re: Error code: ssl_error_renegotiation_not_allowed

Postby forkless » Thu May 17, 2012 8:19 pm

schumaku wrote:
doktornotor wrote:Hello, it has only been one year, not enough time to recompile with non-fscked openssl! :roll: :lol:

What's a year in a human life? :shock:
Whats a year in the earth history? :evil:


It's definitely not long enough to fix a core Apache functionality. But boy, I am glad it now supports MORE flaky webcams nobody ever heard about...
TS-219P+ II
TS-809 PRO
User avatar
forkless
Been there, done that
 
Posts: 944
Joined: Mon Nov 23, 2009 6:52 am
Location: The Netherlands
NAS Model: TS-809 Pro

Re: Error code: ssl_error_renegotiation_not_allowed

Postby forkless » Wed May 23, 2012 8:29 am

*bump
TS-219P+ II
TS-809 PRO
User avatar
forkless
Been there, done that
 
Posts: 944
Joined: Mon Nov 23, 2009 6:52 am
Location: The Netherlands
NAS Model: TS-809 Pro

Re: Error code: ssl_error_renegotiation_not_allowed

Postby doktornotor » Sat Jun 09, 2012 6:46 pm

You've gotta be kidding us, QNAP. The excerpt from the "latest and greatest" (now pulled) 3.7.0's phpinfo:

Code: Select all
SSL_VERSION_LIBRARY   OpenSSL/0.9.7a
openssl
OpenSSL support   enabled
OpenSSL Library Version   OpenSSL 0.9.7a Feb 19 2003
OpenSSL Header Version   OpenSSL 0.9.7a Feb 19 2003


And:

Code: Select all
# locate libssl
/lib/libssl.so
/lib/libssl.so.0
/lib/libssl.so.0.9.7

# file /lib/libssl.so.0.9.7
/lib/libssl.so.0.9.7: ELF 32-bit LSB shared object, ARM, version 1 (SYSV), dynamically linked, stripped


So, you actually downgraded the buggy multi-vulnerable ** even further?!?!

:evil: :twisted: :x :!: :?:
QNAP, why is your homework still not done?
3.8.2 Build0301 - Codename "Titanic" - Dear customer, GTFO! NOT acceptable once again!
QTS 4.0 - Codename "Leaky Snail" - Slower than ever. Yes, we can!
QNAP's new logo competition
User avatar
doktornotor
Experience counts
 
Posts: 2651
Joined: Tue Apr 24, 2012 5:44 am
NAS Model: Not Selected

Re: Error code: ssl_error_renegotiation_not_allowed

Postby River Trent » Sat Jul 14, 2012 3:07 am

Still waiting . . . . .
User avatar
River Trent
Getting the hang of things
 
Posts: 80
Joined: Wed Dec 02, 2009 10:24 pm
NAS Model: TS-419U

Re: Error code: ssl_error_renegotiation_not_allowed

Postby grobylev » Sat Jul 14, 2012 3:58 am

:) being a software developer for some time now, I learned one thing:
Making mistakes is not a problem. Not fixing those problems are...

u'd better start to think on some alternative solution IMO... unless you'll find yourself waiting another one year wasting and waiting... :shock:
QNAP TS-459Pro II 4x2TB in RAID5 3GB RAM | Trunking: IEEE 802.3ad on Cisco SLM2008 | protected by APC SMT1500I with AP9631
QPKGs: Optware, JRE, Python, CrashPlan, DropBox, Squid, Transmission | Router: Linksys E3000 | FW: DD-WRT v24-sp2 mega
User avatar
grobylev
Know my way around
 
Posts: 227
Joined: Fri Jul 22, 2011 2:19 am
Location: Budapest, Hungary
NAS Model: TS-459 Pro II

Re: Error code: ssl_error_renegotiation_not_allowed

Postby forkless » Sun Jul 15, 2012 3:53 pm

Grobylev,

Let me start with saying i'm not angry at you I just taking your observation to comment on the situation ;)

While there are alternatives the problem lies in the fact that the current OpenSSL implementation is not a mistake, it's not even a matter of moral culpability anymore. It is downright criminal negligent. Do not forget that the bulk of the users/owners here do NOT have means of updating their QNAP like a regular OS.

While I myself could easily upgrade the OS to a modded Debian (or whatever flavour) OS. Having to revert to modding a QNAP however to use another OS is beyond reasonable. Not to mention that it implies forfeiting all your OEM OS support on the product itself.

QNAP should get of their lazy ***** and fix this issue for people who can't and want to maintain a secure and reliable platform instead of facilitating every ******* hacker and their smelly cousin.

Cheers,
Fork


ps. Do I sound angry? You bet! I am.
TS-219P+ II
TS-809 PRO
User avatar
forkless
Been there, done that
 
Posts: 944
Joined: Mon Nov 23, 2009 6:52 am
Location: The Netherlands
NAS Model: TS-809 Pro

Re: Error code: ssl_error_renegotiation_not_allowed

Postby grobylev » Sun Jul 15, 2012 4:44 pm

:) I agree that the word 'mistake' is not the best here -- I should've use 'not so up to date' , or 'full with security bugs' instead, but I think you got what I mean.
What I've trying to say is that - according to my observations -, if a feature/security issue/whatever else is really important to you, you'd better resolve it by you own instead of waiting years/months to a manufacturer...

Yes, a lot of 'customers' may not know what openssl is (or even what's the difference between http/https)... just having their webpage up and running... without knowing that their stuff can be...
And I do not want to comment on that for a manufacturers the marketing is more important (like new Time Machince, etc... just because they want to update their 'feature list' to sell more products) than security.
So it looks to me that QNAP decided to be a SOHO NAS - to put your family photos on - , and not to be used in some super-secure-enterprise-bank-fbi environment.

Installing some custom OS in a QNAP device is not the only option, you can also sell it and buy Synology instead for example... much quicker/easier/...
It's your choice, just like their when they're deciding to add some another useless feature instead of maintaining the existing ones.

P.S.: I'm on your side. :)
QNAP TS-459Pro II 4x2TB in RAID5 3GB RAM | Trunking: IEEE 802.3ad on Cisco SLM2008 | protected by APC SMT1500I with AP9631
QPKGs: Optware, JRE, Python, CrashPlan, DropBox, Squid, Transmission | Router: Linksys E3000 | FW: DD-WRT v24-sp2 mega
User avatar
grobylev
Know my way around
 
Posts: 227
Joined: Fri Jul 22, 2011 2:19 am
Location: Budapest, Hungary
NAS Model: TS-459 Pro II

Re: Error code: ssl_error_renegotiation_not_allowed

Postby schumaku » Sun Jul 15, 2012 7:38 pm

Look: Fact is the QNAP Linux in place is highly outdated - plenty of limitaitons and issues with the outdated Kernel and libraries. This does simply prohibit updating OpenSSL just for example. Ridiculous situation.
User avatar
schumaku
Guru
 
Posts: 22283
Joined: Mon Jan 21, 2008 4:41 pm
Location: Kloten (Zurich), Switzerland -- Skype: schumaku
NAS Model: TS-x79 Pro

Re: Error code: ssl_error_renegotiation_not_allowed

Postby doktornotor » Sun Jul 15, 2012 8:10 pm

grobylev wrote:So it looks to me that QNAP decided to be a SOHO NAS - to put your family photos on - , and not to be used in some super-secure-enterprise-bank-fbi environment.


Not even SOHO is a good use for this. To the contrary, some "family photos" may be highly sensitive and you definitely do not want them leaked all over internet. And again - the previous version has been already seriously outdated, vulnerable and buggy and missing many features. However, there simply is absolutely no excuse for downgrading to 0.9.7a by mistake or whatnot. Why does anyone with sane mind have something like that installed and miscompiles bunch of firmwares against that junk as a result goes beyond me. Lame, seriously lame. :x
QNAP, why is your homework still not done?
3.8.2 Build0301 - Codename "Titanic" - Dear customer, GTFO! NOT acceptable once again!
QTS 4.0 - Codename "Leaky Snail" - Slower than ever. Yes, we can!
QNAP's new logo competition
User avatar
doktornotor
Experience counts
 
Posts: 2651
Joined: Tue Apr 24, 2012 5:44 am
NAS Model: Not Selected

Re: Error code: ssl_error_renegotiation_not_allowed

Postby ts-ec1279u-rp » Sun Aug 19, 2012 9:39 pm

Hi Qnap (AlexKe),

How is the fix progressing? Is it planned for the coming firmware release or a later one? Any rough date available?
ts-ec1279u-rp
First post
 
Posts: 1
Joined: Sat Jun 23, 2012 7:09 pm
NAS Model: TS-x79 Pro

Re: Error code: ssl_error_renegotiation_not_allowed

Postby doktornotor » Mon Aug 20, 2012 7:37 pm

ts-ec1279u-rp wrote:How is the fix progressing?


Backwards... :roll:

devolution-of-communication.jpg
You do not have the required permissions to view the files attached to this post.
QNAP, why is your homework still not done?
3.8.2 Build0301 - Codename "Titanic" - Dear customer, GTFO! NOT acceptable once again!
QTS 4.0 - Codename "Leaky Snail" - Slower than ever. Yes, we can!
QNAP's new logo competition
User avatar
doktornotor
Experience counts
 
Posts: 2651
Joined: Tue Apr 24, 2012 5:44 am
NAS Model: Not Selected

Re: Error code: ssl_error_renegotiation_not_allowed

Postby vinajb » Sat Sep 08, 2012 5:13 pm

Did anyone find a non-firefox workaround for this? Can we manually upgrade openssl on the box? I still encounter these issues and would like to get rid of it.
vinajb
New here
 
Posts: 2
Joined: Sat Sep 08, 2012 4:40 pm
NAS Model: TS-859 Pro+

Re: Error code: ssl_error_renegotiation_not_allowed

Postby forkless » Sat Sep 08, 2012 7:21 pm

The toolchain to compile sources is available on the QNAP (via Optware) so you can compile and install any binary or module you wish.

One can obviously argue whether your want to be part of the problem or the solution but the point is that these are core security updates that should be part of QNAP patch/security management cycles and not something the community has to pick up.

What irks me even more is that QNAP has the hubris to refuse to communicate about the issue. Which has been ongoing for years now, clearly QNAP management seems to think we rather have a slick as a babies bottom ajax driven admin interface than a secure and stable platform.
TS-219P+ II
TS-809 PRO
User avatar
forkless
Been there, done that
 
Posts: 944
Joined: Mon Nov 23, 2009 6:52 am
Location: The Netherlands
NAS Model: TS-809 Pro

PreviousNext

Return to Web Server & Applications (Apache + PHP + MySQL / SQLite)

Who is online

Users browsing this forum: No registered users and 5 guests