LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > CentOS
User Name
Password
CentOS This forum is for the discussion of CentOS Linux. Note: This forum does not have any official participation.

Notices


Reply
  Search this Thread
Old 10-19-2018, 09:24 AM   #1
jfalvrz21
LQ Newbie
 
Registered: Oct 2018
Posts: 2

Rep: Reputation: Disabled
CentOS 7 nginx 1.14 with OpenSSL 1.1.1


Hello Community

Who can help me with this topic ?

I have a server with CentOS 7. I want to install nginx 14 with TLS 1.3

I compiled nginx 1.14.0 with openssl 1.1.1

[root@www ~]# nginx -V

nginx version: nginx/1.14.0 built by gcc 4.8.5 20150623 (Red Hat 4.8.5-28) (GCC) built with OpenSSL 1.1.1 11 Sep 2018
TLS SNI support enabled configure arguments: --prefix=/etc/nginx --sbin-path=/usr/sbin/nginx...

However, when I try the connection from Google Chrome or Firefox this error appears:

ERR_SSL_VERSION_OR_CIPHER_MISMATCH

When I checked the connection through of Openssl (openssl s_client -connect x.x.x.x:443)

The result shows this at the end:

---
read R BLOCK
R
RENEGOTIATING
HTTP/1.1 400 Bad Request
Server: nginx/1.14.0
Date: Fri, 19 Oct 2018 13:57:36 GMT
Content-Type: text/html
Content-Length: 173
Connection: close

<html>
<head><title>400 Bad Request</title></head>
<body bgcolor="white">
<center><h1>400 Bad Request</h1></center>
<hr><center>nginx/1.14.0</center>
</body>
</html>
140000528848704:error:1420410A:SSL routines:SSL_renegotiate:wrong ssl version:ssl/ssl_lib.c:2113:



Thanks
 
Old 10-19-2018, 09:28 AM   #2
sevendogsbsd
Senior Member
 
Registered: Sep 2017
Distribution: FreeBSD
Posts: 2,252

Rep: Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011
Does either browser support TLS 1.3? Not researched 1.3 so don't know status yet.
 
Old 10-19-2018, 09:42 AM   #3
jfalvrz21
LQ Newbie
 
Registered: Oct 2018
Posts: 2

Original Poster
Rep: Reputation: Disabled
I think yes, because the openssl is official https://www.openssl.org/news/openssl-1.1.1-notes.html

When I connect to Cloudflare or Facebook, they are using TLS 1.3

Best regards
 
Old 10-19-2018, 09:46 AM   #4
sevendogsbsd
Senior Member
 
Registered: Sep 2017
Distribution: FreeBSD
Posts: 2,252

Rep: Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011
Ah OK, good to know, I just didn't so seemed good first question.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to remove Openssl in CentOS 6.5? nkcedwin Linux - Newbie 7 01-20-2016 11:26 PM
I need openssl 32-bit on a CentOS 6.4 box. how? Dallas Caley Linux - Newbie 5 09-25-2013 04:40 PM
no package 'OpenSSL ' found [CentOS] amanacare Linux - Server 4 06-26-2012 03:20 AM
[SOLVED] Getting most secure version of openssl on CentOS 5 via yum tireswinger Linux - Software 4 01-29-2011 12:39 PM
Downgrading openssl on Centos onesikgypo Linux - Newbie 2 09-27-2010 08:51 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > CentOS

All times are GMT -5. The time now is 09:45 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration