Uploaded image for project: 'Couchbase Server'
  1. Couchbase Server
  2. MB-19174

ns_server closes/rejects ssl connections when it's not happy with default cipher list

    XMLWordPrintable

Details

    • Task
    • Resolution: Unresolved
    • Major
    • None
    • 3.0.2, 4.5.0
    • ns_server
    • None

    Description

      This can only be reproduced on Mac OS X. To reproduce, obtain libcouchbase version 2.5.7 on OS X:

      Looking at the logs:
      [error_logger:error,2016-04-12T13:29:46.695-07:00,ns_1@127.0.0.1:error_logger<0.6.0>:ale_error_logger_handler:do_log:203]
      =========================ERROR REPORT=========================
      application: mochiweb
      "Accept failed error"
      "{'EXIT',\n {{function_clause,\n [{tls_v1,enum_to_oid,[28],[

      {file,\"tls_v1.erl\"}

      ,

      {line,404}

      ]},\n {ssl_handshake,'dec_hello_extensions/2-blc$^1/1-0',1,\n [

      {file,\"ssl_handshake.erl\"},{line,1657}]},\n {ssl_handshake,'dec_hello_extensions/2-blc$^1/1-0',1,\n [{file,"ssl_handshake.erl"}

      ,

      {line,1657}]},\n {ssl_handshake,dec_hello_extensions,2,\n [{file,\"ssl_handshake.erl\"},{line,1657}

      ]},\n {tls_handshake,decode_handshake,3,\n [

      {file,\"tls_handshake.erl\"},{line,182}]},\n {tls_handshake,get_tls_handshake_aux,3,\n [{file,"tls_handshake.erl"}

      ,

      {line,153}

      ]},\n {tls_connection,next_state,4,\n [

      {file,\"tls_connection.erl\"}

      ,

      {line,454}

      ]},\n {gen_fsm,handle_msg,7,[

      {file,\"gen_fsm.erl\"}

      ,

      {line,505}

      ]}]},\n {gen_fsm,sync_send_all_state_event,\n [<0.23229.6>,

      {start,infinity}

      ,infinity]}}}"

      [error_logger:error,2016-04-12T13:29:46.695-07:00,ns_1@127.0.0.1:error_logger<0.6.0>:ale_error_logger_handler:do_log:203]

      To fix this, I needed to explicitly add a list of supported ciphers (https://github.com/couchbase/libcouchbase/commit/dd67004083d2611abd5a2f6a8fd20cd14cd1755c). This is only a problem with ns_server, and not memcached. If there is some magic cipher string to use, is it published somewhere?

      Attachments

        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

        Activity

          People

            Aliaksey Artamonau Aliaksey Artamonau (Inactive)
            mnunberg Mark Nunberg (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:

              Gerrit Reviews

                There are no open Gerrit changes

                PagerDuty