403 Forbidden from client - Seeding PRNG with 0 bytes of entropy

403 Forbidden from client - Seeding PRNG with 0 bytes of entropy

am 08.01.2005 20:51:51 von Devin Tuinstra

This is a multi-part message in MIME format.

------=_NextPart_000_0004_01C4F591.961D4460
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: 7bit

I had a webserver running with this exact same setup recently and have moved
to a new server.



I am running:

Apache/2.0.52 (FreeBSD) PHP/4.3.10 mod_ssl/2.0.52 OpenSSL/0.9.7d
mod_perl/1.99_18 Perl/v5.8.5



I created a new csr on the new server and had a certificate re-issued from
my authority.

Now when I load up the https using the same configuration as the old
server.. I get 403 Forbidden in the browser.



The httpd error-log looks like this:



[Sat Jan 08 14:43:12 2005] [info] Connection to child 5 established (server
www.ocsd.ca:443, client 65.92.64.70)

[Sat Jan 08 14:43:12 2005] [info] Seeding PRNG with 0 bytes of entropy

[Sat Jan 08 14:43:12 2005] [debug] ssl_engine_kernel.c(1771): OpenSSL:
Handshake: start

[Sat Jan 08 14:43:12 2005] [debug] ssl_engine_kernel.c(1779): OpenSSL: Loop:
before/accept initialization

[Sat Jan 08 14:43:12 2005] [debug] ssl_engine_io.c(1506): OpenSSL: read
11/11 bytes from BIO#98d2ac0 [mem: b434000] (BIO dump foll



[Sat Jan 08 14:43:12 2005] [info] Initial (No.1) HTTPS request received for
child 5 (server www.ocsd.ca:443)

[Sat Jan 08 14:43:12 2005] [error] [client 65.92.64.70] client denied by
server configuration: /home/domains/ocsd.ca/web/







I've looked all over and I have a feeling that the Seeding PRNG with 0 bytes
of entropy is the problem.. but I've done everything with ssl.conf in apache
to update with SSLRandomSeed startup file:/dev/random 512 etc etc..



But I can't seem to get that to change.. maybe I'm overlooking something.



Any help would be greatly appreciated,



Thanks,



Devin




------=_NextPart_000_0004_01C4F591.961D4460
Content-Type: text/html;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:st1=3D"urn:schemas-microsoft-com:office:smarttags" =
xmlns=3D"http://www.w3.org/TR/REC-html40">


charset=3Dus-ascii">

namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
name=3D"place"/>









style=3D'font-size:10.0pt;
font-family:Arial'>I had a webserver running with this exact same setup
recently and have moved to a new server.



style=3D'font-size:10.0pt;
font-family:Arial'> 



style=3D'font-size:10.0pt;
font-family:Arial'>I am running:



style=3D'font-size:10.0pt;
font-family:Arial'>Apache/2.0.52 (FreeBSD) PHP/4.3.10 mod_ssl/2.0.52
OpenSSL/0.9.7d mod_perl/1.99_18 Perl/v5.8.5



style=3D'font-size:10.0pt;
font-family:Arial'> 



style=3D'font-size:10.0pt;
font-family:Arial'>I created a new csr on the new server and had a =
certificate
re-issued from my authority.



style=3D'font-size:10.0pt;
font-family:Arial'>Now when I load up the https using the same =
configuration as
the old server.. I get 403 Forbidden in the =
browser.



style=3D'font-size:10.0pt;
font-family:Arial'> 



style=3D'font-size:10.0pt;
font-family:Arial'>The httpd error-log looks like =
this:



style=3D'font-size:10.0pt;
font-family:Arial'> 



style=3D'font-size:10.0pt;
font-family:Arial'>[Sat Jan 08 14:43:12 2005] [info] Connection to child =
5
established (server www.ocsd.ca:443, client =
65.92.64.70)



style=3D'font-size:10.0pt;
font-family:Arial'>[Sat Jan 08 14:43:12 2005] [info] Seeding PRNG with 0 =
bytes
of entropy



style=3D'font-size:10.0pt;
font-family:Arial'>[Sat Jan 08 14:43:12 2005] [debug]
ssl_engine_kernel.c(1771): OpenSSL: Handshake: =
start



style=3D'font-size:10.0pt;
font-family:Arial'>[Sat Jan 08 14:43:12 2005] [debug]
ssl_engine_kernel.c(1779): OpenSSL: w:st=3D"on">Loop:
before/accept initialization



style=3D'font-size:10.0pt;
font-family:Arial'>[Sat Jan 08 14:43:12 2005] [debug] =
ssl_engine_io.c(1506):
OpenSSL: read 11/11 bytes from BIO#98d2ac0 [mem: b434000] (BIO dump =
foll



style=3D'font-size:10.0pt;
font-family:Arial'><!—insert about 5 dumps =
-->



style=3D'font-size:10.0pt;
font-family:Arial'>[Sat Jan 08 14:43:12 2005] [info] Initial (No.1) =
HTTPS
request received for child 5 (server =
www.ocsd.ca:443)



style=3D'font-size:10.0pt;
font-family:Arial'>[Sat Jan 08 14:43:12 2005] [error] [client =
65.92.64.70]
client denied by server configuration: =
/home/domains/ocsd.ca/web/



style=3D'font-size:10.0pt;
font-family:Arial'> 



style=3D'font-size:10.0pt;
font-family:Arial'> 



style=3D'font-size:10.0pt;
font-family:Arial'> 



style=3D'font-size:10.0pt;
font-family:Arial'>I’ve looked all over and I have a feeling that =
the Seeding
PRNG with 0 bytes of entropy is the problem.. but I’ve done =
everything
with ssl.conf in apache to update with SSLRandomSeed startup
file:/dev/random  512    etc =
etc..



style=3D'font-size:10.0pt;
font-family:Arial'> 



style=3D'font-size:10.0pt;
font-family:Arial'>But I can’t seem to get that to change.. maybe =
I’m
overlooking something.



style=3D'font-size:10.0pt;
font-family:Arial'> 



style=3D'font-size:10.0pt;
font-family:Arial'>Any help would be greatly =
appreciated,



style=3D'font-size:10.0pt;
font-family:Arial'> 



style=3D'font-size:10.0pt;
font-family:Arial'>Thanks,



style=3D'font-size:10.0pt;
font-family:Arial'> 



style=3D'font-size:
12.0pt'>Devin



style=3D'font-size:
12.0pt'> 









------=_NextPart_000_0004_01C4F591.961D4460--

____________________________________________________________ __________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
User Support Mailing List modssl-users@modssl.org
Automated List Manager majordomo@modssl.org