SSL internal server errors

SSL internal server errors

am 16.12.2002 17:06:48 von giorgos zervas

hi all,

i have been encountering a pretty strange problem on my webserver since
i caught the slapper work a few weeks ago.

all https connections to cgi scripts produce an internal server error
sometimes together will this message in the log file:

OpenSSL: error:1406B458:SSL routines:GET_CLIENT_MASTER_KEY:key arg too
long

after some research and consultation with support staff from thawtee, my
certificate issuer, i was told that i have to have my certificate
reissued as the worm has corrupted it. i have replaced the certificate
with the brand new one i ordered but i still have the same problems.

i also tried disabling SSLv2 but to no avail.

static pages work fine under https and the cgi scripts that fail under
https work fine under http.

i have upgraded all relevant software and removed the worm. does anyone
else have the same problem or any clue on what could be causing it?

my setup is redhat 7.3 with:
apache 1.3.27 + mod_ssl 2.8.12 + openssl 0.9.6b

any help will be greatly appreciated.

many thanks
giorgos



____________________________________________________________ __________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
User Support Mailing List modssl-users@modssl.org
Automated List Manager majordomo@modssl.org