PDA

View Full Version : Unable to reset/view SSL cert


lasse_d
11-23-2005, 12:57 PM
FlashFXP 3.3.4.1109 (registered) on windows 2000, running behind nat/fw (openbsd box) on ADSL.
On the other end is gLFTpD 2.00+TLS (linux).

This is the log i get:
[18:07:26] [R] AUTH TLS
[18:07:26] [R] 234 AUTH TLS successful
[18:07:26] [R] Connected. Negotiating TLSv1 session..
[18:07:26] [R] TLSv1 negotiation successful...
[18:07:26] [R] TLSv1 encrypted session using cipher DHE-DSS-AES256-SHA (256 bits)
[18:07:27] [R] Connection failed
[18:07:27] [R] Delaying for 120 seconds before reconnect attempt #1


Problem:
There isn't stored any certificate for this specific site in my settings. If I choose to use TLS or SSL, I do not get a "accept/decline/show cert" popup. I cannot reset the cert - the tab is not activated.
I assume there is something stored in a .dat file somewhere that is messed up, but I have no idea how to get rid of it and still keep my settings on the other sites.
I tried ffxp on another box, connected to the same site and was presented with a cert. The login went fine there - no problems.

My sites.dat is probably very old - I've used ffxp for a very long time.

I can connect to other sites just fine, with or without SSL/TLS. On new sites i'm presented with the cert. But with this one site I cannot do anything.

Is there a way for me to reset the cert, or remove the site from any and all settings w/o removing the other stored sitedata?

Regards,

Lasse

bigstar
11-23-2005, 02:25 PM
Can other people log into the site without problems using secure mode?

The certificate isn't stored until you save it, which hasn't occured yet. The certificate information that gets saved is only used as reference as plays no part in the actual authentication procedure, so nothing in your .dat file is causing the problem.

You don't see the certificate dialog on this site because the "Connection failed" message appears before the certificate dialog is displayed.

My guess is that the ftp server isn't configured properly for secure connections.

lasse_d
11-23-2005, 03:46 PM
Thank you for a quick reply.

Yes, other people can log in fine. As previously stated, so can I if I use a different box (both boxes are nat'ed, so the public ip is the same) using the same version of ffxp.

I tried to install ffxp into a new dir, to see if there were anything with the "old" files.
I was greeted with an error that said (in norwegian, so i'll try to translate) "FlashFXP: flashfxp.exe - Could not find ordinal ; Ordinal 3719 was not found in library for dynamic connections LIBEAY32.dll".
After pressing OK on this, ffxp started as normal. I then tried to quick connect to the site, with the same result. I also tried to connect to one of my old sites using quick connect - and this too failed in the same manner.

I can only assume something with the ssl libs (or a cert somewhere) is broken. There's no extra libeay32.dll or ssleay32.dll libs anywhere - they're only in the ffxp dirs.

If you can shed some light on this issue, it's greatly appreciated.

Regards,

Lasse

bigstar
11-23-2005, 03:53 PM
It sounds like a problem with the openssl dlls.

That startup error will completely mess up SSL in FlashFXP.

When FlashFXP starts up, it displays the OpenSSL version info. i.e. WinSock 2.0 -- OpenSSL 0.9.8a 11 Oct 2005

What does your copy of FlashFXP say?

You might try taking the two OpenSSL dlls from the working computer and put them in the folder of the non-working FlashFXP and see if that solves the problem.

lasse_d
11-24-2005, 10:29 AM
Well, i don't know if that will help much. I've downloaded the newest version from your web, and install it. They all show the same info:

FlashFXP v3.3.4 build 1109 [BETA RELEASE]
Support Forums at http://forum.inicom.net
[16:20:42] WinSock 2.0 -- OpenSSL 0.9.8a 11 Oct 2005

I suspected the dll's as well, but I can't see how that is possible. Each installdir has their own dll's - there's no "extra" dll's floating in the winnt dir. It's also weird that i get the error on one install (the new one) and not the other one - on the same computer.
Can it be some registry settings that are messed up?
The new install (giving the error) is done with the newest FlashFXP_34_Beta4_Setup.exe installer. So is the one on the other computer (working fine).

bigstar
11-24-2005, 01:51 PM
Yeah, that is very strange. As far as I know these dll's don't use any registry settings. Also these OpenSSL dlls are fairly new, It's possible that there's something wrong with them.

You might try installing FlashFXP v3.2 final from our website and see if that version works with the site that doesn't work with the beta release.

lasse_d
11-24-2005, 02:48 PM
Thank you for taking the time to answer.
I'll tinker a bit more - see if there's anything that makes sense. If I find an answer, I'll post again.
I really doubt it has anything to do with this particular site - I cannot connect to my "regular" sites with the new install either. I can on the other box though.

Anyway, I appreciate the time spent answering my question.

Regards,

Lasse D.