PDA

View Full Version : ssl trouble


psyko
11-02-2004, 12:26 PM
i have just updated to the latest ffxp version (3.0.2...) and now i get this error:

[L] Connected. Negotiating TLSv1 session..
[L] error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
[L] 425 Can't open data connection.

i never had this error with older versions.

any idea?

Linkster
11-02-2004, 12:49 PM
use the search function...it works well. Change to AUTH-SSL. Your site doesn't support AUTH-TLS. In older versions, FlashFXP incorrectly issued AUTH-SSL even when AUTH-TLS was selected.

psyko
11-02-2004, 01:03 PM
not working. that site supports both, auth-tls and auth-ssl.

i'm using some kind of proxy (modified hpbnc with dynamic target-host) to connect to that site... workx with 3.0.

bigstar
11-02-2004, 02:46 PM
I'm really not sure, It should work exactly the same compared to v3.0. I didn't make any internal changes to the ssl/tls routines in v3.0.2.. The only change to ssl/tls was to auto close the certificate dialog when the ftp connection is lost.

The change linkster is referring to occured in v3.0 and not 3.0.2

psyko
11-02-2004, 03:07 PM
1. reinstalled 3.0 build 1015. works fine.
2. installed 3.0.2 build 1044 again...

[L] PWD
[L] 257 "/" is current directory.
[L] TYPE A
[L] 200 Type set to A.
[L] PROT P
[L] 200 Protection set to Private
[L] PASV
[L] 227 Entering Passive Mode (111,222,333,444,555,66)
[L] Opening data connection IP: 111.222.333.444 PORT: 59220
[L] LIST -al
[L] Connected. Negotiating TLSv1 session..
[L] error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
(soft abort)
[L] ABOR
[L] 425 Can't open data connection.
[L] List Error

:(

bigstar
11-02-2004, 03:54 PM
Would it be possible to give me access to this ftp server so that I can debug the situation? You can send me a private message with the info.

redpoint
11-02-2004, 04:07 PM
Interesting, I can confirm this bug. Usually I don't use hpbnc, but I tested this now. I found a couple of versions in my backups.

It works with a version 3.0 Build 1010 RC4.

It does not work with 3.0.1.1039
It does not work with 3.0.2 build 1044

Maybe it's possible for the developers to test with hpbnc. It's called "hpbnc.v1.5 test2".

Ftp server is glftpd.

bigstar
11-02-2004, 05:24 PM
I have no way of testing this setup. If someone can provide me with a test site I can look into this further.

djrob
11-03-2004, 06:42 PM
Looks a bit like this:

http://forum.flashfxp.com/showthread.php?s=&threadid=4671

(which still is a major problem) :(

bigstar
11-03-2004, 08:29 PM
Actually this bug has nothing to do with ssl. There is a bug in the proxy support (except types socks/http) in v3.0.2.. We will be releasing an update very soon to address this issue.

MadCowFred
12-01-2004, 05:04 AM
I'm having the same issue, but with a PureFTPd server. Not sure if older FlashFXP versions work, though. lftp (UNIX client) can connect fine. I can make a test account available if you need one :)

FlashFXP v3.0.2 (build 1045)
PureFTPD v1.0.20

[L] 200 PORT command successful
[L] LIST -al
[L] Connected. Negotiating TLSv1 session..
[L] 150 Connecting to port 10153
[L] error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
[L] error:14095044:SSL routines:SSL3_READ_N:internal error

bigstar
12-01-2004, 09:17 AM
Is this a public site that we can test?

MadCowFred
12-01-2004, 09:23 AM
Just enabled anonymous, ftp://zort.madcowdisease.org :)

bigstar
12-01-2004, 10:31 AM
There appears to be a problem with FlashFXP

The server is returning an error indicating a secure data connection is not allowed or supported and FlashFXP is not taking this into consideration and trying to establish a secure connection anyways.

[08:25:41] 250 OK. Current directory is /
[08:25:41] PWD
[08:25:41] 257 "/" is your current location
[08:25:41] TYPE A
[08:25:41] 200 TYPE is now ASCII
[08:25:42] PROT P
[08:25:42] 534 Fallback to [C]

In this case FlashFXP should revert to unsecure mode for the data connection.

Thank you for your bug report, this will be resolved in the next release.

Fifer
12-03-2004, 05:18 PM
hi , exact same problem here , glad you you are already on the case. Just wanted to know if there is a temp soloution to this niggling bug ?

Thanks for youre kind assistance.






P.S a Happy Flash fxp user ;)

bigstar
12-03-2004, 05:29 PM
Due to the nature of this problem there is no way to work around the problem. You'll need to wait for the next release.

Fifer
12-03-2004, 05:58 PM
damn, o well i appreciate the fast response. thanks.

chotaire
12-03-2004, 06:45 PM
[message deleted]

bigstar
12-04-2004, 10:40 AM
This didn't come to me until just now, but why not just uncheck the options "Secure File Listing" and "Secure File Transfers" in the Site Manager > SSL Tab

That should work

nic
12-17-2004, 05:27 AM
hi have u worked this bug out yet? if not can someone point me back to the most stable one so i can get rid of this eror it just drives me nuts



lol edit why does my profile say unregistered i bought this program hehe

Mouhamed
12-28-2004, 03:22 PM
I wanna report an other bug...

When you use "Implicit SSL" you cannot switch off secure data connection :eek:
So FlashFXP do something like that :

[R] PROT P
[R] 200 Protection set to Private


But what i want is a "PROT C" :D . Any quick fix ? :confused:

Linkster
12-29-2004, 01:11 AM
This has been "fixed" in the latest beta release. If you are a registered user, you can download it now from the customer portal. If not, you will have to wait for the public beta release.

Mouhamed
12-29-2004, 05:52 AM
Ok thx it works ;)
But i still need the UPNP support for active mode :p

I will wait next release :)