Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Tue Mar 17, 2015 11:24 am 
Offline
Newbie

Joined: Tue Mar 17, 2015 1:25 am
Posts: 2
Leadup:
- Set up a wordpress linode.
- Imported a wordpress site.
- Everything worked.
- Added an ssl certificate from godaddy. It looks like the SSL certificate is installed correctly:
https://www.sslshopper.com/ssl-checker. ... asa-ny.com
- Everything still works, with one caveat.

Issue:
On some machines, people receive the following:
Unable to make a secure connection to the server. This may be a problem with the server, or it may be requiring a client authentication certificate that you don't have.
Error code: ERR_SSL_PROTOCOL_ERROR

Pattern:
The only real pattern I can see is that people with Time Warner in their office cannot load the site.

Evidence and Thoughts:
1) The site works on my laptop and my phone, but when I connected to the wifi in the office with Time Warner, it stopped working. They had an Arris TG### router from Time Warner.
2) Other people complained that they can't load the site with the same error and I confirmed that they are also using Time Warner.
3) No idea if this would be related to the router or the ISP.
4) Have tested this with other friends in various locations without any problems.

This is just a theory and any other ideas and solutions/suggestions would be very helpful.


Top
   
PostPosted: Tue Mar 17, 2015 11:31 am 
Offline
Senior Member

Joined: Mon Jul 05, 2010 5:13 pm
Posts: 392
Ah, got it from your link. I much prefer ssllabs test suite, since it'll clarify what I suspect is at the root of this issue: which clients can/cannot negotiate with your server given its TLS/SSL config:

https://www.ssllabs.com/ssltest/analyze ... asa-ny.com

Based on that, it seems possible that the browsers or networks those people are using are dropping SSLv3 traffic. Given the issues with your SSL config, I'd suggest cleaning up your ciphers and settings based on the advice given by ssllabs and then seeing what happens.

- Les


Last edited by akerl on Tue Mar 17, 2015 11:35 am, edited 1 time in total.

Top
   
PostPosted: Tue Mar 17, 2015 11:34 am 
Offline
Newbie

Joined: Tue Mar 17, 2015 1:25 am
Posts: 2
Thanks. The link was very helpful. I resolved the POODLE security issue, but that didn't resolve the problem.

As I discovered at the following link, it was an issue with ipv6:
http://serverfault.com/questions/676171 ... 200#676200


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group