TLS error 'Failed in proxy receive'

Alan DeKok aland at deployingradius.com
Fri Aug 23 13:27:16 CEST 2019


On Aug 23, 2019, at 6:18 AM, Sharma, Nitin via Freeradius-Users <freeradius-users at lists.freeradius.org> wrote:

  Please don't CC me on messages to the list.  In case you hadn't noticed, I *am* subscribed to the list.

> I started seeing below errors related to TLS.

  So... what changed?  Software doesn't magically change it's behaviour.

  And what versions are you running?  i.e. FreeRADIUS, OpenSSL, etc.

> ```
> Fri Aug 23 09:57:32 2019 : Error: tls: Failed in proxy receive
> Fri Aug 23 09:57:32 2019 : Error: tls: error:140F3042:SSL routines:ssl_undefined_const_function:called a function you should not call
> Fri Aug 23 09:57:32 2019 : Error: tls: error:140E0197:SSL routines:SSL_shutdown:shutdown while in init
> Fri Aug 23 09:57:32 2019 : Error: tls: error:140E0197:SSL routines:SSL_shutdown:shutdown while in init
> Fri Aug 23 09:57:32 2019 : Error: tls: error:140F3042:SSL routines:ssl_undefined_const_function:called a function you should not call
> Fri Aug 23 09:57:32 2019 : Error: tls: error:140E0197:SSL routines:SSL_shutdown:shutdown while in init
> Fri Aug 23 09:57:32 2019 : Error: tls: error:140E0197:SSL routines:SSL_shutdown:shutdown while in init
> Fri Aug 23 09:57:32 2019 : Error: tls: error:140F3042:SSL routines:ssl_undefined_const_function:called a function you should not call
> Fri Aug 23 09:57:32 2019 : Error: tls: error:140E0197:SSL routines:SSL_shutdown:shutdown while in init
> Fri Aug 23 09:57:32 2019 : Error: tls: error:140E0197:SSL routines:SSL_shutdown:shutdown while in init
> Fri Aug 23 09:57:32 2019 : Error: tls: error:140F3042:SSL routines:ssl_undefined_const_function:called a function you should not call
> Fri Aug 23 09:57:32 2019 : Error: tls: error:140E0197:SSL routines:SSL_shutdown:shutdown while in init
> Fri Aug 23 09:57:32 2019 : Error: tls: error:140E0197:SSL routines:SSL_shutdown:shutdown while in init
> ```
> 
> Any suggestion on this will really help.

  Upgrade OpenSSL to a version that isn't broken.

  There's a commit in OpenSSL from 2016 that fixes this issue.

https://github.com/openssl/openssl/commit/64193c8218540499984cd63cda41f3cd491f3f59

  Alan DeKok.




More information about the Freeradius-Users mailing list