v1.5.3 Bug Reports and Comments

DOWNLOAD THE LATEST FIRMWARE HERE
User avatar
Omniflux
Experienced Member
 
Posts: 113
Joined: Tue Feb 24, 2015 3:04 pm
Has thanked: 5 times
Been thanked: 32 times

Re: v1.5.3 Bug Reports and Comments

Sat Aug 17, 2019 10:53 pm

I tried to access a switch through a reverse proxy today, but the proxy complained

Code: Select all
 SSL_do_handshake() failed (SSL: error:141A318A:SSL routines:tls_process_ske_dhe:dh key too small) while SSL handshaking to upstream


Can you update the SSL configuration to use a larger DH key? Many SSL libraries won't connect with a 1024 bit key anymore due to the logjam vulnerability.

I don't have any switches configured with internet access in general, but I connected one to run an SSL diagnosis (https://www.ssllabs.com/ssltest/) while trying to figure this out, and the report was not good. You sell enough switches that I'm sure there are people out there who do assign publicly routable addresses to their devices, so maybe updating to a current SSL library is warranted?

mlow
Member
 
Posts: 29
Joined: Fri Jan 01, 2016 11:17 pm
Location: Crawford Bay
Has thanked: 10 times
Been thanked: 0 time

Re: v1.5.3 Bug Reports and Comments

Sun Aug 18, 2019 9:56 am

Stephen wrote:I'll add that to the list of things to fix.
In the mean time, if you have the ip addresses of where those services map too you should be able to use them that way.

Great, looking forward to the fix :) That's what I've been doing.

coreinput
Member
 
Posts: 16
Joined: Tue Dec 27, 2016 1:59 pm
Has thanked: 2 times
Been thanked: 14 times

Re: v1.5.3 Bug Reports and Comments

Sun Aug 18, 2019 12:33 pm

Upgraded from 1.5.2 running since May 2019 and everything went smooth (and no POE loss). Hats off to the team including beta testers for making this a good release. Thanks!

Previous
Return to Hardware and software issues

Who is online

Users browsing this forum: Google [Bot] and 73 guests