Tls https connection failure (negotiation failed)

Source: Internet
Author: User

An error occurred while using TLS to connect to the server. After N-plus queries, the following Windows Update is found:
This update is not a security update that the end user can install. We recommend that you only use this update for the server administrator. This update will deploy an alternative method to disable Transport Layer Security (TLS) and Secure Socket Layer (SSL) Support for renegotiation on affected systems, to help protect clients connected to such servers from being exploited by this vulnerability.

TLS re-negotiation is a Transport Layer Security Protocol component and is used by some applications.ProgramRequired. We recommend that the customer verify the need to implement this alternative method and, if deemed necessary, carefully test this alternative method for the Application Deployment Solution.
Functions and objectives of Alternative Methods
This alternative provides the system administrator with a way to protect all clients connected to the server from being exploited by the vulnerabilities described in security bulletin 977377. The alternative method is to disable TLS/SSL re-negotiation. This is a component of the TLS/SSL protocol that is vulnerable to such attacks.

This method is only valid for Server installation. The installation of the alternative method protects all connections to the server (initiated by the client. This alternative should not be installed on the client computer because it does not provide any other security benefits.
Known issues
This alternative will disable TLS/SSL re-negotiation and common protocol features required by some applications. This may cause the software to stop working normally. In case of any side effects, the customer should uninstall the alternative method to solve the problem.

Microsoft has tested the following software and found that these problems occur when you install the update:
Windows 7 directaccess: ip https interface will not work.
Exchange ActiveSync: it will not work when using the certificate client for authentication.
Internet Information Service (IIS): In some configurations, IIS that uses certificate client authentication (including certificate ing schemes) will be affected. Client certificate authentication throughout the site will not be affected and will continue to work.
Internet Explorer: You may not be able to connect to a website that requires client certificate authentication (not client certificate authentication across the site.
Back to Top
Configuration
After the installation, the update will prohibit the client from re-negotiation with the server. This behavior can be controlled by two registry entries:
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ securityproviders \ Schannel \ disablerenegoonclient

HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ securityproviders \ Schannel \ disablerenegoonserver
Note:
If the disablerenegoonclient sub-item exists and has any non-zero value:
The client will not initialize and re-negotiate.
The client will not respond to the re-negotiation.
If the disablerenegoonclient Sub-item is lost or exists and the value is zero:
The client starts the negotiation again.
The client will respond to the re-negotiation.
If the disablerenegoonserver subitem exists and has any non-zero value:
Server startup re-negotiation is not allowed.
The server will not respond to the re-negotiation request from the client.
If the disablerenegoonserver subitem is lost or exists and the value is zero:
The server is allowed to restart the negotiation.
The server will respond to the re-negotiation request from the client.

Change disablerenegoonclient to 0 to connect to the https server.

Server Update has not been attempted yet.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.