OK, it turns out that this is openssl 0.9.6's fault. If the server is running 0.9.7 then all is well. I'm going to reassign this to openssl, though I doubt anything can be done about it besides releasing sarge...
noah
pgpnv0kaLdWus.pgp
Description: PGP signature