Hello,

Disabling session caching does appear to resolve/prevent the problem
however we would like to keep it enabled for performance reasons and are
trying to understand root cause as we'd expect this to work with session
caching enabled.

Are their logs/traces/etc that we could enabled that would help us
catch/diagnose the issue?

On Thu, Feb 18, 2016 at 6:13 AM Ángel González <[email protected]>
wrote:

> Shaun Amyotte wrote:
> > The error in the subject has been encountered at random by some of my
> > users when using Firefox. In researching this issue I've come across
> > a number of dated articles/bits of information that suggest at one
> > point there was a bug in OpenSSL 0.9.8g that caused this error. We
> > are running
> > 1.0.1j-1.4.0.420
>
> Have you checked that you have session cached enabled? (and available,
> eg. the folder is not read-only)
>
> >
> > Since this is a client side error, I understand this may no longer be
> > tied
> > to the original OpenSSL bug, however I was hoping to rule it out. In
> > doing
> > so I wanted to trace the changelist referenced in the firefox bug
> > post @
> > https://bugzilla.mozilla.org/show_bug.cgi?id=430703 however it looks
> > as
> > though the tranition to GitHub has since made the link obsolete. The
> > link
> > in question is http://cvs.openssl.org/chngview?cn=17098 and there is
> > reference to your involvement in this issue.
>
>
> This seems to be dc634aff252943c5f61fa1a245a4206259cf941f:
> > Don't send zero length session ID if stateless session resupmtion is
> > successful. Check be seeing if there is a cache hit.
>  http://git.openssl.org/?p=openssl.git;a=commit;h=dc634aff252943c5f61fa
> 1a245a4206259cf941f
> <http://git.openssl.org/?p=openssl.git;a=commit;h=dc634aff252943c5f61fa1a245a4206259cf941f>
>
>
> Cheers
> --
> dev-tech-crypto mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-tech-crypto
-- 
dev-tech-crypto mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-tech-crypto

Reply via email to