[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Ftpapi] Peer not recognized or badly formatted





I’m getting the Peer not recognized or badly formatted message received.  I spent some time trying to look into this and I read a few other messages with this problem. I don’t know a lot about SSL encryption ciphers but I understand from the other messages that may be the issue.
I am also aware that we’re on an old version of HTTPAPI, I’m currently working with the Operation staff to upgrade.

My HTTP error log is at the bottom of this message.  I’m doing an http_url_post_stmf, the process is identical to other processes where it works with other vendors.  The link I’m sending to is an https.  The vendor gave me a list of information about their site including:
Their SSL connection using TLSv1.2 / ECDHE-RSA-AES128-GCM-SHA256
Their Cipher selection: ALL:!EXPORT:!EXPORT40:!EXPORT56:!aNULL:!LOW:!RC4:@STRENGTH

I asked the Operations Manager to see if we have the Ciphers necessary for the SSL connection required.
He sent me a print screen of QSSLPCL Secure sockets layer protocols and said we’re already configured to support TSLv1.2.
The screen showed showed Protocols  

 *TLSV1.2   

 *TLSV1.1   

 *TLSV1     


I don’t know if this means we have the Ciphers we need, he seemed to think it does.
At this point the only thing I can think of to do is to upgrade our HTTPAPI, which is now in the hands of operations.
I’m not sure how soon they will schedule the upgrade. 
Any advice that might guide me in the right direction would be appreciated.

Regards,
Charlie



Httpapi error log

HTTPAPI Ver 1.23 released 2008-04-24                                    

OS/400 Ver V7R3M0                                                       

                                                                         

New iconv() objects set, PostRem=819. PostLoc=0. ProtRem=819. ProtLoc=0 

http_url_post_stmf(): entered                                           

getting post file size...                                               

opening file to be sent...                                               

opening file to be received                                             

http_persist_open(): entered                                            

http_long_ParseURL(): entered                                           

DNS resolver retrans: 2                                                 

DNS resolver retry  : 2                                                 

DNS resolver options: x'00000136'                                       

DNS default domain: us.adler.corp                                        

DNS default domain: us.adler.corp                                              

DNS server found: 10.1.20.11                                                   

DNS server found: 10.1.20.12                                                    

https_init(): entered                                                          

--------------------------------------------------------------------------------

Dump of local-side certificate information:                                     

--------------------------------------------------------------------------------

(GSKit) Peer not recognized or badly formatted message received.               

ssl_error(415): (GSKit) Peer not recognized or badly formatted message received.

SetError() #30: SSL Handshake: (GSKit) Peer not recognized or badly formatted message received.

--------------------------------------------------------------------------------

Dump of server-side certificate information:                                    

--------------------------------------------------------------------------------

Cert Validation Code = 0                                                       

(GSKit) An operation which is not valid for the current SSL session state was attempted.  

ssl_error(5): (GSKit) An operation which is not valid for the current SSL session state was attempted.

(GSKit) An operation which is not valid for the current SSL session state was attempted.



This email has been scanned for viruses by Mimecast.

-- 
_______________________________________________
Ftpapi mailing list
Ftpapi@xxxxxxxxxxxxxxxxxxxxxx
http://scottklement.com/mailman/listinfo/ftpapi