New issue
Advanced search Search tips

Issue 607460 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 3
Type: Bug



Sign in to add a comment

SSL fallback error

Reported by kld.belh...@gmail.com, Apr 28 2016

Issue description

Chrome Version       : 50.0.2661.87
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
URLs (if applicable) :
Other browsers tested:
  Add OK or FAIL after other browsers where you have tested this issue:
     Safari 5:
  Firefox 4.x:OK
     IE 7/8/9:OK

What steps will reproduce the problem?
1.Go to http://www.interparking.be/brusselsairport/Home.aspx
2.fill the dates and click on "Next step"
3.

What is the expected result?
Get access to a secure connection  

What happens instead of that?
ERR_SSL_FALLBACK_BEYOND_MINIMUM_VERSION

Please provide any additional information below. Attach a screenshot if
possible.

UserAgentString: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.87 Safari/537.36



 
net-internals-log.json
831 KB View Download
This happens only when in version 50, Chrome 49 works fine.
Components: Internals>Network>SSL
https://secure-booking.interparking.com/ does appear to be buggy. This looks like an instance of the Microsoft AES-GCM bug from way back,  issue #433406 , which is why Firefox is not affected.

The fix is fortunately very easy. They just need to take updates on that server. I'll reach out to them.
Dear David,

Seeing that I'm personally working for interparking and in contact with the
Web developers, I'll transfer the ticket to them.

Thanks for your help.

Best regards,
Khaled BELHOUARI
Oh, perfect! Sorry, I didn't realize that. I just sent info@interparking.com an email, but I'll copy details here too.

There was a one month window where the fix for the MS14-066 security vulnerability had a problem in it and caused issues with some clients. (It got silently masked by the insecure TLS version fallback, but that causes security issues for all sites, so we've been phasing that out.) The fix was later respun and fixed, but your server appears to still have the broken version.

The advice I got from Microsoft way back was that you want to install KB3042058 (https://support.microsoft.com/en-us/kb/3042058) and its prerequisites. Note that KB3042058 describes important prerequisites that must be installed prior to installing KB3042058.

I suspect going through and catching up on updates in general will also resolve things (and is generally advisable), but I'm not very familiar with Windows updates and can't say for sure.
It looks like you all have since resolved the issues with https://secure-booking.interparking.com/. Is this right? Shall I go ahead and close this?
Status: WontFix (was: Unconfirmed)
(Going ahead and closing this. Let me know if the site's still not working on your end.)
Hi David,

The patch you provided worked perfectly. The site is now back on his feet.
Thank you very much.

Best regards,
Khaled BELHOUARI
Great! Glad to hear it. And good to have confirmation that the instructions work! :-)

Sign in to add a comment