java - Google Cloud Platform (app engine) SSL Handshake error -


i have using ssl google app engine application. have setup , certificate verified sites https://ssltools.websecurity.symantec.com/checker/views/certcheck.jsp. have tested site java sslpoke. lastly, have written java program post site , works too.

however, when use portecle examine site, getting handshake issues. javax.net.debug output below.

does have ideas why might error?

trigger seeding of securerandom done seeding securerandom ignoring unavailable cipher suite: tls_ecdhe_rsa_with_aes_256_cbc_sha ignoring unavailable cipher suite: tls_dhe_rsa_with_aes_256_cbc_sha ignoring unavailable cipher suite: tls_ecdh_rsa_with_aes_256_cbc_sha ignoring unsupported cipher suite: tls_dhe_dss_with_aes_128_cbc_sha256 ignoring unsupported cipher suite: tls_dhe_dss_with_aes_256_cbc_sha256 ignoring unsupported cipher suite: tls_dhe_rsa_with_aes_128_cbc_sha256 ignoring unsupported cipher suite: tls_ecdh_rsa_with_aes_128_cbc_sha256 ignoring unsupported cipher suite: tls_dhe_rsa_with_aes_256_cbc_sha256 ignoring unsupported cipher suite: tls_ecdhe_rsa_with_aes_256_cbc_sha384 ignoring unsupported cipher suite: tls_ecdh_ecdsa_with_aes_256_cbc_sha384 ignoring unsupported cipher suite: tls_rsa_with_aes_256_cbc_sha256 ignoring unavailable cipher suite: tls_ecdhe_ecdsa_with_aes_256_cbc_sha ignoring unsupported cipher suite: tls_ecdhe_rsa_with_aes_128_cbc_sha256 ignoring unsupported cipher suite: tls_ecdhe_ecdsa_with_aes_256_cbc_sha384 ignoring unavailable cipher suite: tls_dhe_dss_with_aes_256_cbc_sha ignoring unsupported cipher suite: tls_ecdh_rsa_with_aes_256_cbc_sha384 ignoring unsupported cipher suite: tls_ecdhe_ecdsa_with_aes_128_cbc_sha256 ignoring unsupported cipher suite: tls_ecdh_ecdsa_with_aes_128_cbc_sha256 ignoring unavailable cipher suite: tls_ecdh_ecdsa_with_aes_256_cbc_sha ignoring unavailable cipher suite: tls_rsa_with_aes_256_cbc_sha ignoring unsupported cipher suite: tls_rsa_with_aes_128_cbc_sha256 awt-eventqueue-0, setsotimeout(10000) called allow unsafe renegotiation: false allow legacy hello messages: true initial handshake: true secure renegotiation: false %% no cached client session *** clienthello, tlsv1 randomcookie:  gmt: 1433037580 bytes = { 42, 125, 100, 34, 251, 8, 45, 185, 226,  131, 130, 128, 139, 33, 24, 191, 86, 29, 239, 60, 47, 12, 226, 212, 68, 61, 233 , 27 } session id:  {} cipher suites: [tls_ecdhe_ecdsa_with_aes_128_cbc_sha, tls_ecdhe_rsa_with_aes_128 _cbc_sha, tls_rsa_with_aes_128_cbc_sha, tls_ecdh_ecdsa_with_aes_128_cbc_sha, tls _ecdh_rsa_with_aes_128_cbc_sha, tls_dhe_rsa_with_aes_128_cbc_sha, tls_dhe_dss_wi th_aes_128_cbc_sha, tls_ecdhe_ecdsa_with_rc4_128_sha, tls_ecdhe_rsa_with_rc4_128 _sha, ssl_rsa_with_rc4_128_sha, tls_ecdh_ecdsa_with_rc4_128_sha, tls_ecdh_rsa_wi th_rc4_128_sha, tls_ecdhe_ecdsa_with_3des_ede_cbc_sha, tls_ecdhe_rsa_with_3des_e de_cbc_sha, ssl_rsa_with_3des_ede_cbc_sha, tls_ecdh_ecdsa_with_3des_ede_cbc_sha,  tls_ecdh_rsa_with_3des_ede_cbc_sha, ssl_dhe_rsa_with_3des_ede_cbc_sha, ssl_dhe_ dss_with_3des_ede_cbc_sha, ssl_rsa_with_rc4_128_md5, tls_empty_renegotiation_inf o_scsv] compression methods:  { 0 } extension elliptic_curves, curve names: {secp256r1, sect163k1, sect163r2, secp19 2r1, secp224r1, sect233k1, sect233r1, sect283k1, sect283r1, secp384r1, sect409k1 , sect409r1, secp521r1, sect571k1, sect571r1, secp160k1, secp160r1, secp160r2, s ect163r1, secp192k1, sect193r1, sect193r2, secp224k1, sect239k1, secp256k1} extension ec_point_formats, formats: [uncompressed] *** [write] md5 , sha1 hashes:  len = 149 0000: 01 00 00 91 03 01 55 6a   6b 0c 2a 7d 64 22 fb 08  ......ujk.*.d".. 0010: 2d b9 e2 83 82 80 8b 21   18 bf 56 1d ef 3c 2f 0c  -......!..v..</. 0020: e2 d4 44 3d e9 1b 00 00   2a c0 09 c0 13 00 2f c0  ..d=....*...../. 0030: 04 c0 0e 00 33 00 32 c0   07 c0 11 00 05 c0 02 c0  ....3.2......... 0040: 0c c0 08 c0 12 00 0a c0   03 c0 0d 00 16 00 13 00  ................ 0050: 04 00 ff 01 00 00 3e 00   0a 00 34 00 32 00 17 00  ......>...4.2... 0060: 01 00 03 00 13 00 15 00   06 00 07 00 09 00 0a 00  ................ 0070: 18 00 0b 00 0c 00 19 00   0d 00 0e 00 0f 00 10 00  ................ 0080: 11 00 02 00 12 00 04 00   05 00 14 00 08 00 16 00  ................ 0090: 0b 00 02 01 00                                     ..... awt-eventqueue-0, write: tlsv1 handshake, length = 149 [raw write]: length = 154 0000: 16 03 01 00 95 01 00 00   91 03 01 55 6a 6b 0c 2a  ...........ujk.* 0010: 7d 64 22 fb 08 2d b9 e2   83 82 80 8b 21 18 bf 56  .d"..-......!..v 0020: 1d ef 3c 2f 0c e2 d4 44   3d e9 1b 00 00 2a c0 09  ..</...d=....*.. 0030: c0 13 00 2f c0 04 c0 0e   00 33 00 32 c0 07 c0 11  .../.....3.2.... 0040: 00 05 c0 02 c0 0c c0 08   c0 12 00 0a c0 03 c0 0d  ................ 0050: 00 16 00 13 00 04 00 ff   01 00 00 3e 00 0a 00 34  ...........>...4 0060: 00 32 00 17 00 01 00 03   00 13 00 15 00 06 00 07  .2.............. 0070: 00 09 00 0a 00 18 00 0b   00 0c 00 19 00 0d 00 0e  ................ 0080: 00 0f 00 10 00 11 00 02   00 12 00 04 00 05 00 14  ................ 0090: 00 08 00 16 00 0b 00 02   01 00                    .......... awt-eventqueue-0, received eofexception: error awt-eventqueue-0, handling exception:  javax.net.ssl.sslhandshakeexception: remot e host closed connection during handshake awt-eventqueue-0, send tlsv1 alert:  fatal, description = handshake_failure awt-eventqueue-0, write: tlsv1 alert, length = 2 [raw write]: length = 7 0000: 15 03 01 00 02 02 28                               ......( awt-eventqueue-0, called closesocket() awt-eventqueue-0, ioexception in getsession():    javax.net.ssl.sslhandshakeexception: remote host closed connection during handshake awt-eventqueue-0, called close() awt-eventqueue-0, called closeinternal(true) 

given see eofexception , ioexception in getsession(): javax.net.ssl.sslhandshakeexception: remote host closed connection during handshake, appears remote host closed connection during handshake.

i'm not sure if tlsv1 supported, or whether there's no problem that, it's best guess have. really, you'd have post more info, , wouldn't worried if every other site (including, crucially, browsers) able validate cert , all.


Comments

Popular posts from this blog

node.js - Using Node without global install -

How to access a php class file from PHPFox framework into javascript code written in simple HTML file? -

java - Null response to php query in android, even though php works properly -