Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

Immortality consists largely of boredom. -- Zefrem Cochrane, "Metamorphosis", stardate 3219.8


computers / Rocksolid Nodes Help / Need advice to troubleshoot SSL connection failure

SubjectAuthor
* Need advice to troubleshoot SSL connection failureSyber Shock
`* Need advice to troubleshoot SSL connection failureRetro Guy
 `- Need advice to troubleshoot SSL connection failureRetro Guy

1
Need advice to troubleshoot SSL connection failure

<f5d0a892f23b50c8ab1bd5aa2f6a67ee$1@sybershock.com>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=318&group=rocksolid.nodes.help#318

  copy link   Newsgroups: rocksolid.nodes.help
Path: i2pn2.org!rocksolid2!.POSTED.nightbulb.net!not-for-mail
From: admin@sybershock.com (Syber Shock)
Newsgroups: rocksolid.nodes.help
Subject: Need advice to troubleshoot SSL connection failure
Date: Wed, 26 Apr 2023 04:15:07 -0500
Organization: sybershock.com
Message-ID: <f5d0a892f23b50c8ab1bd5aa2f6a67ee$1@sybershock.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Injection-Info: novabbs.org; posting-account="sybershock"; posting-host="nightbulb.net:216.24.252.247";
logging-data="30145"; mail-complaints-to="usenet@novabbs.org"
 by: Syber Shock - Wed, 26 Apr 2023 09:15 UTC

I tried to get Rslight to pull from news.grc.com:563 via SSL and the
cron says it could not connect to the host.

But when I pull from port 119 without SSL enabled it works as expected.

I have no problem connecting to news.grc.com:563 with openssl s_client.

$> openssl s_client -ign_eof -connect news.grc.com:563

I triple checked to ensure SSL was set at '1' in the config.

I can't tell if the problem is with my Rslight config or grc.com SSL
config.

What should I look at? Is there a way to make the PHP output the SSL
connection handshake to a file that I can examine?

Also is there a way to do starttls at port 119?

Please advise.

--
SugarBug | https://sybershock.com

Re: Need advice to troubleshoot SSL connection failure

<765ef9092ca412ae018bbc09459d06d0@rocksolidbbs.com>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=320&group=rocksolid.nodes.help#320

  copy link   Newsgroups: rocksolid.nodes.help
Path: i2pn2.org!.POSTED.rocksolidbbs.com!not-for-mail
From: retro.guy@rocksolidbbs.com (Retro Guy)
Newsgroups: rocksolid.nodes.help
Subject: Re: Need advice to troubleshoot SSL connection failure
Date: Wed, 26 Apr 2023 19:06:42 +0000
Organization: RetroBBS
Message-ID: <765ef9092ca412ae018bbc09459d06d0@rocksolidbbs.com>
References: <f5d0a892f23b50c8ab1bd5aa2f6a67ee$1@sybershock.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Info: i2pn2.i2pn2.org; posting-account="retrobbs"; posting-host="rocksolidbbs.com:2a03:b0c0:3:d0::fec:9001";
logging-data="11050"; mail-complaints-to="usenet@i2pn2.org"
User-Agent: Rocksolid Light 0.8.0
X-Spam-Checker-Version: SpamAssassin 4.0.0 (2022-12-13) on rocksolidbbs
X-Spam-Level: **
X-Rslight-Site: $2y$10$K/w/.vbcRHf9NK4GWhASL..rorNX5lE0EdGnvlFKQ3HwK/ciXPkte
X-Rslight-Posting-User: 7f2224730128256930309c9186f6203084896743
 by: Retro Guy - Wed, 26 Apr 2023 19:06 UTC

Syber Shock wrote:

> I tried to get Rslight to pull from news.grc.com:563 via SSL and the
> cron says it could not connect to the host.

> But when I pull from port 119 without SSL enabled it works as expected.

> I have no problem connecting to news.grc.com:563 with openssl s_client.

> $> openssl s_client -ign_eof -connect news.grc.com:563

> I triple checked to ensure SSL was set at '1' in the config.

This has worked in the past with a small selection of test sites I tried,
but I can confirm that it does not work now.

> I can't tell if the problem is with my Rslight config or grc.com SSL
> config.

Most likely rslight.

> What should I look at? Is there a way to make the PHP output the SSL
> connection handshake to a file that I can examine?

I will look into this now and get back with whatever results I find.

> Also is there a way to do starttls at port 119?

When working properly, it shouldn't matter the port number for the remote
server, just that SSL is set to '1'.

I'll post my test results here. (current test results is that it doesn't work :(

--
Posted on RetroBBS

Re: Need advice to troubleshoot SSL connection failure

<84868d733cb853c9d25e98322d9b89ea@rocksolidbbs.com>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=321&group=rocksolid.nodes.help#321

  copy link   Newsgroups: rocksolid.nodes.help
Path: i2pn2.org!.POSTED.rocksolidbbs.com!not-for-mail
From: retro.guy@rocksolidbbs.com (Retro Guy)
Newsgroups: rocksolid.nodes.help
Subject: Re: Need advice to troubleshoot SSL connection failure
Date: Wed, 26 Apr 2023 20:20:07 +0000
Organization: RetroBBS
Message-ID: <84868d733cb853c9d25e98322d9b89ea@rocksolidbbs.com>
References: <f5d0a892f23b50c8ab1bd5aa2f6a67ee$1@sybershock.com> <765ef9092ca412ae018bbc09459d06d0@rocksolidbbs.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Info: i2pn2.i2pn2.org; posting-account="retrobbs"; posting-host="rocksolidbbs.com:2a03:b0c0:3:d0::fec:9001";
logging-data="19969"; mail-complaints-to="usenet@i2pn2.org"
User-Agent: Rocksolid Light 0.8.0
X-Spam-Checker-Version: SpamAssassin 4.0.0 (2022-12-13) on rocksolidbbs
X-Spam-Level: **
X-Rslight-Site: $2y$10$EZQgZ16IHFrnKT67pKYcFukJVTn3Tmk4ehyVZ1q/1eoM0kB/E5TGK
X-Rslight-Posting-User: 7f2224730128256930309c9186f6203084896743
 by: Retro Guy - Wed, 26 Apr 2023 20:20 UTC

Retro Guy wrote:

> Syber Shock wrote:

>> snip

> I will look into this now and get back with whatever results I find.

>> Also is there a way to do starttls at port 119?

> When working properly, it shouldn't matter the port number for the remote
> server, just that SSL is set to '1'.

> I'll post my test results here. (current test results is that it doesn't work :(

Here are my initial test results:

Fails for news.grc.com:
Starting Spoolnews...
Loaded groups
SERVER=news.grc.com PORT=563
bool(false) <- FAILS
NULL
int(0)
END

Works for news.novabbs.org:
Starting Spoolnews...
Loaded groups
SERVER=news.novabbs.org PORT=563
resource(22) of type (stream) <- WORKS
string(0) ""
int(0)
END

Works for news.newshosting.com:
Starting Spoolnews...
Loaded groups
SERVER=news.newshosting.com PORT=563
resource(23) of type (stream) <- WORKS
string(0) ""
int(0)
END

I did make one change to /var/www/html/<section>/newsportal.php:

Changed line 96 from:
$ns=@fsockopen('ssl://'.$nserver.":".$nport);

to:
$ns = fsockopen("ssl://".$nserver, $nport, $error, $errorString, 30));

If you could try a different server to see if you get the same results,
that may help.

news.novabbs.org:563 should work for rocksolid groups.

At this time, I don't yet know why it's not working for news.grc.com

--
Posted on RetroBBS


computers / Rocksolid Nodes Help / Need advice to troubleshoot SSL connection failure

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor