Статус: Активный участник
Группы: Участники
Зарегистрирован: 27.04.2016(UTC) Сообщений: 108
Сказал(а) «Спасибо»: 9 раз Поблагодарили: 1 раз в 1 постах
|
Автор: Евгений Афанасьев  Ошибку получаете сразу после Client Hello? Нужен боле детальный лог, так как может не отправляться клиентский сертификат, если он не подходит по каким-то параметрам (в частности, доверенные издатели сервера). Другие тестовые адреса - https://www.cryptopro.ru/products/csp/tc26tls (Стенд открытого тестирования СКЗИ "КриптоПро CSP"/"КриптоПро TLS"). Да, ошибка сразу после Client Hello. Вот лог: Код:Mar 27, 2019 9:16:34 AM ru.CryptoPro.ssl.A run
FINE: Applet launched: false
Mar 27, 2019 9:16:34 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO: keyStore is :
Mar 27, 2019 9:16:34 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO: keyStore type is : HDImageStore
Mar 27, 2019 9:16:34 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO: keyStore provider is :
Mar 27, 2019 9:16:34 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO: init key store
Mar 27, 2019 9:16:34 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO: defaultStoreProvider =
Mar 27, 2019 9:16:34 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO:
Mar 27, 2019 9:16:36 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO: init key manager of type GostX509
Mar 27, 2019 9:16:36 AM ru.CryptoPro.ssl.r <init>
FINE: %% adding as private keys %%
Mar 27, 2019 9:16:36 AM ru.CryptoPro.ssl.r <init>
FINER: ***42d01794*** : loading private key (JCP)...
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.r <init>
FINER: ***42d01794*** : private key is loaded.
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.r <init>
FINE:
found key: ***42d01794***
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.r <init>
FINE:
------
Certificate chain [0] for key:***42d01794***
Subject: STREET=??. ?????? ?. 77, CN=?? ??????-??????? (???), O=?? ??????-??????? (???), L=???????????, ST=16 ?????????? ?????????,***
Valid from Mon Jan 21 13:38:03 MSK 2019 until Tue Jan 21 13:38:03 MSK 2020
------
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO: trustStore is: ***trusted.store
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO: trustStore type is : CertStore
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO: trustStore provider is :
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO: init trust store
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO: init trust manager of type GostX509
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.g <init>
FINE: Trusted certificates: key store.
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.g a
FINE:
%% adding as trusted certificates %%
--------
Subject: STREET=??. ?????? ?. 77, CN=?? ??????-??????? (???), O=?? ??????-??????? (???), L=???????????, ST=16 ?????????? ?????????,***
Serial number: ******
Valid from Mon Jan 21 13:38:03 MSK 2019 until Tue Jan 21 13:38:03 MSK 2020
--------
Subject: CN=??????????? ??????, OID.1.2.643.3.131.1.1=#120C303037373130343734333735, OID.1.2.643.100.1=#120D31303437373032303236373031, O=??????????? ??????, STREET="????? ????????, ??? 7", L=?. ??????, ST=77 ??????, C=RU, EMAILADDRESS=dit@minsvyaz.ru
Serial number: 4e6d478b26f27d657f768e025ce3d393
Valid from Fri Jul 06 15:18:06 MSK 2018 until Tue Jul 01 15:18:06 MSK 2036
--------
Subject: EMAILADDRESS=***
Serial number: 500b
Valid from Fri Oct 26 13:57:17 MSK 2018 until Tue Nov 05 13:57:17 MSK 2019
--------
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO: init context...
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.SSLContextImpl engineInit
FINE: SSLContext engineInit
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.SSLContextImpl engineInit
FINER: trigger seeding of SecureRandom
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.SSLContextImpl engineInit
FINER: done seeding SecureRandom
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.SSLContextImpl d
INFO: Context initiated.
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.y <init>
FINER: Created: [Session-1, Unknown 0x0:0x0]
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.f a
FINE: Allow unsafe renegotiation: false
Allow legacy hello messages: true
Is initial handshake: true
Is secure renegotiation: false
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.am setSoTimeout
FINER: Thread-5, setSoTimeout(0) called
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.ao r
FINE: %% No cached client session
Mar 27, 2019 9:16:37 AM ru.CryptoPro.ssl.f q
FINE: %% ClientHello, TLSv1; Cipher Suites: [TLS_CIPHER_2012, TLS_CIPHER_2001, SSL3_CK_GVO_KB2]; Compression Methods: 0; Extensions: Extension ext_hash_and_mac_alg_select, ext_hash_and_mac_alg_select: [48, 32, 48, 30, 48, 8, 6, 6, 42, -123, 3, 2, 2, 9, 48, 8, 6, 6, 42, -123, 3, 2, 2, 22, 48, 8, 6, 6, 42, -123, 3, 2, 2, 23], Extension renegotiation_info, renegotiated_connection: <empty>;
Mar 27, 2019 9:17:26 AM ru.CryptoPro.ssl.am b
FINER: --WRITE--
Mar 27, 2019 9:17:26 AM ru.CryptoPro.ssl.D a
ALL: [Raw write]: length = 97
0000: 16 03 01 00 5C 01 00 00 58 03 01 5C 9B 15 76 20 ....\...X..\..v
0010: 1E 82 5D B8 78 B7 3F 38 B2 A5 17 4E 3B 11 5A 00 ..].x.?8...N;.Z.
0020: 59 40 7A F3 C6 A1 C2 D2 DC C2 F1 00 00 04 FF 85 Y@z.............
0030: 00 81 01 00 00 2B FD E8 00 22 30 20 30 1E 30 08 .....+..."0 0.0.
0040: 06 06 2A 85 03 02 02 09 30 08 06 06 2A 85 03 02 ..*.....0...*...
0050: 02 16 30 08 06 06 2A 85 03 02 02 17 FF 01 00 01 ..0...*.........
0060: 00 .
Mar 27, 2019 9:17:26 AM ru.CryptoPro.ssl.am a
FINER: Reading and processing packages...
Mar 27, 2019 9:17:26 AM ru.CryptoPro.ssl.am a
FINER: --READ--
Mar 27, 2019 9:17:26 AM ru.CryptoPro.ssl.v a
ALL: [Raw read]: length = 5
0000: 15 03 01 00 02 .....
Mar 27, 2019 9:17:26 AM ru.CryptoPro.ssl.v a
ALL: [Raw read]: length = 2
0000: 02 28 .(
Mar 27, 2019 9:17:26 AM ru.CryptoPro.ssl.am b
FINE: Thread-13, RECV TLSv1 ALERT: fatal, description = HANDSHAKE_FAILURE
Mar 27, 2019 9:17:26 AM ru.CryptoPro.ssl.am k
FINER: Thread-13, called closeSocket()
Mar 27, 2019 9:17:26 AM ru.CryptoPro.ssl.am a
FINER: Thread-13, handling exception: javax.net.ssl.SSLHandshakeException: Received fatal alert: HANDSHAKE_FAILURE
Mar 27, 2019 9:17:26 AM ru.CryptoPro.ssl.am a
FINE: THROW
javax.net.ssl.SSLHandshakeException: Received fatal alert: HANDSHAKE_FAILURE
|