<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Extreme Control TLS Alert in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95848#M391</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Rather than wasting time troubleshooting the below error I wondered if the Extreme Control Engine will reject older encryption protocols such as SSL V3.0?&lt;/P&gt;&lt;P&gt;Old Windows XP with 802.1x PEAP:&lt;/P&gt;&lt;P&gt;Event:&lt;/P&gt;&lt;P&gt;eap_peap: TLS Alert write:fatal:handshake failure eap_peap: Failed in __FUNCTION__ (SSL_read): error:1408A0C1:SSL routines:ssl3_get_client_hello:no shared cipher eap_peap: System call (I/O) error (-1) eap_peap: TLS receive handshake failed during operation&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
    <pubDate>Mon, 15 May 2023 09:09:32 GMT</pubDate>
    <dc:creator>RobertD1</dc:creator>
    <dc:date>2023-05-15T09:09:32Z</dc:date>
    <item>
      <title>Extreme Control TLS Alert</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95848#M391</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Rather than wasting time troubleshooting the below error I wondered if the Extreme Control Engine will reject older encryption protocols such as SSL V3.0?&lt;/P&gt;&lt;P&gt;Old Windows XP with 802.1x PEAP:&lt;/P&gt;&lt;P&gt;Event:&lt;/P&gt;&lt;P&gt;eap_peap: TLS Alert write:fatal:handshake failure eap_peap: Failed in __FUNCTION__ (SSL_read): error:1408A0C1:SSL routines:ssl3_get_client_hello:no shared cipher eap_peap: System call (I/O) error (-1) eap_peap: TLS receive handshake failed during operation&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 09:09:32 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95848#M391</guid>
      <dc:creator>RobertD1</dc:creator>
      <dc:date>2023-05-15T09:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control TLS Alert</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95850#M392</link>
      <description>&lt;P&gt;Hello Robert,&lt;/P&gt;&lt;P&gt;This is likely the case.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000066220" target="_blank"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000066220&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I will need to get this article modified. You can test the appliance property in the article, but I believe at this point these ciphers have been completely deprecated and are not available for use at all.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 12:12:48 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95850#M392</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2023-05-15T12:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control TLS Alert</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95851#M393</link>
      <description>&lt;P&gt;Correct. Control will reject any SSLv3 based encipherment. It will also reject a core list of now defunct / legacy ciphers from older clients as listed in GTAC KB&amp;nbsp;@&amp;nbsp;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000100637" target="_blank"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000100637&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 12:13:04 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95851#M393</guid>
      <dc:creator>Robert_Haynes</dc:creator>
      <dc:date>2023-05-15T12:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control TLS Alert</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95852#M394</link>
      <description>&lt;P&gt;A more recent article:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000100637" target="_blank"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000100637&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 12:14:17 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95852#M394</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2023-05-15T12:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control TLS Alert</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95853#M395</link>
      <description>&lt;P&gt;... take a trace of the PEAP connection to expose the ciphers the client is requesting and compare against what is set as seen in the NSJBoss.properties 'tomcat.ciphers' entry.&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 12:15:49 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95853#M395</guid>
      <dc:creator>Robert_Haynes</dc:creator>
      <dc:date>2023-05-15T12:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control TLS Alert</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95856#M396</link>
      <description>&lt;P&gt;Thanks Robert!&lt;/P&gt;&lt;P&gt;Based on your response it does look like the issue is that neither the client or server can agree on a cipher to use after taking a capture of the client hello.&lt;/P&gt;&lt;P&gt;Trace shows client hello...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobertD1_0-1684158924144.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/6513i67B7D78F8DA324C1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RobertD1_0-1684158924144.png" alt="RobertD1_0-1684158924144.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The enterasys.tomcat.ciphers list:&lt;/P&gt;&lt;P&gt;enterasys.tomcat.ciphers=TLS_RSA_WITH_AES_128_CBC_SHA,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,ECDHE-ECDSA-AES256-GCM-SHA384,ECDHE-RSA-AES256-GCM-SHA384,ECDHE-ECDSA-AES128-GCM-SHA256,ECDHE-RSA-AES128-GCM-SHA256,ECDHE-ECDSA-AES256-SHA384,ECDHE-RSA-AES256-SHA384,ECDHE-ECDSA-AES128-SHA256,ECDHE-RSA-AES128-SHA256&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 14:00:05 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95856#M396</guid>
      <dc:creator>RobertD1</dc:creator>
      <dc:date>2023-05-15T14:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control TLS Alert</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95863#M397</link>
      <description>&lt;P&gt;Thank you for the trace. The client cipher list presented is wholly deprecated at this point, a collection of RC4 (cryptographically weak), CBC (Beast/Poodle Attacks) and defunct EXPORT ciphers. OpenSSL long ago deprecated these ciphers which our Control appliance uses.&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2023 12:13:23 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-tls-alert/m-p/95863#M397</guid>
      <dc:creator>Robert_Haynes</dc:creator>
      <dc:date>2023-05-16T12:13:23Z</dc:date>
    </item>
  </channel>
</rss>

