Solved

Re-negotiation handshake failed: Not accepted by client!?

Posted on 2016-07-27
8
177 Views
Last Modified: 2016-08-22
We recently renewed an ssl cert on a web server and now see the following error in the logs.

In ssl_request log
Re-negotiation handshake failed: Not accepted by client!?

In ssl_error_log
 AH02042: rejecting client initiated renegotiation

Are these simply clients updating or unable to and a problem? And if a problem, how can it be fixed since we simply renewed the cert.

UPDATE: I thought this was ssl related but I'm now seeing the second error on a server that didn't get an SSL renewal.

AH02042: rejecting client initiated renegotiation
0
Comment
Question by:projects
  • 4
  • 3
8 Comments
 
LVL 61

Accepted Solution

by:
gheist earned 500 total points (awarded by participants)
Comment Utility
Which means that client is security scanner / attacker. It is best to reduce log level to ignore such messages.
0
 

Author Comment

by:projects
Comment Utility
Are you sure about that because it is funny timing that I have never seen these before the SSL cert was played with.
0
 
LVL 61

Expert Comment

by:gheist
Comment Utility
It has nothing to do with certificate, or its validity or its size.
0
6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

 

Author Comment

by:projects
Comment Utility
If it has nothing to do with the certificate then it definitely includes not it's validity or its size :).
However, my question is, how do you know for sure this is unrelated to ssl cert then since it looks like an ssl error.
0
 
LVL 61

Expert Comment

by:gheist
Comment Utility
Drill through qualys server test.
AH02042 is so-called insecure renegotiation that can be used to dry server's random pool and enormous rate.
0
 

Author Comment

by:projects
Comment Utility
Do you mean this?
https://www.qualys.com/

So it's just scanning and since I'm not seeing a large enough number of them to panic, it must mean all is fine with the server then?

And, it just happened to be coincidence that I've started seeing these since renewing the SSL cert?
0
 

Author Comment

by:projects
Comment Utility
It looks like you are not exactly correct and that this is a well known SSL issue that's come up before.
I'll dig up the info and post it. If you are right, then I'll award it even though your reply about looking things up is rather than guessing is rather snide.
I'm not sure why you bother to reply to my questions anymore, all you do is throw personal comments in there. If I wanted that, I'd go to any forum out there but instead I pay to try and remain professional. Kinda tired of those kinds of remarks.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

#SSL #TLS #Citrix #HTTPS #PKI #Compliance #Certificate #Encryption #StoreFront #Web Interface #Citrix XenApp
SSL stands for “Secure Sockets Layer” and an SSL certificate is a critical component to keeping your website safe, secured, and compliant. Any ecommerce website must have an SSL certificate to ensure the safe handling of sensitive information like…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now