Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Re-negotiation handshake failed: Not accepted by client!?

Posted on 2016-07-27
8
762 Views
Last Modified: 2016-08-22
We recently renewed an ssl cert on a web server and now see the following error in the logs.

In ssl_request log
Re-negotiation handshake failed: Not accepted by client!?

In ssl_error_log
 AH02042: rejecting client initiated renegotiation

Are these simply clients updating or unable to and a problem? And if a problem, how can it be fixed since we simply renewed the cert.

UPDATE: I thought this was ssl related but I'm now seeing the second error on a server that didn't get an SSL renewal.

AH02042: rejecting client initiated renegotiation
0
Comment
Question by:projects
  • 4
  • 3
8 Comments
 
LVL 62

Accepted Solution

by:
gheist earned 500 total points (awarded by participants)
ID: 41734949
Which means that client is security scanner / attacker. It is best to reduce log level to ignore such messages.
0
 

Author Comment

by:projects
ID: 41736108
Are you sure about that because it is funny timing that I have never seen these before the SSL cert was played with.
0
 
LVL 62

Expert Comment

by:gheist
ID: 41736633
It has nothing to do with certificate, or its validity or its size.
0
Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

 

Author Comment

by:projects
ID: 41736641
If it has nothing to do with the certificate then it definitely includes not it's validity or its size :).
However, my question is, how do you know for sure this is unrelated to ssl cert then since it looks like an ssl error.
0
 
LVL 62

Expert Comment

by:gheist
ID: 41736659
Drill through qualys server test.
AH02042 is so-called insecure renegotiation that can be used to dry server's random pool and enormous rate.
0
 

Author Comment

by:projects
ID: 41736682
Do you mean this?
https://www.qualys.com/

So it's just scanning and since I'm not seeing a large enough number of them to panic, it must mean all is fine with the server then?

And, it just happened to be coincidence that I've started seeing these since renewing the SSL cert?
0
 

Author Comment

by:projects
ID: 41762809
It looks like you are not exactly correct and that this is a well known SSL issue that's come up before.
I'll dig up the info and post it. If you are right, then I'll award it even though your reply about looking things up is rather than guessing is rather snide.
I'm not sure why you bother to reply to my questions anymore, all you do is throw personal comments in there. If I wanted that, I'd go to any forum out there but instead I pay to try and remain professional. Kinda tired of those kinds of remarks.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If your site has a few sections that need to be secure when data is transmitted between the server and local computer, such as a /order/ section for ordering or /customer/ which contains customer data, etc it would of course be recommended to secure…
I. Introduction There's an interesting discussion going on now in an Experts Exchange Group — Attachments with no extension (http://www.experts-exchange.com/discussions/210281/Attachments-with-no-extension.html). This reminded me of questions tha…
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question