On Tuesday 07 June 2016 21:14:32 Andrei Popov wrote:
> Jumping to the end of the thread, it looks like this is an FTP issue
> that repros when TLS 1.2 is negotiated. Not a TLS version
> intolerance.
> The conclusion seems to be that
> https://support.microsoft.com/en-us/kb/2888853 resolves the issue, by
> updating FTP binaries. 
> Cheers,

yes that thing should be fixed now

that being said, I've seen reports that IIS 7.5 does support TLSv1.2 
while at the same time being intolerant to TLS 1.3 Client Hello.

Unfortunately I don't have access to a server that I'm certain is 
running IIS 7.5 that I could test this hypothesis with.


To continue my reply to Yoav, so just because we sometimes not see 
different intolerancies, doesn't mean they are not there. TLS library 
programmers do actively shape their Client Hello's to trigger as little 
issues as possible.
-- 
Regards,
Hubert Kario
Senior Quality Engineer, QE BaseOS Security team
Web: www.cz.redhat.com
Red Hat Czech s.r.o., Purkyňova 99/71, 612 45, Brno, Czech Republic

Attachment: signature.asc
Description: This is a digitally signed message part.

_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls

Reply via email to