KS-Soft. Network Management Solutions
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister    ProfileProfile    Log inLog in 

POP3 test failed

 
Post new topic   Reply to topic    KS-Soft Forum Index -> Configuration, Maintenance, Troubleshooting
View previous topic :: View next topic  
Author Message
James65



Joined: 26 Feb 2024
Posts: 8

PostPosted: Mon Mar 04, 2024 6:11 am    Post subject: POP3 test failed Reply with quote

Good day,
With the latest HM version 14.28 we get an error with some POP3 tests connecting to 3rd party servers. The error is

276: Failed to verify key exchange signature

HM is running on Windows 10. It works ok using HM version 13.80. We already tried sslProto_POP3 in Misc section but none of the values are solving the issue.

Are there any other settings we can try?
Thanks for any suggestions.

Best regards
Michael
Back to top
View user's profile Send private message
KS-Soft



Joined: 03 Apr 2002
Posts: 12795
Location: USA

PostPosted: Mon Mar 04, 2024 11:49 am    Post subject: Reply with quote

Probably some old weak cipher suites are not supported anymore.
What exactly algorithms supported on the server?

>Are there any other settings we can try?

I think its a good idea to update old software on server side..
If not possible, then tell us what TLS versions supported on your server, what ciphers supported (key exchange, signature algorithms), may be we can enable old cipher or add some option.

Regards
Alex
Back to top
View user's profile Send private message Visit poster's website
James65



Joined: 26 Feb 2024
Posts: 8

PostPosted: Tue Mar 05, 2024 4:34 am    Post subject: Reply with quote

Hi Alex,
Thanks for the info. We checked further and the problem seems to be only happening when the POP3-Server is running on Windows Server 2022. We connected to the POP3-Server using OpenSSL and the connection shows following information:

TLSv1.2, Cipher is ECDHE-RSA-AES256-GCM-SHA384

When the same POP3-Server is running on "Windows Server 2019" it works fine and OpenSSL shows the same TLS and Cipher.

Will also check with the developer of the POP3-Server if there are any updates available.

Best regards
Michael
Back to top
View user's profile Send private message
KS-Soft



Joined: 03 Apr 2002
Posts: 12795
Location: USA

PostPosted: Tue Mar 05, 2024 3:06 pm    Post subject: Reply with quote

Yes, when OpenSSL is not used but Windows API is used for encryption then result depends on Windows version (and settings).
But Windows 2022 supports ECDHE-RSA-AES256-GCM-SHA384
https://learn.microsoft.com/en-us/windows/win32/secauthn/tls-cipher-suites-in-windows-server-2022

Could you check SSL Cipher Suite Order group policy setting using gpedit.msc?
Computer Configuration -> Administrative Templates -> Network -> SSL Configuration Settings -> SSL Cipher Suite Order

Also TLS 1.2 should be enabled in HostMonitor settings. TLS 1.2 enabled by default or when you set sslProto_POP3 parameter to
- 2048 (just TLS 1.2)
- 2560 (TLS 1.1 and 1.2)
- 10752 (TLS 1.1, 1.2, 1.3)

In HostMonitor 13.80 by default enabled SSL3, TLS1, TLS1.1 and TLS1.2
In HostMonitor 14.00 by default enabled TLS1.1, TLS1.2, TLS 1.3

Quote:
We already tried sslProto_POP3 in Misc section but none of the values are solving the issue.

Have you tried sslProto_POP3=2560?

Have you tried to set sslProto_POP3 parameter to 2720 (like old HM 13.80)?
This will not help if server really supports TLS 1.2 but this may help if server does not support TLS 1.2 and even TLS 1.1 while supports really old protocols.

Note: you have to restart HostMonitor when you making such changed

Regards
Alex
Back to top
View user's profile Send private message Visit poster's website
James65



Joined: 26 Feb 2024
Posts: 8

PostPosted: Wed Mar 06, 2024 4:30 am    Post subject: Reply with quote

Hi Alex,
Thanks for the detailed information. The SSL Cipher Suite Order group policy is not configured.
I can confirm it works fine with HM14 when using sslProto_POP3 with 2048 or 2560. It fails with 10752. The POP3 Server we are connecting to does not support TLS1.3 yet, so it looks like HM tries to use the highest available TLS version from its configuration for some reason. Maybe the POP3 Server does not announce its available TLS version during connection...
So we use one of working settings for now.
Thanks again for your assistance.

Best regards
Michael
Back to top
View user's profile Send private message
KS-Soft



Joined: 03 Apr 2002
Posts: 12795
Location: USA

PostPosted: Wed Mar 06, 2024 3:46 pm    Post subject: Reply with quote

You are welcome.
We will check the code on our side as well..

Regards
Alex
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    KS-Soft Forum Index -> Configuration, Maintenance, Troubleshooting All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group

KS-Soft Forum Index