KSSL problems

Bug #44311 reported by leonbottou
264
Affects Status Importance Assigned to Milestone
kdelibs (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

I noticed some SSL strangeness on Dapper Flight 7

The first example arises with the Fidelity web site
because they check that the encryption level
is sufficient, probably using a slightly flawed
algorithm.

1) Go to kcontrol/crypto, enable everything
     Go to https://www.fidelity.com.
     Using the security icon in the konqueror status
     bar, you can check that it uses AES256-SHA.

2) Click the login button.
     Chances are that you go to a page explaining
     that you do not have 128 bit
     encryption. Note that this is working
     on breezy/kubuntu-3.5.2.

3) Return to the crypto configuration and
     select the 'most compatible' ciphers.
     This disable AES256-SHA in principle.
     Click apply. Reload the Fidelity home page.
     Check the encryption with the lock icon.
     Still AES256-SHA despite being disabled!!!!

4) Disable SSLv3 in the crypto dialog.
    This time Fidelity loads in SSLv2 128 bits.
    Login still does not work..

The second problem was reported in bug #32846
in kdepim. I am not sure they are related.
I had similar problems a few years ago.
They were caused by running kssl with
an openssl version different from that
used for compiling kssl.

I check 'security issue' because ssl is a key
security component. Malfunction is dangerous.

- L. B.

Revision history for this message
Kees Cook (kees) wrote :

I cannot reproduce this. From the main page, I see RC4-MD5, and for login pages, I see AES256-SHA, and it doesn't tell me I'm missing 128bit. Do you still see this problem with Dapper?

Revision history for this message
leonbottou (leon-bottou) wrote : Re: [Bug 44311] Re: KSSL problems

On Wednesday 04 October 2006 15:07, Kees Cook wrote:
> I cannot reproduce this. From the main page, I see RC4-MD5, and for
> login pages, I see AES256-SHA, and it doesn't tell me I'm missing
> 128bit. Do you still see this problem with Dapper?

Yes. I also see AES256-SHA, but it tells me I'm missing 128 bits.
I tried changing the browser identity and playing with the kssl config as described in the bug report.
Regardless of what I am doing, clicking on the login button leads me to http://interceptor.fidelity.com/
But it was working in Breezy. I wonder what is changed...
Difficult to know without knowing what they check...

- L.

Revision history for this message
Kees Cook (kees) wrote :

Do you still see problems in Edgy? I'm still unable to reproduce the problem.

Revision history for this message
leonbottou (leon-bottou) wrote :

I did not try edgy yet.
The problem happens using konqueror-3.5.2 on dapper.
It does not happen using konqueror-3.5.2 on breezy.
If it works in edgy, great!

(but somehow i would have liked
 to understand what is going on.)

- L.

Changed in kdelibs:
status: Unconfirmed → Needs Info
Revision history for this message
Rich Johnson (nixternal) wrote :

I am going to fix release this as I have been using Konqueror for a while to check my Fidelity accounts. And I haven't messed with any of the kcontrol/crypto settings either. If you feel this is still an issue, I urge you to please reopen this report with any further information you may have. Thank you.

Changed in kdelibs:
status: Needs Info → Fix Released
Revision history for this message
leonbottou (leon-bottou) wrote :

On Friday 08 June 2007 21:57:50 Richard Johnson wrote:
> I am going to fix release this as I have been using Konqueror for a
> while to check my Fidelity accounts. And I haven't messed with any of
> the kcontrol/crypto settings either. If you feel this is still an issue,
> I urge you to please reopen this report with any further information you
> may have. Thank you.

For me the problem is gone with kde-3.5.6.
It now works.,
- L.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.