Re: [Qemu-devel] Error when attempting to perform TLS NBD connection

From: Alex Bligh
Re: [Qemu-devel] Error when attempting to perform TLS NBD connection
Date: Wed, 6 Apr 2016 10:17:09 +0100

On 6 Apr 2016, at 10:09, Daniel P. Berrange <address@hidden> wrote:

> I've just tested using your certs and they work correctly for me. I have
> gnutls-3.4.10-1.fc23.x86_64  on Fedora 23, so either there's something
> broken with gnutls 2.x compatibility in general, or there's a specific
> bug in your exact version of gnutls. I'll try and investigate further

Thanks. My concern is that it looks (unless I've been an idiot)
like it won't work on vanilla LTS ubuntu, which is a bit sad!

I don't think I did anything abnormal beyond a 'git pull' and
  './configure --prefix=/usr --target-list=x86_64-softmmu

I'm guessing the problem is an older libgnutls.

Here's a complete list of what I have installed that could
possibly have anything to do with crypto:

$ dpkg --list | egrep 'nss|ssl|tls|crypto' | awk '{print $2, $3}'
docbook-dsssl 1.79-7ubuntu1
ecryptfs-utils 104-0ubuntu1.14.04.3
erlang-crypto 1:16.b.3-dfsg-1ubuntu2.1
erlang-ssl 1:16.b.3-dfsg-1ubuntu2.1
gcr 3.10.1-1
gnutls-bin 3.0.11+really2.12.23-12ubuntu2.5
insserv 1.14.0-5ubuntu2
ldp-docbook-dsssl 0.0.20040321-2build1
libcrypt-openssl-dsa-perl 0.14-1
libcrypt-ssleay-perl 0.58-1build1
libcurl3-gnutls:amd64 7.35.0-1ubuntu2.5
libcurl3-nss:amd64 7.35.0-1ubuntu2.1
libcurl4-openssl-dev:amd64 7.35.0-1ubuntu2.5
libecryptfs0 104-0ubuntu1.14.04.3
libevent-openssl-2.0-5:amd64 2.0.21-stable-1ubuntu1.14.04.1
libflac8:amd64 1.3.0-2ubuntu0.14.04.1
libgnutls-dev 2.12.23-12ubuntu2.4
libgnutls-openssl27:amd64 2.12.23-12ubuntu2.4
libgnutls26:amd64 2.12.23-12ubuntu2.4
libgnutlsxx26:amd64 2.10.5-1ubuntu3.3
libgnutlsxx27:amd64 2.12.23-12ubuntu2.4
libhcrypto4-heimdal:amd64 1.6~git20131207+dfsg-1ubuntu1.1
libio-socket-ssl-perl 1.965-1ubuntu1
libk5crypto3:amd64 1.12+dfsg-2ubuntu5.2
libneon27-gnutls 0.30.0-1ubuntu1
libnet-smtp-ssl-perl 1.01-3
libnet-ssleay-perl 1.58-1
libnettle4:amd64 2.7.1-1
libnss-mdns:amd64 0.10-6
libnss3:amd64 2:
libnss3-1d:amd64 2:
libnss3-nssdb 2:
libssl-dev:amd64 1.0.1f-1ubuntu2.16
libssl-doc 1.0.1f-1ubuntu2.16
libssl0.9.8:amd64 0.9.8o-7ubuntu3.
libssl1.0.0:amd64 1.0.1f-1ubuntu2.16
libwavpack1:amd64 4.70.0-1
openssh-client 1:6.6p1-2ubuntu2.4
openssh-server 1:6.6p1-2ubuntu2.4
openssh-sftp-server 1:6.6p1-2ubuntu2.4
openssl 1.0.1f-1ubuntu2.16
python-crypto 2.6.1-4build1
python-openssl 0.13-2ubuntu6
python-passlib 1.5.3-0ubuntu3
python3-crypto 2.6.1-4build1
ssl-cert 1.0.33

Alex Bligh

