[gnutls-devel] GnuTLS | gnutls-serv and gnutls-client fail with "Detected downgrade to TLS 1.2 from TLS 1.3" (#837)

Development of GNU's TLS library gnutls-devel at lists.gnutls.org
Sat Sep 21 13:36:51 CEST 2019




Richard Frith-Macdonald commented:


Oops, I realise I just realised I got part of that the wrong way round:
> but that means that the connection will be established using the oldest version
> that client and server support, not the newest/best, which seems undesirable.

So the 'workaround' is to specify the versions in the more natural/desirable order,  which makes this a minor usability issue rather than a serious bug.
NB. connecting with the same priority string to an openssl server works, which suggests they implemented a 'fix' at the server and to improve usability.

-- 
Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/issues/837#note_220191783
You're receiving this email because of your account on gitlab.com.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.gnupg.org/pipermail/gnutls-devel/attachments/20190921/40b7b47f/attachment.html>


More information about the Gnutls-devel mailing list