Welcome, Guest. Please login or register.

Author Topic: -Amiga SSL Certificate Update  (Read 1349 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline DrummerboyTopic starter

  • Hero Member
  • *****
  • Join Date: Jul 2003
  • Posts: 512
    • Show only replies by Drummerboy
-Amiga SSL Certificate Update
« on: November 13, 2015, 03:35:48 AM »
Hello,

Anyone know if exist an update SSL Certificate for AOS 3.X?. I frecuently navigate on my A1200 OS 3.0, using Ibrowse,  but some sites show this message (as Twitter or Wikipedia): "SSL Connect error. Ther remote server is using an encryption protocol not supported by IBrowse.", and some time ago, work without problems.

Any suggest or comment are welcome.

Regards.
Amiga 1000, 500, 600, 2000, 1200, 4000...

C= VIC 20 / 64 /SX64/ 128

Atari 600XL (SIC Cartdridge)
Atari 800XL (SIO2SD unit)

Jay Miner`s Atari 2600 - Wood front -

\\"Amiga, this Computer have a Own Live\\"--\\"Silence When the Drums are Talking\\".... DrummerBoy
 

Offline Oldsmobile_Mike

Re: -Amiga SSL Certificate Update
« Reply #1 on: November 13, 2015, 03:58:00 AM »
AFAIK Oliver Roberts has been working on an update to AmiSSL for years, but he's hamstrung by the rest of the "IBrowse team" until they get their act together.  That's paraphrasing pretty badly, but more specific info should already exist on the forum somewhere. ;)
Amiga 500: 2MB Chip|16MB Fast|30MHz 68030+68882|3.9|Indivision ECS|GVP A500HD+|Mechware card reader + 8GB CF|Cocolino|SCSI DVD-RAM
Amiga 2000: 2MB Chip|136MB Fast|50MHz 68060|3.9|Indivision ECS + GVP Spectrum|Mechware card reader + 8GB CF|AD516|X-Surf 100|RapidRoad|Cocolino|SCSI CD-RW
 Amiga videos and other misc. stuff at https://www.youtube.com/CompTechMike/videos
 

Offline LoadWB

  • Hero Member
  • *****
  • Join Date: Jul 2006
  • Posts: 2901
  • Country: 00
    • Show only replies by LoadWB
Re: -Amiga SSL Certificate Update
« Reply #2 on: November 13, 2015, 06:40:25 AM »
For what it's worth, it's not an SSL certificate that needs to be updated, but the AmiSSL suite altogether (i believe IBrowse uses AmiSSL, it's been so long I can't remember.)  It only supports up to SSLv3, which has been deprecated industry-wide as it has numerous exploitable flaws, including an error in the block-ciphers which cannot be fixed as it is ingrained in the protocol itself.

Within the next year TLSv1 will be deprecated, as well, even though it supports good ciphers like AES128-SHA256.  The idea is that since it is based upon SSLv3 (SSL is the Netscape secure sockets implementation, TLS is the resultant standard) it won't be long before it will be compromised, as well.

SSLv2 and SSLv3 are done.  MD5- and RC4- based ciphers are easily exploitable.  SHA1 hashed ciphers are now proven weak due to the (relative) ease of finding collisions.  As well, SSL certificates with SHA1 signatures will be tossed within the next six months (it's already virtually impossible to get a SHA1-signed certificate from the major vendors.)

tl;dr: AmiSSL needs to be updated to support TLSv1.2.
 

Offline DrummerboyTopic starter

  • Hero Member
  • *****
  • Join Date: Jul 2003
  • Posts: 512
    • Show only replies by Drummerboy
Re: -Amiga SSL Certificate Update
« Reply #3 on: November 14, 2015, 03:50:18 AM »
@LoadWB,

Thanks for the data!.
Amiga 1000, 500, 600, 2000, 1200, 4000...

C= VIC 20 / 64 /SX64/ 128

Atari 600XL (SIC Cartdridge)
Atari 800XL (SIO2SD unit)

Jay Miner`s Atari 2600 - Wood front -

\\"Amiga, this Computer have a Own Live\\"--\\"Silence When the Drums are Talking\\".... DrummerBoy
 

Offline Dandy

  • Hero Member
  • *****
  • Join Date: Apr 2004
  • Posts: 1221
    • Show only replies by Dandy
    • http://www.wiehltalbahn.de/en/
Re: -Amiga SSL Certificate Update
« Reply #4 on: November 26, 2015, 12:07:09 PM »
Quote from: LoadWB;799159


For what it's worth, it's not an SSL certificate that needs to be updated, but the AmiSSL suite altogether (i believe IBrowse uses AmiSSL, it's been so long I can't remember.)  It only supports up to SSLv3, which has been deprecated industry-wide as it has numerous exploitable flaws, including an error in the block-ciphers which cannot be fixed as it is ingrained in the protocol itself.
...

tl;dr: AmiSSL needs to be updated to support TLSv1.2.



An SSL update is not just urgently required for IBrowse, but also e.g. for YAM.

Currently it is not possible to access securepop and securesmtp servers
with YAM 2.9p1 - all attempts result in error messages.


I may also point you to the discusion drummerboy started at AmigaWorld.net, where I came to this conclusion:

"So what we would urgently need for our classic AmigaOS 3.x systems is something based on at least TLS 1.2 / OpenSSL v1.0.2d."
All the best,

Dandy

Website maintained by me

If someone enjoys marching to military music, then I already despise him. He got his brain accidently - the bone marrow in his back would have been sufficient for him! (Albert Einstein)