Alpha Software Mobile Development Tools:   Alpha Anywhere    |   Alpha TransForm subscribe to our YouTube Channel  Follow Us on LinkedIn  Follow Us on Twitter  Follow Us on Facebook

Announcement

Collapse

The Alpha Software Forum Participation Guidelines

The Alpha Software Forum is a free forum created for Alpha Software Developer Community to ask for help, exchange ideas, and share solutions. Alpha Software strives to create an environment where all members of the community can feel safe to participate. In order to ensure the Alpha Software Forum is a place where all feel welcome, forum participants are expected to behave as follows:
  • Be professional in your conduct
  • Be kind to others
  • Be constructive when giving feedback
  • Be open to new ideas and suggestions
  • Stay on topic


Be sure all comments and threads you post are respectful. Posts that contain any of the following content will be considered a violation of your agreement as a member of the Alpha Software Forum Community and will be moderated:
  • Spam.
  • Vulgar language.
  • Quotes from private conversations without permission, including pricing and other sales related discussions.
  • Personal attacks, insults, or subtle put-downs.
  • Harassment, bullying, threatening, mocking, shaming, or deriding anyone.
  • Sexist, racist, homophobic, transphobic, ableist, or otherwise discriminatory jokes and language.
  • Sexually explicit or violent material, links, or language.
  • Pirated, hacked, or copyright-infringing material.
  • Encouraging of others to engage in the above behaviors.


If a thread or post is found to contain any of the content outlined above, a moderator may choose to take one of the following actions:
  • Remove the Post or Thread - the content is removed from the forum.
  • Place the User in Moderation - all posts and new threads must be approved by a moderator before they are posted.
  • Temporarily Ban the User - user is banned from forum for a period of time.
  • Permanently Ban the User - user is permanently banned from the forum.


Moderators may also rename posts and threads if they are too generic or do not property reflect the content.

Moderators may move threads if they have been posted in the incorrect forum.

Threads/Posts questioning specific moderator decisions or actions (such as "why was a user banned?") are not allowed and will be removed.

The owners of Alpha Software Corporation (Forum Owner) reserve the right to remove, edit, move, or close any thread for any reason; or ban any forum member without notice, reason, or explanation.

Community members are encouraged to click the "Report Post" icon in the lower left of a given post if they feel the post is in violation of the rules. This will alert the Moderators to take a look.

Alpha Software Corporation may amend the guidelines from time to time and may also vary the procedures it sets out where appropriate in a particular case. Your agreement to comply with the guidelines will be deemed agreement to any changes to it.



Bonus TIPS for Successful Posting

Try a Search First
It is highly recommended that a Search be done on your topic before posting, as many questions have been answered in prior posts. As with any search engine, the shorter the search term, the more "hits" will be returned, but the more specific the search term is, the greater the relevance of those "hits". Searching for "table" might well return every message on the board while "tablesum" would greatly restrict the number of messages returned.

When you do post
First, make sure you are posting your question in the correct forum. For example, if you post an issue regarding Desktop applications on the Mobile & Browser Applications board , not only will your question not be seen by the appropriate audience, it may also be removed or relocated.

The more detail you provide about your problem or question, the more likely someone is to understand your request and be able to help. A sample database with a minimum of records (and its support files, zipped together) will make it much easier to diagnose issues with your application. Screen shots of error messages are especially helpful.

When explaining how to reproduce your problem, please be as detailed as possible. Describe every step, click-by-click and keypress-by-keypress. Otherwise when others try to duplicate your problem, they may do something slightly different and end up with different results.

A note about attachments
You may only attach one file to each message. Attachment file size is limited to 2MB. If you need to include several files, you may do so by zipping them into a single archive.

If you forgot to attach your files to your post, please do NOT create a new thread. Instead, reply to your original message and attach the file there.

When attaching screen shots, it is best to attach an image file (.BMP, .JPG, .GIF, .PNG, etc.) or a zip file of several images, as opposed to a Word document containing the screen shots. Because Word documents are prone to viruses, many message board users will not open your Word file, therefore limiting their ability to help you.

Similarly, if you are uploading a zipped archive, you should simply create a .ZIP file and not a self-extracting .EXE as many users will not run your EXE file.
See more
See less

SSL issue with Chrome browser

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    SSL issue with Chrome browser

    My website is experiencing SSL issues that only seem to affect the Chrome browser. The error is intermittent - it only happens on some computers and only sometimes.

    The issue is that the user will occasionally get an SSL Connection error. Most of the time, doing a refresh fixes the problem.

    I have rekeyed my SSL Certificate using a version of Alpha V12 that is only about a month old. (It is a pre-release version.)

    My server is with Go-Daddy and they say that the error is because of the SHA-1 Root certificate that is part of the SSL setup. But I don't know how to fix that.

    Help?

    #2
    Re: SSL issue with Chrome browser

    Start by having Qualys SSL Labs run a free SSL test against your site.
    https://www.ssllabs.com/ssltest/

    That site may give you a better idea of what might be wrong with the certificate. Maybe your certificate is not from a trusted source. Where was the SSL certificate purchased from? Who bought and installed the certificate and were all the steps followed to get it properly registered with the certificate authority?

    Another issue that comes up across the various browser platforms is the SSL "Cipher List". Search this newsgroup on that topic.

    Comment


      #3
      Re: SSL issue with Chrome browser

      I searched for cypher lists. My original cypher list was:

      ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:ECDHE-RSA-RC4-SHA:ECDHE-ECDSA-RC4-SHA:AES128:AES256:RC4-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!3DES:!MD5:!PSK

      I found a cypher list on this forum that said to use:

      ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5:!DSS:-SSLv3

      The post I saw said it was working great.

      After changing to that new cypher list, I got a great rating on the test site you specified (A-) and now it works great in Chrome and Explorer.

      However, now firefox won't connect at all. It says it can't find a connection profile. I assume that means my list is now too short and doesn't include a connection that FF wants to use.

      Can someone please give me a cypher list that will work with Firefox, Explorer, Chrome AND Safari?

      Comment


        #4
        Re: SSL issue with Chrome browser

        Larry I do not trust Godaddy tech support people the are weak.
        Zebrahost would have this fixed up for you, quickly.
        Nicholas Wieland
        LedgerSuite.com Corp
        [email protected]
        http://www.ledgersuite.com

        Comment


          #5
          Re: SSL issue with Chrome browser

          Zebrahost is the one that has taken care of my SSL certificate. They did the setup for me, notified me when it was time to renew, and made sure I did the necessary follow up with the certifying authority to have them issue it.

          That all went very smoothly, but when it comes to the Cipher List, it takes a lot more effort. I think it is too important to completely trust someone else to setup. Only YOU can determine the compromise between the level of security vs. the range of browsers that you want to allow into your site.

          Of course, if you have looked into the Cipher List then you may also have discovered that each vendor (Alpha Software, in our case) that uses OpenSSL must compile their own version of SSL libraries from the pure source code that openSSL.org provides. And, digging deeper you may have discovered that running a particular cipher list through different vendors's SSL enabled server software results in different levels of SSL/TSL compatibility. Factors that influence compatibility include: 1) how the vendor chose to process the cipher list and initialize their OpenSSL instance, and 2) which version of source base code from openssl.org the vendor is using.

          Comment


            #6
            Re: SSL issue with Chrome browser

            Then what I need is a cipher list creator/decipher.

            Something that lists all of the possible ciphers and allows me to choose between them - then creates a cipher list for me that will work in Alpha.

            Even better - something that I can put my current list into, have it tell me what ciphers are in it, then allow me to remove them until it works how I want it.

            That way I can modify the cipher list and test different options out.

            Otherwise I have no idea what to do - this is all Greek to me.

            And while I do value Zebrahost's helpfulness - have servers with them, this server is not on Zebrahost, so ...

            Comment


              #7
              Re: SSL issue with Chrome browser

              Larry,
              As far as I can tell from the openssl wiki site , we need Alpha to give us the openSSL.exe command line tool that they would have built to go along with the two files they distribute: "libeay32.dll" and "ssleay32.dll".

              I just asked Alpha if they could post it for us.


              I found this web site that has a free e-book about OpenSSL: https://www.feistyduck.com/library/openssl-cookbook/

              Comment


                #8
                Re: SSL issue with Chrome browser

                Rich, which version of the DLLs are you using? You will need the matching openssl.exe.

                Also the Feisty Duck books are excellent. The author is the person behind the tools at https://www.ssllabs.com/ssltest/

                Lenny Forziati
                Vice President, Internet Products and Technical Services
                Alpha Software Corporation

                Comment


                  #9
                  Re: SSL issue with Chrome browser

                  I don't know about Rich, but I am currently using Alpha Version 12.3 Build 3258. It is a pre-release.

                  So whatever SSL files come with that.

                  I'd be willing to replace the ssl files with new ones to get everything to the right place.

                  Comment


                    #10
                    Re: SSL issue with Chrome browser

                    Lenny,
                    Alpha Build 2999 is what I will be using. I believe that is the latest official production release.
                    The SSL files say "File version 1.01.16" and "Product version 1.0.1p"

                    Thanks for jumping in here, Lenny.

                    Comment


                      #11
                      Re: SSL issue with Chrome browser

                      All of the OpenSSL 1.0.1p EXEs and DLLs as built by Alpha can now be downloaded from http://downloads.alphasoftware.com/O...SSL_1.0.1p.zip

                      Lenny Forziati
                      Vice President, Internet Products and Technical Services
                      Alpha Software Corporation

                      Comment


                        #12
                        Re: SSL issue with Chrome browser

                        What is the default cypher list that comes with that build, please?

                        Comment


                          #13
                          Re: SSL issue with Chrome browser

                          Lenny, Thanks.

                          Others,
                          So I did the following:
                          1) Download and unzip the file from Lenny's Post #11 above, to a NEW folder.
                          2) Went to the command prompt,
                          3) CD into that NEW folder.
                          4) entered the command, "Openssl"
                          5) and then waited for a minute or so for it to initialize and come up with the "OpenSSL>" prompt.
                          6) then gave it the command "ciphers -v "my_ciphers"
                          where my_ciphers is the string displayed on my Alpha Web Server console under the "SSL" tab.
                          7) I got back a list of encryptions that match that string. If you want to see all, just leave out your cipher list. If you want more detail use an upper case "-V".

                          Comment


                            #14
                            Re: SSL issue with Chrome browser

                            Larry, I don't have an actual Web Server installed from scratch directly off of build 2999. But the developer server that gets installed with Build 2999 and the 1.0.1p SSL libraries appears to have this as the default cipher list:

                            Code:
                            ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:ECDHE-RSA-RC4-SHA:ECDHE-ECDSA-RC4-SHA:AES128:AES256:RC4-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!3DES:!MD5:!PSK

                            Comment


                              #15
                              Re: SSL issue with Chrome browser

                              That list looks exactly like the one I have up top.

                              It gives a less than stellar rating on the ssl test site and it occasionally (1 in about 40 times) gives Chrome and Safari issues - at least on the Godaddy site that I am using.

                              It works fine for IE and Firefox so far as I can tell.

                              I really have no idea how to proceed.

                              Comment

                              Working...
                              X