SSL not working

These are old archives. They are kept for historic purposes only.
Post Reply
Syzop
UnrealIRCd head coder
Posts: 2179
Joined: Sat Mar 06, 2004 8:57 pm
Location: .nl
Contact:

Post by Syzop »

(topic split from previously unrelated issue)
Shintorojin wrote:could you plz explain the process of setting up the precompiled windows version of unrealircd to accept ssl connections...
see the documentation on the listen block (a section in unreal32docs.html) :).

I'll leave the rest to someone else ;p.
Last edited by Syzop on Sat Jul 02, 2005 12:59 am, edited 1 time in total.
Shintorojin
Posts: 17
Joined: Sat Jun 18, 2005 1:44 pm
Location: Neo-Tokyo
Contact:

Post by Shintorojin »

lol thanks ;P I checked the listen block, but when i get someone to try and connect it just says connection refused or timed out... SO i'm at a loss with what to do. A friend told me he had to load a module on the nix version. So i was wondering if maybe i'm missing something...
Death, Life's true voyeur...
Syzop
UnrealIRCd head coder
Posts: 2179
Joined: Sat Mar 06, 2004 8:57 pm
Location: .nl
Contact:

Post by Syzop »

Could you paste your listen block you use for SSL? Also perhaps output from '/stats P' to doublecheck if it is indeed listening.

And 3rd, make sure you have no firewall/router issues.
Shintorojin
Posts: 17
Joined: Sat Jun 18, 2005 1:44 pm
Location: Neo-Tokyo
Contact:

Post by Shintorojin »

Listen Block:
listen *:6697 {
options {
ssl;
clientsonly;
};
};


Stats P:
-
-neo-tokyo.Galaxycorp.za.net- *** Listener on *:6697, clients 1. is PERM clientsonly SSL
-
-neo-tokyo.Galaxycorp.za.net- *** Listener on *:6667, clients 1. is PERM
-

I've opened up the ssl and normal port on my router. Everything is fine on the normal port. One thing i find strange is that i can't log in on the ssl port from my local lan either :\

Thanks for the help so far,
JM
Death, Life's true voyeur...
Syzop
UnrealIRCd head coder
Posts: 2179
Joined: Sat Mar 06, 2004 8:57 pm
Location: .nl
Contact:

Post by Syzop »

Yup, looks good.
Are you actually connecting with an SSL enabled client, and did you specify in the client it is an ssl port?
Like... '/server -e 127.0.0.1 6697' in mIRC or '/server -SSL 127.0.0.1 6697' in irssi.

'Connection refused' means something (and not unreal) is wrong, it means nothing is listening on the port, but as you can see from the '/stats P' output it is... So that means either a client/user issue, firewall or router problem.
'Connection timed out' is also firewall/router issue.
Assuming you did everything local (127.0.0.1) or to the LAN IP (eg: 192.168.1.100) then connection timed out/connection refused must be some firewall in-between :P.


blabla :P
Shintorojin
Posts: 17
Joined: Sat Jun 18, 2005 1:44 pm
Location: Neo-Tokyo
Contact:

Post by Shintorojin »

Hmmm, okay this :"/server -e 127.0.0.1 6697" works. But now, how do i set things up the people don't need to use the "-e" And yes it's all on local box...


THanks for all the help so far,
JM
Death, Life's true voyeur...
Stealth
Head of Support
Posts: 2085
Joined: Tue Jun 15, 2004 8:50 pm
Location: Chino Hills, CA, US
Contact:

Post by Stealth »

You need to always use the -e, or +6697. The client can only connect to an SSL port if you tell it the port is SSL.
Shintorojin
Posts: 17
Joined: Sat Jun 18, 2005 1:44 pm
Location: Neo-Tokyo
Contact:

Post by Shintorojin »

okay but then how is it with other servers such as shadowfire.org or lagnet.za.org you don't need either? and it is on the ssl port... But yeah, i'm just curious.
Thanks for all your help!

JM
Death, Life's true voyeur...
Stealth
Head of Support
Posts: 2085
Joined: Tue Jun 15, 2004 8:50 pm
Location: Chino Hills, CA, US
Contact:

Post by Stealth »

If you don't tell the client you want SSL, it won't use SSL.
Rascal999
Posts: 4
Joined: Wed Jul 27, 2005 8:55 am

Post by Rascal999 »

I have the same problem as Shintorojin but when I tried '/server -e 127.0.0.1 6697' it said * /server: ssl not available ??
Dukat
Posts: 1083
Joined: Tue Mar 16, 2004 5:44 pm
Location: Switzerland

Post by Dukat »

You have to install OpenSSL first...
http://www.mirc.co.uk/ssl.html
If you don't make mistakes, you aren't really trying.
- Coleman Hawkins
Rascal999
Posts: 4
Joined: Wed Jul 27, 2005 8:55 am

Post by Rascal999 »

Thankyou that did sort out my problem. If anyone else wanted to connect to my server would they have to download OpenSSL as well?
Dukat
Posts: 1083
Joined: Tue Mar 16, 2004 5:44 pm
Location: Switzerland

Post by Dukat »

Unless you provide an additional, unencrypted port... Yes... (if they are using mIRC)
If you don't make mistakes, you aren't really trying.
- Coleman Hawkins
Post Reply