Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: Checkpoint FW-1 on HPUX -- SSL problem
From: Ken Kempster <kempster @ monarch . rnb . com>
Organization: Republic National Bank
Date: Thu, 27 Feb 1997 13:55:35 -0500 (EST)
To: "Schlueter, Ian" <ian @ netwrx . net>
Cc: "firewalls @ greatcircle . com" <firewalls @ GreatCircle . COM>
Comments: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Comments: Internet Message: Sender identity is not verified.
Comments: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
In-reply-to: <c=US%a=_%p=Avnet_Inc . %l=AZ1011-N1-970227170138Z-371 @ az1011-n1 . avnet . com>

On 27-Feb-97 Schlueter, Ian wrote:
>
>
>
>       I have run into something that I cannot explain, and I need some
>advice.
>
>       When accessing certain secure pages my users, and I, receive an error
>stating "Insufficient encryption
> This document requires a larger secret key size for encryption than
>your browser is capable of supporting. "  I can hit my ISP account and
>use the same browser, computer etc. to access this same page without
>that error.  
>
>    I am fairly sure that this is due to something happening at our
>Checkpoint FW-1 level.  I have examined configs and rules, and from what
>I can tell I have done everything correctly.  We are able to access
>other secure web sites, it just appears that this particular site is
>doing something, possible involving a much larger key.
>
>   If case you are interested the site is http://www.intel.com/sales/ --
>attempt to enter the secure area from this site and you should be
>prompted for a username and password.  We are not getting the login
>prompt, we are getting the "key size" error.

I got the same error sitting behind Gauntlet 3.2
I'll fire off an email to TIS and see if they have any suggestions.


>
>
>                               Ian Schlueter
>
>
>
>

|~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
|  Ken Kempster               kempster @
 monarch .
 rnb .
 com    |   
|  Network Systems Engineer          _\|/_                |
|  Republic National Bank            (o o)                |
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~oOO-(_)-OOo~~~~~~~~~~~~~~


References:
Indexed By Date Previous: Re: virus checking
From: Pavel Galynin <pgalynin @ chipnet . cz>
Next: Re: Checkpoint FW-1 on HPUX -- SSL problem
From: Darren Fallis <darren . fallis @ wcom . com>
Indexed By Thread Previous: Checkpoint FW-1 on HPUX -- SSL problem
From: "Schlueter, Ian" <ian @ netwrx . net>
Next: Re: Checkpoint FW-1 on HPUX -- SSL problem
From: Darren Fallis <darren . fallis @ wcom . com>

Google
 
Search Internet Search www.greatcircle.com