Alan,
I think best is to file a bug report.
Wizard Brian did a great job and probably has a lot other to do, so a
bit patient may be required...
https://core.tcl-lang.org/tcltls/reportlist
or
https://github.com/bohagan1/TclTLS/issues
Take care,
Harald
On 29/01/2026 15:37, Harald Oehlmann wrote:
Alan,
I think best is to file a bug report.
Wizard Brian did a great job and probably has a lot other to do, so a
bit patient may be required...
https://core.tcl-lang.org/tcltls/reportlist
or
https://github.com/bohagan1/TclTLS/issues
Take care,
Harald
I'll do that Harald. There's no hurry as far as I'm concerned - Ive
simply reverted to tls 2.0b2.
Alan
On 1/29/26 2:55 PM, Alan Grunwald wrote:
On 29/01/2026 15:37, Harald Oehlmann wrote:
Alan,
I think best is to file a bug report.
Wizard Brian did a great job and probably has a lot other to do, so a
bit patient may be required...
https://core.tcl-lang.org/tcltls/reportlist
or
https://github.com/bohagan1/TclTLS/issues
Take care,
Harald
I'll do that Harald. There's no hurry as far as I'm concerned - Ive
simply reverted to tls 2.0b2.
Alan
Remove the "-tls1 1" argument from your tls::socket command and it
should work (it did for me on 2.0 and 2.0b2).
The reason it worked for 2.0b2, but not 2.0 is I simplified the logic
for setting which TLS protocols to use. For 2.0, with just the "-tls1 1" argument, you told it to only offer TLS 1.0 and not 1.1, 1.2, or 1.3.
Most web servers will refuse connections for anything less than 1.2 nowadays. That's the error you got. In 2.0b2, I always forced TLS 1.2
and 1.3 to be allowed unless you used "-tls1.2 0 -tls1.3 0" to turn them off. Why the change? OpenSSL prefers we specify ranges of allowed
protocols now instead of them individually.
As a rule of thumb, in TLS 2.0 you don't need to specify which TLS
protocols to use anymore. In fact, it's discouraged unless you really
need one of the older protocols.
Thanks Brian.
I can (and indeed do) now register the https protocol with
http::register https 443 ::tls::socket
which is vastly simpler than it has been with previous incarnations of
the (tcl)tls package. I seem to have plagued you with questions about
this package recently, thank you very much for the speedy and always accurate and relevant support.
Alan
| Sysop: | DaiTengu |
|---|---|
| Location: | Appleton, WI |
| Users: | 1,096 |
| Nodes: | 10 (0 / 10) |
| Uptime: | 364:29:02 |
| Calls: | 14,034 |
| Calls today: | 2 |
| Files: | 187,081 |
| D/L today: |
1,583 files (486M bytes) |
| Messages: | 2,478,467 |