TLS handshake timeout

Démarré par PsYkO, Hier à 17:26:01

« précédent - suivant »

0 Membres et 1 Invité sur ce sujet

Je suis touché par des erreurs de connexion TLS à certains services seulement, et de facon intermitente (~40%)
Je constate ces problèmes que ce soit en filaire ou en wifi, et avec la même machine sur un hotspot, plus d'erreur.

KO:
% openssl s_client -connect github.com:443 -servername github.com
Connecting to 140.82.121.3
CONNECTED(00000005)
<plus rien>

OK:
% openssl s_client -connect github.com:443 -servername github.com
Connecting to 140.82.121.3
CONNECTED(00000005)
depth=2 C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication Root E46
verify return:1
depth=1 C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA DV E36
verify return:1
depth=0 CN=github.com
verify return:1
---
Certificate chain
 0 s:CN=github.com
   i:C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA DV E36
<...>

Curl:
% curl -v https://github.com
* Host github.com:443 was resolved.
* IPv6: (none)
* IPv4: 140.82.121.4
*   Trying 140.82.121.4:443...
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* Connection timed out after 300339 milliseconds
* closing connection #0
curl: (28) Connection timed out after 300339 milliseconds

Curl -vv
% curl -vv https://github.com
17:31:05.035415 [0-0] * Host github.com:443 was resolved.
17:31:05.035679 [0-0] * IPv6: (none)
17:31:05.035702 [0-0] * IPv4: 140.82.121.4
17:31:05.035728 [0-0] * [HTTPS-CONNECT] adding wanted h2
17:31:05.035752 [0-0] * [HTTPS-CONNECT] added
17:31:05.035775 [0-0] * [HTTPS-CONNECT] connect, init
17:31:05.035809 [0-0] *   Trying 140.82.121.4:443...
17:31:05.036033 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
17:31:05.036062 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
17:31:05.036088 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 1 socks
17:31:05.040668 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
17:31:05.040704 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
17:31:05.040731 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 1 socks
17:31:05.141379 [0-0] * ALPN: curl offers h2,http/1.1
17:31:05.141731 [0-0] * TLSv1.3 (OUT), TLS handshake, Client hello (1):
17:31:05.152143 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
17:31:05.152196 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
17:31:05.152240 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 1 socks
17:31:06.153457 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
17:31:06.153632 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
17:31:06.153739 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 1 socks
17:31:07.154053 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
17:31:07.154219 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
17:31:07.154321 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 1 socks
17:31:08.155081 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
17:31:08.155148 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
17:31:08.155182 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 1 socks
17:31:09.155594 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
17:31:09.155773 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
17:31:09.155879 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 1 socks
17:31:10.157136 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
17:31:10.157300 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
17:31:10.157404 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 1 socks
17:31:11.158078 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
17:31:11.158153 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
17:31:11.158207 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 1 socks
17:31:12.159444 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
17:31:12.159626 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
17:31:12.159737 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 1 socks
17:31:13.160998 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
17:31:13.161166 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
17:31:13.161271 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 1 socks
17:31:14.161837 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
17:31:14.162009 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
17:31:14.162115 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 1 socks
17:31:15.163399 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
17:31:15.163581 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
17:31:15.163695 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 1 socks
<...>

Une idée de ce qu'il peut se passer ?
Merci !

Pareillement affecté : je pense à un souci de routage, peering  car en utilisant un vpn j'accède à github en un clin d'oeil.

Bonjour,
pouvez vous ressayez svp ?
cdlt
D.M.

Le problème est apparement résolu !
Merci pour la réponse/action rapide !