SAP Knowledge Base Article - Preview

3696113 - TLSv1.2 ciphers not working on ASE backupserver

Symptom

  • Attempting to use SSL with ASE 
  • Using TLSv1.2
  • Using ciphers TLS_ECDHE_RSA_WITH_AES128_GCM_SHA256 and TLS_ECDHE_RSA_WITH_AES256_GCM_SHA384 
  • Problem may applied to other ciphers as well
  • Get error
Srv-00000003: ClientHello: Client offers 3 cipher suite(s) and SCSV(s):
[backupserver        ][SSL         ][     1] Srv-00000003: Cipher suites Client:
[backupserver        ][SSL         ][     1]     TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
[backupserver        ][SSL         ][     1]     TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

These are the ciphers the server will negotiate with
Srv-00000003: ########## TLSERROR: Failure in TLS [0xA0600245: ClientHello message does not offer any cipher suite the server was configured to support.]
[backupserver        ][SSL         ][     1] Cipher suites Server:
[backupserver        ][SSL         ][     1]     TLS_RSA_WITH_AES_256_GCM_SHA384
[backupserver        ][SSL         ][     1]     TLS_RSA_WITH_AES_128_GCM_SHA256
[backupserver        ][SSL         ][     1]     TLS_RSA_WITH_AES_256_CBC_SHA
[backupserver        ][SSL         ][     1]     TLS_RSA_WITH_AES_128_CBC_SHA
[backupserver        ][SSL         ][     1] Selected cipher: None
[backupserver        ][SSL         ][     1] Srv-00000003: ########## TLSERROR: ClientHello::cipher_suites does not contain any cipher suite that the server accepts. [0xA0600245: ClientHello message does not offer any cipher suite the server was configured to support.]


Read more...

Environment

  • Adaptive Server Enterprise 16.0 
  • ASE Backupserver 16.0

Keywords

TLS_RSA_WITH_AES_128_GCM_SHA256, TLS_RSA_WITH_AES_256_GCM_SHA384, TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_RSA_WITH_AES128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES256_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES128_CBC_SHA, TLS_ECDHE_RSA_WITH_AES256_CBC_SHA384, TLS_ECDHE_RSA_WITH_AES256_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES256_GCM_SHA384, TLS_ECDHE_ECDSA_WITH_AES256_CBC_SHA384, TLS_ECDHE_ECDSA_WITH_AES128_CBC_SHA256
, KBA , BC-SYB-ASE , Sybase ASE Database Platform (non Business Suite) , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.