mIRC Home    About    Download    Register    News    Help

Print Thread
Unable to connect to server (SSL wrong version num #268493 22/02/21 11:06 PM
Joined: Feb 2003
Posts: 2,759
Raccoon Offline OP
Hoopy frood
OP Offline
Hoopy frood
Joined: Feb 2003
Posts: 2,759
Been over a year of receiving this error message. It affects half of EFNet servers. I have no means of debugging it at my disposal.

* Unable to connect to server (SSL wrong version number)


Well. At least I won lunch.
Good philosophy, see good in bad, I like!
Re: Unable to connect to server (SSL wrong version num [Re: Raccoon] #268497 23/02/21 03:23 PM
Joined: Dec 2002
Posts: 4,934
Khaled Offline
Hoopy frood
Offline
Hoopy frood
Joined: Dec 2002
Posts: 4,934
See here.

Re: Unable to connect to server (SSL wrong version num [Re: Khaled] #268499 23/02/21 07:26 PM
Joined: Aug 2003
Posts: 294
P
Protopia Offline
Fjord artisan
Offline
Fjord artisan
P
Joined: Aug 2003
Posts: 294
I guess if you follow the chain of links, you will see that it might be possible to re-enable the cipher type that EFnet is using and make it work. If you want to connect to EFnet anyway, given that the alternative is a non-encrypted connection, it can be argued that any encryption (however compromised) is better than an unencrypted link.

You will need to investigate the ciphers present in the EFnet certificate to know what cipher type(s) to enable.

Re: Unable to connect to server (SSL wrong version num [Re: Protopia] #268500 23/02/21 08:50 PM
Joined: Feb 2003
Posts: 2,759
Raccoon Offline OP
Hoopy frood
OP Offline
Hoopy frood
Joined: Feb 2003
Posts: 2,759
If only I could see some sort of debug messaging to understand why this is sometimes and not all the time. Why doesn't mIRC at least tell me the SSL cipher the server is demanding I use, or is capable of using, or that I attempted to use but failed.


Well. At least I won lunch.
Good philosophy, see good in bad, I like!
Re: Unable to connect to server (SSL wrong version num [Re: Raccoon] #268502 26/02/21 09:49 AM
Joined: Dec 2002
Posts: 4,934
Khaled Offline
Hoopy frood
Offline
Hoopy frood
Joined: Dec 2002
Posts: 4,934
Quote
If only I could see some sort of debug messaging to understand why this is sometimes and not all the time.

Very likely because you are using the round-robin server address. This means that you are cycling through different servers on the EFnet network, some of which are using out-of-date ciphers and protocols.

Quote
Why doesn't mIRC at least tell me the SSL cipher the server is demanding I use, or is capable of using, or that I attempted to use but failed.

The server chooses from the cipher list that the client presents. If the server can't find anything it likes, it returns an error. The only way to know what the server supports is for the client to build a list of ciphers it supports internally and to connect to the server using each one individually to see which are accepted or rejected.

mIRC's set of allowable ciphers and protocols is set at such a low level, to allow connections to old IRC servers that have not been updated in years, that if the server you are trying to connect to is not accepting them, you may as well not be using SSL.

That is the reason why mIRC's server list does not include SSL servers for EFNet.

mIRC should really be using a stricter default cipher list. As I mentioned here, the cipher list was last updated in 2014.

It is on my to-do list to review the default cipher list, as well as the servers list, to determine which networks are acceptable for use with SSL.