"bad record mac" with SSL connecting to Cloudflare on Arch Linux

Viewed 774

I have a simple Erlang program trying to perform an HTTPS GET. However, it fails with "bad record mac" whenever ApiUrl points to a domain proxied by cloudflare.

#!/usr/bin/env escript
main([]) -> 
    inets:start(), 
    ssl:start(),
    ApiUrl = "https://remexre.xyz/",
    io:format("ApiUrl = ~p~n", [ApiUrl]),
    Request = {ApiUrl, []},
    SslOpts = [{verify, verify_none}],
    Opts = [{body_format, binary}],
    {ok, {{_, 200, _}, _, Body}} = httpc:request(get, Request, [{ssl, SslOpts}], Opts),
    io:format("~p~n", [Body]).

It does, however, work with non-Cloudflare HTTPS domains, including example.com and this site.

I inspected the tls stream with Wireshark, and it appears that the remote (so cloudflare) is sending the "bad record mac" to the client.

EDIT: This occurs on Arch Linux (multiple machines), but not on a friend's Ubuntu machine.

EDIT 2: Here's the wireshark dump.

EDIT 3: I'm on: Erlang/OTP 20 [erts-9.0.1] [source] [64-bit] [smp:4:4] [ds:4:4:10] [async-threads:10] [hipe] [kernel-poll:false], which is from version 20.0.1-2 of the erlang package in Arch.

0 Answers
Related