SSL raises version error only on re-connect attempt?

Viewed 26

We have a server and client both running python3.

The client connects to the server and authenticates upon initialisation of the client. This completes without issue.

However, if the connection drops, the client catches the error (the socket.recv returning 0) and attempts to re-run the code that connects to the server).

The server recieves the initial request whilst listening on its given recieving socket and then once making a connection the next recv call raises the following error:

 File "/usr/lib64/python3.7/ssl.py", line 1056, in recv
    return self.read(buflen)
  File "/usr/lib64/python3.7/ssl.py", line 931, in read
    return self._sslobj.read(len)
ssl.SSLError: [SSL: TLSV1_ALERT_PROTOCOL_VERSION] tlsv1 alert protocol version (_ssl.c:2570)

Why would this succeed upon the first connection but then raise this error thereafter? If the client is closed and restarted the error is avoided upon the next connection. However, if the server is closed and the client tries to connect once the server restarts this error is encountered.

At the client end the following error is raised:

  File "\Our_Code", line 100, in make_connection
    data = self.ssl_sock.recv(1024)
  File "C:\Users\Home\AppData\Local\Programs\Python\Python39\lib\ssl.py", line 1226, in recv226, in recv
    return self.read(buflen)                                                    101, in read
  File "C:\Users\Home\AppData\Local\Programs\Python\Python39\lib\ssl.py", line 1101, in read
    return self._sslobj.read(len)
ssl.SSLError: [SSL] internal error (_ssl.c:2633)

This exact formultation suggests to me that the issue is actually with the client and some data that it is saving between reconnects. But it overwrites the sockets for a new connection so I thought all data from the previous connection would be discarded?

The connection function is as:

import socket
import ssl

    def make_connection(self, email, password):
        try:
            self.ssl_sock = []
    
            HOST = "9:9:99:999"  # The server's hostname or IP address (not our actual IP)
            PORT = 5432  # The port used by the server (not our actual port)
    
            sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
            sock.connect((HOST, PORT))
            self.ssl_sock = self.context.wrap_socket(sock)
    
            password = password.encode('utf-8').strip()
            password = base64.b64encode(password).decode("utf-8")
    
            tcp_string = (f"^{email}*{password}$")
    
            tcp_string = tcp_string.encode('utf-8')
            self.ssl_sock.sendall(tcp_string)
    
            data = self.ssl_sock.recv(1024)
            data = data.decode('utf-8')
    
            if data == "^good_connect$":
                return True
            else:
                return False
        except Exception:
            print(f"make_connection - {traceback.format_exc()}")

I'm still fairly new to python and particularly networking, so I suspect I have made a rookie error. But so far all my searches have returned the obvious, that the TLS version is wrong, but the fact that it authenticates fine on the initial connection suggests to me that that isn't the case.

I'm happy to answer any questions I can about the situation.

0 Answers
Related