Description of problem: I am not able to connect to e.g. rc4.badssl.com even if I set LEGACY profile in crypto-policies. Version-Release number of selected component (if applicable): # rpm -q gnutls crypto-policies gnutls-3.5.10-1.fc26.x86_64 crypto-policies-20170214-2.gitf3018dd.fc26.noarch How reproducible: always Steps to Reproduce: 1. update-crypto-policies --set LEGACY 2. gnutls-cli --priority @SYSTEM rc4.badssl.com Actual results: Setting system policy to LEGACY Processed 172 CA certificate(s). Resolving 'rc4.badssl.com:443'... Connecting to '104.154.89.105:443'... *** Fatal error: A TLS fatal alert has been received. *** Received alert [40]: Handshake failed *** handshake has failed: A TLS fatal alert has been received. Expected results: Connection succeeds.
Thank you. I've pushed a fix in rawhide/f26. https://gitlab.com/nmav/fedora-crypto-policies/commit/55b66da0575cf59265f09ebbe89adc7cf0e90ded