Return-Path: X-Original-To: apmail-jmeter-user-archive@www.apache.org Delivered-To: apmail-jmeter-user-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id AD1D717767 for ; Wed, 3 Jun 2015 10:14:20 +0000 (UTC) Received: (qmail 74565 invoked by uid 500); 3 Jun 2015 10:14:20 -0000 Delivered-To: apmail-jmeter-user-archive@jmeter.apache.org Received: (qmail 74526 invoked by uid 500); 3 Jun 2015 10:14:20 -0000 Mailing-List: contact user-help@jmeter.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "JMeter Users List" Delivered-To: mailing list user@jmeter.apache.org Received: (qmail 74515 invoked by uid 99); 3 Jun 2015 10:14:20 -0000 Received: from Unknown (HELO spamd2-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 03 Jun 2015 10:14:20 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd2-us-west.apache.org (ASF Mail Server at spamd2-us-west.apache.org) with ESMTP id B88981A4438 for ; Wed, 3 Jun 2015 10:14:19 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd2-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: 3.401 X-Spam-Level: *** X-Spam-Status: No, score=3.401 tagged_above=-999 required=6.31 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=3, URIBL_BLOCKED=0.001] autolearn=disabled Authentication-Results: spamd2-us-west.apache.org (amavisd-new); dkim=pass (2048-bit key) header.d=yahoo.de Received: from mx1-us-east.apache.org ([10.40.0.8]) by localhost (spamd2-us-west.apache.org [10.40.0.9]) (amavisd-new, port 10024) with ESMTP id dG-59DnnQYbj for ; Wed, 3 Jun 2015 10:14:08 +0000 (UTC) Received: from nm41-vm1.bullet.mail.gq1.yahoo.com (nm41-vm1.bullet.mail.gq1.yahoo.com [67.195.87.88]) by mx1-us-east.apache.org (ASF Mail Server at mx1-us-east.apache.org) with ESMTPS id C884E43AC7 for ; Wed, 3 Jun 2015 10:14:07 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.de; s=s2048; t=1433326441; bh=e3ilnGzrdy0gR8xEGMYQ3Z0hW+Ay8qRdsQiTRwDtHTs=; h=Date:From:Reply-To:To:In-Reply-To:References:Subject:From:Subject; b=TZ5DfkSR4Rjw5dupMyvI8r8luso/sYTr/ixvqrGzDk2lfHKC8GfPiZ77G3X0nG2Ckfe/Sb5ML73257WxllvMt4HpWW735ugapyPifMaJGTTRVpRSpKL7kYFIyWod+Ic+mSjjjzFkqmT/de8jfR69nmQ0DhGmeZ1tnxmJ3x0eV+ImPmxO3XKtU3yrtSdXgwNPmHC1Q14AObCzfuuihG8+gfAuAPG7qRC2F9GDWr7Q65n9REYDImNqvi3FZMaLgW5AWCF2dKAZSXFGDCKyiMBaN8fJ4pclkVKP07fEt7jfbdmlU1jc8g0iJSmefWE2lKR3e43UIzFSqpYDip1AnNJPzg== Received: from [127.0.0.1] by nm41.bullet.mail.gq1.yahoo.com with NNFMP; 03 Jun 2015 10:14:01 -0000 Received: from [98.137.12.190] by nm41.bullet.mail.gq1.yahoo.com with NNFMP; 03 Jun 2015 10:11:12 -0000 Received: from [212.82.98.51] by tm11.bullet.mail.gq1.yahoo.com with NNFMP; 03 Jun 2015 10:11:12 -0000 Received: from [212.82.98.89] by tm4.bullet.mail.ir2.yahoo.com with NNFMP; 03 Jun 2015 10:11:11 -0000 Received: from [127.0.0.1] by omp1026.mail.ir2.yahoo.com with NNFMP; 03 Jun 2015 10:11:11 -0000 X-Yahoo-Newman-Property: ymail-4 X-Yahoo-Newman-Id: 896498.68788.bm@omp1026.mail.ir2.yahoo.com X-YMail-OSG: JZLxhmcVRDvCnDTIVzc4vdqLz5KZczkG7KLwxloUrBt6fbItdg-- Received: by 212.82.98.117; Wed, 03 Jun 2015 10:11:11 +0000 Date: Wed, 3 Jun 2015 10:11:10 +0000 (UTC) From: George Reply-To: George To: JMeter Users List Message-ID: <1120964482.6456020.1433326270636.JavaMail.yahoo@mail.yahoo.com> In-Reply-To: <556C177A.8060103@internetallee.de> References: <556C177A.8060103@internetallee.de> Subject: Re: JMeter SMTP Sampler with (SSL/TLS) and TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_Part_6456018_582859949.1433326270622" ------=_Part_6456018_582859949.1433326270622 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Hello, yes my server can do tls 1.2 perfectly and also with the above (strong) cip= her.I did some more tests where i modify step by step my server configurati= on until it works and here are my results. Test 1:My server allows ONLY tls 1.2 and ONLY the cipher ECDHE_ECDSA_WITH_A= ES_256_GCM_SHA384 Test 2:My server allows ONLY tls 1.2 and ANY cipher Test 3:My server allows tls 1.2 and tls 1.1 and ANY cipher Test 4:My server allows tls 1.2 and tls 1.1 and tls 1.0 and ANY cipher My jmeter.properties is set to do tls1.2 only - but the SSL configuration i= s only for the http protocol and not for smtp(s).Thus i think this does not= care.I have java jre 1.8 latest plus the oracle security "Unlimited Streng= th Java Cryptography Extension Policy Files" pakage. My jmeter test plan is very easy.=20 One thread one smtp sampler and one "view results in tree".The SMTP Sampler= target my mail server on port "465" and the checkbox "use ssl" is enabled = and the hook "Trust all certificates" is enabled too.There is one Subject: = hello and Email body: hello. Simple Results:Test 1: Fail - no ssl handshakeTest 2: Fail - no ssl handshakeTest = 3: Fail - no ssl handshakeTest 4: Success: Perfectly SSL Handshake. SSL Con= nection established using "TLSv1 ECDHE-ECDSA-AES256-SHA" (no client certifi= cate checkup <- means no mutual ssl) OK thus it works.I can sent an email with jmeter SMTP sampler using (direct= ) ssl on port 465 - but it only works if i activate tls1.0.=20 I do not found any jmeter configuration about "smtps". I did some further tests wirh thunderbird 31.4 (on a linux).Here the result= s.Test 1: Fails - no ssl connectionTest 2, 3 and 4: Success. Looking on the thunderbird settings its strange but the cipher i want to us= e is not available. Thus i can do tls1.2 but not with my "strong" cipher. Br.George =20 Felix Schumacher schrieb am 10:29 = Montag, 1.Juni 2015: =20 Am 29.05.2015 um 13:16 schrieb George: > Hello, > i try to sent a "hello" email using SMTP Sampler and want to use SSL/TLS = on standard port 465 for this connection.More i want to use TLSv1.2 with th= e very strong cipher "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384"Currently the= handshake fail. > Technially if i change the configuration on my server to also accept TLSv= 1.1 and v1.0 then the SSL connection works and the email is sent perfectly.= I see in the logs that the client (jmeter) and my server aggreed on a ciphe= r comming from TLS1.0.Thus in general SSL is working but not with TLSv1.2. > Anyone any idea how i can use SMTP(s) with TLSv1.2 and the above cipher?I= tried to put this in my jmeter.sh file but seems it does not matter? > JMETER_OPTS=3D"-Dhttps.cipherSuites=3DTLS_ECDHE_ECDSA_WITH_AES_256_GCM_SH= A384" The smtp sampler has no option to specify the wanted ciphersuites, so=20 the option given above will not be used. > I also installed lates java jdk and i also installed the additional stron= g security pakage and replaced the .jar files in /usr/java/jre.../lib/secur= ity Which jdk did you install exactly? Have you checked (with openssl or something similar), that your=20 mailserver is capable of TLSv1.2? Regards =C2=A0 Felix > BrGeorge > > --------------------------------------------------------------------- To unsubscribe, e-mail: user-unsubscribe@jmeter.apache.org For additional commands, e-mail: user-help@jmeter.apache.org ------=_Part_6456018_582859949.1433326270622--