Skip to content
DataMiner DoJo

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Search in posts
Search in pages
Log in
Menu
  • Blog
  • Questions
  • Learning
    • E-learning Courses
    • Open Classroom Training
    • Certification
      • DataMiner Fundamentals
      • DataMiner Configurator
      • DataMiner Automation
      • Scripts & Connectors Developer: HTTP Basics
      • Scripts & Connectors Developer: SNMP Basics
      • Visual Overview – Level 1
      • Verify a certificate
    • Tutorials
    • Video Library
    • Books We Like
    • >> Go to DataMiner Docs
  • Expert Center
    • Solutions & Use Cases
      • Solutions
      • Use Case Library
    • Markets & Industries
      • Media production
      • Government & defense
      • Content distribution
      • Service providers
      • Partners
      • OSS/BSS
    • DataMiner Insights
      • Security
      • Integration Studio
      • System Architecture
      • DataMiner Releases & Updates
      • DataMiner Apps
    • Agile
      • Agile Webspace
      • Everything Agile
        • The Agile Manifesto
        • Best Practices
        • Retro Recipes
      • Methodologies
        • The Scrum Framework
        • Kanban
        • Extreme Programming
      • Roles
        • The Product Owner
        • The Agile Coach
        • The Quality & UX Coach (QX)
    • DataMiner DevOps Professional Program
  • Downloads
  • More
    • Feature Suggestions
    • Climb the leaderboard!
    • Swag Shop
    • Contact
      • General Inquiries
      • DataMiner DevOps Support
      • Commercial Requests
    • Global Feedback Survey
  • PARTNERS
    • All Partners
    • Technology Partners
    • Strategic Partner Program
    • Deal Registration
  • >> Go to dataminer.services

SSL/TLS Handshake failed for MySQL queries

Solved1.59K views5th July 2023MySQL ssl SSL-TLS
3
Matthias Neirinck [SLC] [DevOps Enabler]76 17th May 2023 1 Comment

Hi,
We are encountering a "The handshake failed due to an unexpected packet format." error on a customer DMA which seems to be caused by an SSL/TLS issue.

Their setup consists of a master server that is used in production and slave server that replicates the master server for testing. The element is using the Generic Database driver and is connecting to their MySQL database. Connections from the MySQL workbench and client to both the master and slave server are working fine. The DMA element is able to run queries on the slave server but the "handshake failed" issue occurs on the master server. The master and slave both support TLSv1.2 and older versions. A workaround is to explicitly disable SSL by setting "SSL Mode=None" in the connection string. Then queries are able to execute on the master server but this does not solve the root problem.

When connecting from the MySQL client, the following cipher is used:
Master server: DHE-RSA-AES128-GCM-SHA256
Slave server: ECDHE-RSA-AES128-GCM-SHA256

The slave server has the following SSL connection when polled from inside the DMA element:
SSL cipher: ECDHE-RSA-AES256-SHA
TLS version: TLSv1.1

The driver is using SLDatabase.dll which is using MySql.Data version 6.9.12.0 and that is part of MySQL Connector/NET.
Page https://dev.mysql.com/doc/connector-net/en/connector-net-versions.html mentions that
"Secure connections using the TLSv1.2 protocol require Connector/NET 8.0.11 or later."

Could it be that the master configuration of the customer somehow forces the DMA to use TLSv1.2 and that this is not supported by the MySQL Connector?

Marieke Goethals [SLC] [DevOps Catalyst] Selected answer as best 5th July 2023
Seppe Dejonckheere [SLC] [DevOps Advocate] commented 17th May 2023

Hi,
Do you happen to have access to wireshark traces? This can be usefull to see why the handshake fails. Please feel free to contact me directly to follow up on this.

kr,

1 Answer

  • Active
  • Voted
  • Newest
  • Oldest
1
Seppe Dejonckheere [SLC] [DevOps Advocate]2.21K Posted 17th May 2023 0 Comments

After investigating wireshark traces, it looks like the Master server does not support TLSv1.1 or any of the ciphers the client (DMA) supports because the Master server immediately sends a TCP reset message after receiving the Client Hello message.

Marieke Goethals [SLC] [DevOps Catalyst] Selected answer as best 5th July 2023
You are viewing 1 out of 1 answers, click here to view all answers.
Please login to be able to comment or post an answer.

My DevOps rank

DevOps Members get more insights on their profile page.

My user earnings

0 Dojo credits

Spend your credits in our swag shop.

0 Reputation points

Boost your reputation, climb the leaderboard.

Promo banner DataMiner DevOps Professiona Program
DataMiner Integration Studio (DIS)
Empower Katas

Recent questions

How to implement bearer token refresh? 0 Answers | 0 Votes
Web Applications exception in Cube due to invalid certificate 0 Answers | 0 Votes
Redundancy Groups and Alarming – Duplicate Alarms 0 Answers | 0 Votes

Question Tags

adl2099 (115) alarm (62) Alarm Console (82) alarms (100) alarm template (83) Automation (223) automation scipt (111) Automation script (167) backup (71) Cassandra (180) Connector (109) Correlation (69) Correlation rule (52) Cube (151) Dashboard (194) Dashboards (188) database (83) DataMiner Cube (57) DIS (81) DMS (71) DOM (140) driver (65) DVE (56) Elastic (83) Elasticsearch (115) elements (80) Failover (104) GQI (159) HTTP (76) IDP (74) LCA (152) low code app (166) low code apps (93) lowcodeapps (75) MySQL (53) protocol (203) QAction (83) security (88) SNMP (86) SRM (337) table (54) trending (87) upgrade (62) Visio (539) Visual Overview (345)
Privacy Policy • Terms & Conditions • Contact

© 2025 Skyline Communications. All rights reserved.

DOJO Q&A widget

Can't find what you need?

? Explore the Q&A DataMiner Docs

[ Placeholder content for popup link ] WordPress Download Manager - Best Download Management Plugin