Issue
After upgrading MaxScale, client connections fail with SSL negotiation errors. The MaxScale logs contain the following error messages:
OpenSSL ssl error. error:0A000102:SSL routines::unsupported protocolClient failed SSL negotiation.
Environment
MariaDB MaxScale 25.10.3
Cause
In recent versions of MaxScale, the default ssl_version is set to MAX, which enforces a strict minimum of TLSv1.2. If older clients attempt to connect using deprecated protocols like TLSv1.0 or TLSv1.1, the connection will fail. Additionally, modern operating systems may block insecure TLS versions at the system level.
Resolution
Warning: Enabling legacy TLS versions exposes the environment to known cryptographic vulnerabilities. This should only be used as a temporary workaround until clients can be upgraded to support TLSv1.2 or higher.
- Open the MaxScale configuration file.
- Locate the listener configuration block.
- Modify or add the
ssl_versionparameter to explicitly allow older TLS versions. For example:
ssl_version=TLSv1.0,TLSv1.1,TLSv1.2,TLSv1.3 - If running on an operating system with strict cryptographic policies, enable legacy crypto policies by running the following command:
update-crypto-policies --set LEGACY - Restart the MaxScale service to apply the changes:
systemctl restart maxscale
Metadata
- State: In Progress
- Visibility: Customer
- Version verified: MariaDB MaxScale 25.10.3
- Category: Configuration
- Keywords: OpenSSL ssl error, error:0A000102, unsupported protocol, failed SSL negotiation, TLSv1.0, TLSv1.1
- Source: 243127