Discussions related to using object storage as a backup target.
Post Reply
fabian.papenfuss
Service Provider
Posts: 3
Liked: 1 time
Joined: Oct 22, 2024 7:03 am
Full Name: Fabian Papenfuss
Contact:

HTTP exception: SSL Error: WINHTTP_CALLBACK_STATUS_FLAG_SECURITY_CHANNEL_ERROR internal error., error code: 0

Post by fabian.papenfuss »

Veeam Case #07533884

Hello everyone,

I currently have the problem on a VBR server that it is not possible to create an S3 bucket.
When selecting the folder, the error message “The bucket could not be found” always appears.

And the error message always appears in the log:

Code: Select all

[17.12.2024 08:06:09.837] < 16768> aws | WARN|HTTP request failed, retry in [1] seconds, attempt number [2], total retry timeout left: [13] seconds
[17.12.2024 08:06:09.837] < 16768> aws | >> |SSL Error: WINHTTP_CALLBACK_STATUS_FLAG_SECURITY_CHANNEL_ERROR internal error.
For your information, the functionality of the bucket is definitely given.
The bucket can be integrated on other VBR servers without any problems, but the firewall and antivirus software is also enabled / disabled before the affected VBR server where the error message appears.

Unfortunately there is no solution in the support case yet...
Have any of you ever had this error and can possibly contribute a solution here?

I look forward to your answers

Thank you and best regards!
--
Fabian Papenfuß
sfirmes
Veeam Software
Posts: 321
Liked: 150 times
Joined: Jul 24, 2018 8:38 pm
Full Name: Stephen Firmes
Contact:

Re: HTTP exception: SSL Error: WINHTTP_CALLBACK_STATUS_FLAG_SECURITY_CHANNEL_ERROR internal error., error code: 0

Post by sfirmes »

Fabian,

Are you using cloud object storage or on-premises object storage?
Steve Firmes | Senior Solutions Architect, Product Management - Alliances @ Veeam Software
david.domask
Veeam Software
Posts: 2651
Liked: 614 times
Joined: Jun 28, 2016 12:12 pm
Contact:

Re: HTTP exception: SSL Error: WINHTTP_CALLBACK_STATUS_FLAG_SECURITY_CHANNEL_ERROR internal error., error code: 0

Post by david.domask »

Hi Fabian, welcome to the forums, and sorry to hear about the challenges.

Thank you for sharing your case number, and please continue with Support on this issue; I understand a bit of research and work into anti-virus and firewall has been done and yielded no positive results, so Support will continue their investigation.

> WINHTTP_CALLBACK_STATUS_FLAG_SECURITY_CHANNEL_ERROR

https://learn.microsoft.com/en-us/windo ... ck#remarks

In the table here, it points to an application SSL issue -- any chance you're seeing SChannel events in the System/Application log from the Veeam server itself? Is TLS 1.2 perhaps disabled and the S3 provider doesn't yet support TLS 1.3?
David Domask | Product Management: Principal Analyst
fabian.papenfuss
Service Provider
Posts: 3
Liked: 1 time
Joined: Oct 22, 2024 7:03 am
Full Name: Fabian Papenfuss
Contact:

Re: HTTP exception: SSL Error: WINHTTP_CALLBACK_STATUS_FLAG_SECURITY_CHANNEL_ERROR internal error., error code: 0

Post by fabian.papenfuss »

Hello Steve and David,

thank you very much for your feedback!

@Steve:
We use an “on-premise” NetApp Strorage Grid as object storage.

@David
The issue is a bit strange, my understanding is that TLS 1.2 should actually be enabled, but I am following up with support and have sent them some more information such as a network recording etc.

Best regards
--
Fabian Papenfuß
fabian.papenfuss
Service Provider
Posts: 3
Liked: 1 time
Joined: Oct 22, 2024 7:03 am
Full Name: Fabian Papenfuss
Contact:

Re: HTTP exception: SSL Error: WINHTTP_CALLBACK_STATUS_FLAG_SECURITY_CHANNEL_ERROR internal error., error code: 0

Post by fabian.papenfuss » 1 person likes this post

Hello everyone,

I would like to report back on the case and its solution, I have already shared the findings with the support team.

Through another troubleshooting session, we were able to find the error ourselves.

About the error description:
Basically, this was apparently caused by a former domain membership or the GPOs associated with it.

The following registry key was provided with the GPOs:
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\Configuration\SSL\00010002]
“Functions“=”TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P521,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P521, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P384,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P521,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA_P521,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA_P384,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA_P256, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384_P521,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384_P384,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256_P521,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256_P384, TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256_P256,TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384_P521,TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384_P384,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256_P521, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256_P384,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256_P256,TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA_P521,TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA_P384, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA_P256,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA_P521,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA_P384,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA_P256, TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA”

By removing this registry key and then restarting the system, the error message disappeared and the connection establishment via the VBR server as S3 gateway works perfectly.

Best regards
--
Fabian Papenfuß
david.domask
Veeam Software
Posts: 2651
Liked: 614 times
Joined: Jun 28, 2016 12:12 pm
Contact:

Re: HTTP exception: SSL Error: WINHTTP_CALLBACK_STATUS_FLAG_SECURITY_CHANNEL_ERROR internal error., error code: 0

Post by david.domask » 1 person likes this post

Hi Fabian,

Glad to hear that you were able to find the root cause, and thank you very much for sharing it. So it was an SSL issue, but not about TLS version just about ciphers.

Appreciate you sharing the resolution!
David Domask | Product Management: Principal Analyst
Post Reply

Who is online

Users browsing this forum: No registered users and 13 guests