Add mirror.stinner-it.com in Graz, Austria - #1386
Open
stinnerIT wants to merge 1 commit into
Open
Conversation
Member
|
Hello, It looks like there is a SSL/TLS issue on the mirror, can you take a look? > openssl s_client -connect mirror.stinner-it.com:443 2026-07-29 12:26:02
Connecting to 91.112.149.206
CONNECTED(00000005)
401F14F301000000:error:0A000438:SSL routines:ssl3_read_bytes:tlsv1 alert internal error:ssl/record/rec_layer_s3.c:918:SSL alert number 80
---
no peer certificate available
---
No client certificate CA names sent
Negotiated TLS1.3 group: <NULL>
---
SSL handshake has read 7 bytes and written 1552 bytes
Verification: OK
---
New, (NONE), Cipher is (NONE)
Protocol: TLSv1.3
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)
---
401F14F301000000:error:0A000197:SSL routines:SSL_shutdown:shutdown while in init:ssl/ssl_lib.c:2804:Also, I missed this portion on the mailing list, but the connectivity is on the lower end of what we'd like to list. Is there any way you can bump the port speed? We like to have our users experience the best speeds in their geographical location, and anything that's <100Mbps can quickly become problematic. Thanks for your interest and contribution :) |
Author
|
Hello Cody,
thank you for the feedback.
The SSL/TLS issue has now been resolved. It was caused by overlapping port 443 forwarding rules on the firewall. The conflicting rules have been removed, and the mirror now presents the correct Let’s Encrypt certificate and responds successfully over HTTP/2.
Regarding connectivity, I would like to clarify that the current connection is 80 Mbps downstream and 20 Mbps upstream. Since mirror downloads use our upstream capacity, I understand that the currently available effective mirror bandwidth is well below your preferred threshold.
We are currently working with our ISP to have the site included in their next network expansion, which is expected within approximately two to three months. We are targeting an upgraded connection and are specifically clarifying the available upstream capacity, as we understand that at least 100 Mbps upstream is required for the mirror.
We are also implementing QoS on the firewall to prioritize public mirror traffic during congestion. I understand that this improves availability on the current connection but does not replace the required bandwidth upgrade.
Please feel free to retest the TLS connection. I will provide an update once the upgraded upstream capacity has been confirmed.
Thanks again,
Thomas
Mit freundlichen Grüßen/With best regards,
Thomas STINNER [cid:logo_stinner-it_designelemente-1_1ab056e0-aff7-4a3d-91ef-951ef2eb1539.png]
Geschäftsführender Inhaber
Stinner IT-Solutions e.U.
Wegenergasse 1,
8010 Graz
Österreich
t: +43 316375033100<https://editor-eu.codetwo.com/>
m: +43 69917098772<https://editor-eu.codetwo.com/>
f: +43 316375033150
e: ***@***.***<mailto:%7BE-mail%7D>
[cid:f59c4a40-c160-4349-9e9a-d975805b99d2.png]
www.stinner-it.com<https://stinner-it.com/>
The security of your data is one of our greatest concerns. That is why we put extra effort into ensuring your data is always safe and up to date. Contact ***@***.***> if you want to access or change your personal information or if you want us to remove it completely from our database. If you do not wish to receive more emails from us, click here<https://stinner-it.us4.list-manage.com/unsubscribe?u=9ae720ffa4a26df77b0a1217c&id=fcb28e028e&e=[UNIQID]&c=82de05feff>.
Von: Cody Robertson ***@***.***>
Gesendet: Mittwoch, 29. Juli 2026 18:31
An: AlmaLinux/mirrors ***@***.***>
Cc: Thomas Stinner ***@***.***>; Author ***@***.***>
Betreff: Re: [AlmaLinux/mirrors] Add mirror.stinner-it.com in Graz, Austria (PR #1386)
[cid:~WRD0003.jpg]codyro left a comment (AlmaLinux/mirrors#1386)<#1386 (comment)>
Hello,
It looks like there is a SSL/TLS issue on the mirror, can you take a look?
openssl s_client -connect mirror.stinner-it.com:443 2026-07-29 12:26:02
Connecting to 91.112.149.206
CONNECTED(00000005)
401F14F301000000:error:0A000438:SSL routines:ssl3_read_bytes:tlsv1 alert internal error:ssl/record/rec_layer_s3.c:918:SSL alert number 80
---
no peer certificate available
---
No client certificate CA names sent
Negotiated TLS1.3 group: <NULL>
---
SSL handshake has read 7 bytes and written 1552 bytes
Verification: OK
---
New, (NONE), Cipher is (NONE)
Protocol: TLSv1.3
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)
---
401F14F301000000:error:0A000197:SSL routines:SSL_shutdown:shutdown while in init:ssl/ssl_lib.c:2804:
curl https://mirror.stinner-it.com/almalinux 2026-07-29 12:26:52
curl: (35) LibreSSL/3.3.6: error:1404B438:SSL routines:ST_CONNECT:tlsv1 alert internal error
Also, I missed this portion on the mailing list, but the connectivity is on the lower end of what we'd like to list. Is there any way you can bump the port speed? We like to have our users experience the best speeds in their geographical location, and anything that's <100Mbps can quickly become problematic.
Thanks for your interest and contribution :)
—
Reply to this email directly, view it on GitHub<#1386?email_source=notifications&email_token=BUFTRHEZMQMMU5HTKSLKUDL5HIRCVA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTKMJSGA3DMOJXGM32M4TFMFZW63VGMF2XI2DPOKSWK5TFNZ2KYZTPN52GK4S7MNWGSY3L#issuecomment-5120669737>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/BUFTRHDLCQOQNF3XBU5RQKT5HIRCVAVCNFSNUABFKJSXA33TNF2G64TZHMZTGNZRGY4DSMRZHNEXG43VMU5TKMBRGEYTSMRXGI3KC5QC>.
You are receiving this because you authored the thread.Message ID: ***@***.***>
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add the public AlmaLinux mirror operated by Stinner IT-Solutions e.U. in Graz, Austria.
Mirror URL:
The mirror synchronizes every 3 hours and currently provides AlmaLinux 8, 9 and 10.