<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[TLS 1.3 certificate authentication fails with &quot;post-handshake&quot; error.]]></title><description><![CDATA[<p dir="auto">TLS 1.3 "cannot perform post-handshake authentication" when using client certificate authentication.</p>
<p dir="auto">opera-stable-101.0.4843.58-0.x86_64  on Fedora 36</p>
<p dir="auto">Web page served on Apache httpd-2.4.37-56<br />
OpenSSL 1.1.1k<br />
on AlmaLinux 8.7<br />
(I'm running this node, so can change the config to test TLS v1.3 functionality)</p>
<p dir="auto">Works fine doing client certificate authentication with Apache config line:<br />
SSLProtocol  -all +TLSv1.2<br />
but error shows up with<br />
SSLProtocol  -all +TLSv1.2 +TLSv1.3<br />
Firefox seems to have a "config setting" to allow post-handshake authentication that<br />
prevents this problem, but if Opera has such a flag, it' <em>very</em> well hidden.</p>
<p dir="auto">It's only a matter of time before TLSv1.2 becomes insecure, so having the full suite of capabilities on TLSv1.3 is essential.</p>
]]></description><link>https://forums.opera.com/topic/65808/tls-1-3-certificate-authentication-fails-with-post-handshake-error</link><generator>RSS for Node</generator><lastBuildDate>Mon, 10 Aug 2026 09:09:11 GMT</lastBuildDate><atom:link href="https://forums.opera.com/topic/65808.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 30 Aug 2023 12:33:35 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to TLS 1.3 certificate authentication fails with &quot;post-handshake&quot; error. on Thu, 31 Aug 2023 22:54:24 GMT]]></title><description><![CDATA[<p dir="auto">@fonm<br />
your suggestion doesn't fix the "post-handshake" error with TLS 1.3, and in addition causes many other websites (including This one!) to fail, because they are not running TLS 1.3.</p>
]]></description><link>https://forums.opera.com/post/324996</link><guid isPermaLink="true">https://forums.opera.com/post/324996</guid><dc:creator><![CDATA[celane23]]></dc:creator><pubDate>Thu, 31 Aug 2023 22:54:24 GMT</pubDate></item><item><title><![CDATA[Reply to TLS 1.3 certificate authentication fails with &quot;post-handshake&quot; error. on Thu, 31 Aug 2023 08:32:39 GMT]]></title><description><![CDATA[<p dir="auto">@fonm said in <a href="/post/324925">TLS 1.3 certificate authentication fails with "post-handshake" error.</a>:</p>
<blockquote>
<p dir="auto">opera-stable --tls1.3 --ssl-version-min 1.3</p>
</blockquote>
<pre><code>opera-stable --tls1.3 --ssl-version-min="tls1.3"
</code></pre>
]]></description><link>https://forums.opera.com/post/324956</link><guid isPermaLink="true">https://forums.opera.com/post/324956</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Thu, 31 Aug 2023 08:32:39 GMT</pubDate></item><item><title><![CDATA[Reply to TLS 1.3 certificate authentication fails with &quot;post-handshake&quot; error. on Thu, 31 Aug 2023 05:41:17 GMT]]></title><description><![CDATA[<p dir="auto">opera-stable --tls1.3 --ssl-version-min 1.3</p>
]]></description><link>https://forums.opera.com/post/324925</link><guid isPermaLink="true">https://forums.opera.com/post/324925</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Thu, 31 Aug 2023 05:41:17 GMT</pubDate></item></channel></rss>