"SSL client handshake completion failure" on IOS 26.x
search cancel

"SSL client handshake completion failure" on IOS 26.x

book

Article ID: 420488

calendar_today

Updated On:

Products

SSP-S410 PLATFORM

Issue/Introduction

With the IOS 26.x upgrade, access to some sites failed with "SSL client handshake completion failure" error. One of the sites was "example.com".

Issue is seen only on iphones. All other (Windows, MacOS or Android) are unaffected.

Environment

SGOS 7.3.18.3 and older

Cause

IOS 26.x update includes support for X25519MLKEM768. Native support for X25519MLKEM768 was introduced in 7.4.13.1.

In SGOS versions 7.3.18.3 and older tunneled connections with kyber/mlkem keyexchange with no ECH extension throw a cert validation failure and fails the connection. This was fixed in 7.3.18.4

Resolution

Upgrade SGOS to 7.3.18.4, but it is recommended upgrading to 7.4.13.1 at least