# Sudden increase in handshake duration

**URL:** <https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010>\
**Category:** Server\
**Created:** [February 24, 2019, 1:07pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010 "2019-02-24T13:07:41Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![dave.higgins](https://avatars.discourse-cdn.com/v4/letter/d/b38774/32.png) [@dave.higgins](https://community.letsencrypt.org/u/dave.higgins)\
**Post date:** [February 24, 2019, 1:07pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/1 "2019-02-24T13:07:41Z")

</div>

I am a bit at a loss right now.

I’ve had a setup for quite some time now where I have configured an LE wildcard certificate in a custom Java application. So far, so good. That worked great for about the past six months until about yesterday or two days ago (cant pinpoint it precisely I am afraid), when the establishing of the TLS connection suddenly started to take “ages”, about 15 seconds. This appears to affect exclusively browsers (Firefox and Chrome) and there was no apparent change or upgrade to either configuration (neither browsers nor server side nor the certificate). From my perspective it started out of the blue.

One thing I noticed during my debug attempts so far is that I hadnt configured the intermediate certificate but only sent the actual site certificate. Adding the former one hasnt changed anything however.

Assuming, for the time being, that it is not a local issue my immediate thought would have been that there might be some problem with the live revocation check, however that does not seem to be the case.

As I said, I am a bit at a loss right now, would anybody have a possible explanation why that might suddenly start without any apparent local changes?

Thank you!

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [February 24, 2019, 1:37pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/2 "2019-02-24T13:37:23Z")

</div>

Hi @dave.higgins

> [@dave.higgins](#):
>
> That worked great for about the past six months until about yesterday or two days ago (cant pinpoint it precisely I am afraid), when the establishing of the TLS connection suddenly started to take “ages”, about 15 seconds. This appears to affect exclusively browsers (Firefox and Chrome) and there was no apparent change or upgrade to either configuration (neither browsers nor server side nor the certificate).

to check that, we need your domain name.

---

<div class="post-metadata">

**Author:** ![dave.higgins](https://avatars.discourse-cdn.com/v4/letter/d/b38774/32.png) [@dave.higgins](https://community.letsencrypt.org/u/dave.higgins)\
**Post date:** [February 24, 2019, 1:48pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/3 "2019-02-24T13:48:40Z")

</div>

I am afraid the machine is on a closed network.

I was merely wondering what could be a possible reason for that behaviour. Typically my first guess would have been a delay certificate revocation check, but that does not seem to be the case here. Could there be anything else?

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [February 24, 2019, 2:04pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/4 "2019-02-24T14:04:39Z")

</div>

> [@dave.higgins](#):
>
> what could be a possible reason for that behaviour

There are thousand reasons possible that a connection is slow. So it's mindless to speculate.

PS: There is a list of Third-party-tools to check a domain:

> [@Third-party-Tools to check your configuration](https://community.letsencrypt.org/t/third-party-tools-to-check-your-configuration/76272):
>
> I…

But that requires incoming connections.

A closed network to debug from outside - that's not really possible.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 24, 2019, 2:12pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/5 "2019-02-24T14:12:16Z")

</div>

> [@dave.higgins](#):
>
> would anybody have a possible explanation why that might suddenly start without any apparent local changes?

No explanation, but have you considered debugging with Wireshark?

---

<div class="post-metadata">

**Author:** ![dave.higgins](https://avatars.discourse-cdn.com/v4/letter/d/b38774/32.png) [@dave.higgins](https://community.letsencrypt.org/u/dave.higgins)\
**Post date:** [February 24, 2019, 2:17pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/6 "2019-02-24T14:17:53Z")

</div>

> [@JuergenAuer](#):
>
> There are thousand reasons possible that a connection is slow. So it’s mindless to speculate.

The connection itself is okay, it specifically is the handshake.

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/4/f/4fd97398a7c3525239cc99db46518b99c8b7f2df.png)

> [@JuergenAuer](#):
>
> But that requires incoming connections.
> 
> A closed network to debug from outside - that’s not really possible.

I am aware of that 😐

> [@Osiris](#):
>
> No explanation, but have you considered debugging with Wireshark?

I was hoping to be able to avoid that 😄, but I guess I will have to go that route.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 24, 2019, 2:29pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/7 "2019-02-24T14:29:08Z")

</div>

> [@dave.higgins](#):
>
> I was hoping to be able to avoid that 😄, but I guess I will have to go that route.

There's nothing more fun than tracking and debugging the packages of a network connection! 😃

---

<div class="post-metadata">

**Author:** ![orangepizza](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/orangepizza/32/19597_2.png) [@orangepizza](https://community.letsencrypt.org/u/orangepizza)\
**Post date:** [February 24, 2019, 2:38pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/8 "2019-02-24T14:38:02Z")

</div>

Maybe you can try change it with some self signed cert so it’s letsencrypt problem

---

<div class="post-metadata">

**Author:** ![dave.higgins](https://avatars.discourse-cdn.com/v4/letter/d/b38774/32.png) [@dave.higgins](https://community.letsencrypt.org/u/dave.higgins)\
**Post date:** [February 24, 2019, 4:53pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/9 "2019-02-24T16:53:15Z")

</div>

This was actually an excellent idea. Same issue with a self-signed certificate, so I can definitely rule out LE. Thanks @orangepizza

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [February 24, 2019, 8:21pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/10 "2019-02-24T20:21:22Z")

</div>

> [@dave.higgins](#):
>
> would anybody have a possible explanation why that might suddenly start without any apparent local changes

Sudden MTU changes somewhere along the network path (sometimes in combination with certain types of network filtering) can look like this.

Lowering MTU to something like 1300 is a decent way to exclude it.

---

<div class="post-metadata">

**Author:** ![dave.higgins](https://avatars.discourse-cdn.com/v4/letter/d/b38774/32.png) [@dave.higgins](https://community.letsencrypt.org/u/dave.higgins)\
**Post date:** [February 25, 2019, 3:14pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/11 "2019-02-25T15:14:04Z")

</div>

That would have been a lovely idea, unfortunately it does not seem to fix it either.

Reduced it to 1300, 1000, 800, and 500 and the issue remained.

Well, out of LE’s scope 🙂

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [February 25, 2019, 5:28pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/12 "2019-02-25T17:28:54Z")

</div>

Possibly the software at your end is doing some kind of lookup in connection with each incoming connection before allowing the connection to complete (for example, a reverse DNS lookup).

---

<div class="post-metadata">

**Author:** ![dave.higgins](https://avatars.discourse-cdn.com/v4/letter/d/b38774/32.png) [@dave.higgins](https://community.letsencrypt.org/u/dave.higgins)\
**Post date:** [February 26, 2019, 8:07pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/13 "2019-02-26T20:07:58Z")

</div>

You appear to have hit the nail on the head.

I am actually a bit embarrassed and disappointed I havent thought of that earlier, as I had a similar issue years ago but in this case I completely ignored that possibility. It seems to be the exact issue as the one at [https://coderanch.com/t/656284/java/HttpsServer-SSL-extremely-slow-times](https://coderanch.com/t/656284/java/HttpsServer-SSL-extremely-slow-times)

Now I just need to find out how to convince Java to refrain from the lookup 🙂

Thanks a million @schoen

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 28, 2019, 8:08pm UTC](https://community.letsencrypt.org/t/sudden-increase-in-handshake-duration/87010/14 "2019-03-28T20:08:00Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
