[BUG] DOCA-OFED 3.4.0 Repository SSL Handshake Failure on Debian 13 (Trixie)
Environment
- OS: Debian 13 (trixie)
- DOCA version: 3.4.0
- Architecture: x86_64
- Container: yes (Docker)
- Working baseline: Debian 12 with identical steps succeeds
Issue
Following the official DOCA-OFED installation guide, apt-get update fails to fetch the Release file from the Mellanox repository with an OpenSSL EOF error. The package is then unavailable for install.
Steps to Reproduce
- Add the DOCA repository as documented:
echo 'deb [signed-by=/etc/apt/trusted.gpg.d/nvidia-doca-debian-gpg-public-key.gpg] https://linux.mellanox.com/public/repo/doca/3.4.0/debian13/x86_64/ ./' \
> /etc/apt/sources.list.d/doca.list
- Run
apt-get update - Run
apt-get install doca-ofed
Error Output
Ign:4 https://linux.mellanox.com/public/repo/doca/3.4.0/debian13/x86_64 ./ InRelease
Get:5 https://linux.mellanox.com/public/repo/doca/3.4.0/debian13/x86_64 ./ Release [1347 B]
Err:5 https://linux.mellanox.com/public/repo/doca/3.4.0/debian13/x86_64 ./ Release
OpenSSL error: error:0A000126:SSL routines::unexpected eof while reading [IP: 168.62.212.37 443]
E: The repository '... ./ Release' does not have a Release file.
E: Unable to locate package doca-ofed
Troubleshooting Already Attempted
- Reinstalled
ca-certificates(20250419) — error persists - The SSL EOF error (
0A000126) occurs during the TLS handshake, suggesting the Mellanox server may be dropping connections from clients using Debian 13’s OpenSSL 3.x with its stricter TLS defaults
Root Cause Hypothesis
Debian 13 ships with a newer OpenSSL (3.x) that enforces stricter TLS negotiation. The linux.mellanox.com repository server appears to close the connection mid-handshake, which is consistent with a server-side TLS configuration that does not support the cipher suites or protocol versions preferred by Debian 13’s OpenSSL.
The same steps work without issue on Debian 12, which uses an older OpenSSL with more permissive defaults.
Questions
- Is DOCA 3.4.0 officially supported on Debian 13 / trixie, or is the
debian13repo path still in early access? - Is there a known TLS compatibility issue with the repository server and OpenSSL 3.x?
- Is there a recommended workaround (e.g., a different mirror, a local repo mirror, or a TLS config override) while this is investigated?
Thank you.