[BUG] DOCA-OFED 3.4.0 Repository SSL Handshake Failure on Debian 13 (Trixie)

[BUG] DOCA-OFED 3.4.0 Repository SSL Handshake Failure on Debian 13 (Trixie)

Environment

  • OS: Debian 13 (trixie)
  • DOCA version: 3.4.0
  • Architecture: x86_64
  • Container: yes (Docker)
  • Working baseline: Debian 12 with identical steps succeeds

Issue
Following the official DOCA-OFED installation guide, apt-get update fails to fetch the Release file from the Mellanox repository with an OpenSSL EOF error. The package is then unavailable for install.

Steps to Reproduce

  1. Add the DOCA repository as documented:
echo 'deb [signed-by=/etc/apt/trusted.gpg.d/nvidia-doca-debian-gpg-public-key.gpg] https://linux.mellanox.com/public/repo/doca/3.4.0/debian13/x86_64/ ./' \
  > /etc/apt/sources.list.d/doca.list
  1. Run apt-get update
  2. Run apt-get install doca-ofed

Error Output

Ign:4 https://linux.mellanox.com/public/repo/doca/3.4.0/debian13/x86_64 ./ InRelease
Get:5 https://linux.mellanox.com/public/repo/doca/3.4.0/debian13/x86_64 ./ Release [1347 B]
Err:5 https://linux.mellanox.com/public/repo/doca/3.4.0/debian13/x86_64 ./ Release
  OpenSSL error: error:0A000126:SSL routines::unexpected eof while reading  [IP: 168.62.212.37 443]
E: The repository '... ./ Release' does not have a Release file.
E: Unable to locate package doca-ofed

Troubleshooting Already Attempted

  • Reinstalled ca-certificates (20250419) — error persists
  • The SSL EOF error (0A000126) occurs during the TLS handshake, suggesting the Mellanox server may be dropping connections from clients using Debian 13’s OpenSSL 3.x with its stricter TLS defaults

Root Cause Hypothesis
Debian 13 ships with a newer OpenSSL (3.x) that enforces stricter TLS negotiation. The linux.mellanox.com repository server appears to close the connection mid-handshake, which is consistent with a server-side TLS configuration that does not support the cipher suites or protocol versions preferred by Debian 13’s OpenSSL.

The same steps work without issue on Debian 12, which uses an older OpenSSL with more permissive defaults.

Questions

  1. Is DOCA 3.4.0 officially supported on Debian 13 / trixie, or is the debian13 repo path still in early access?
  2. Is there a known TLS compatibility issue with the repository server and OpenSSL 3.x?
  3. Is there a recommended workaround (e.g., a different mirror, a local repo mirror, or a TLS config override) while this is investigated?

Thank you.

Hi @pranavpadmasali ,

Thank you for posting your query on the NVIDIA Developer Community.

We appreciate the detailed report and the thorough troubleshooting steps already performed.

Before proceeding, we recommend confirming that your full software stack is within a supported configuration for DOCA 3.4.0. Please verify the following against the DOCA 3.4.0 General Support matrix:

  • OS and kernel version (Debian 13 with kernel 6.12.63 is supported for doca-ofed)

  • DOCA Host version (3.4.0)

  • NIC/DPU firmware version

  • Architecture (x86_64 / aarch64)

Regarding Your Reported Issue

This is a known TLS compatibility issue between the linux.mellanox.com repository server and the OpenSSL 3.x HTTPS transport used by apt on Debian 13.

The repository content and GPG signatures are valid; the failure is in the HTTPS transport layer only.

Recommended Workaround

Switch the repository URL from https:// to http:// in your /etc/apt/sources.list.d/doca.list file:

Then run:

apt-get update
apt-get install doca-ofed

Package integrity is maintained as GPG signature verification remains in place.

References

If you experience continued issues after following the guidance above, a valid support entitlement for the HCA/DPU in use will be needed to perform additional troubleshooting. If an active entitlement/support contract is in place, please do not hesitate to open a support ticket by logging into the ESP Portal and submitting a new case. For contracts, please reach out to Networking-Contracts@nvidia.com.

Thanks,
NVEX Networking Technical Support Team

Hi,
FYI: This also affects Ubuntu 26.04.
Is it possible to adjust the documentation for the affected distributions/versions?
See e.g. : NVIDIA DOCA 3.5.0 Downloads | NVIDIA Developer

Do you know if this is going to ‘fixed’ at one point, and if so you know this will be approximately?

Thanks,
Niels van der Waart

This is still a problem.
I suspect at least one of the servers in your web farm is mis-configured. Can someone please check it out?