Firefox: Error code: ssl_error_weak_server_ephemeral_dh_key

Print

firefox-logoStarting with Firefox v39 you will receive the following errors when accessing secure websites with a weak ephemeral Diffie-Hellman key:

An error occurred during a connection to helios.alt-itc.ca:8443. SSL received a weak ephemeral Diffie-Hellman key in Server Key Exchange handshake message. (Error code: ssl_error_weak_server_ephemeral_dh_key)

How to resolve this:

1) Ask the webmaster to correct this on the server side (if you have such an option).

2) Perform the following:

i) In the address field of Firefox, type in: 

about:config

ii) Click "I'll be careful, I promise"

iii) Find the following keys (type this into the search field):

security.ssl3.dhe_rsa_aes_128_sha

Click on "true" under "Value" to make it "false"

Find the next key:

security.ssl3.dhe_rsa_aes_256_sha

Click on "true" under "Value" to make it "false"

close the window and you're done. You should be able to refresh the page that was not connecting. No need to restart Firefox.

 

Office
Comments (11)
Thank you
11 Tuesday, 14 November 2017 15:01
Trev
This should be fixed server side by using better keys, but is helpful for debugging older software!
SSL_ERROR_WEAK_SERVER_EPHEMERAL_DH_KEY
10 Wednesday, 18 October 2017 02:43
Bhupathi
Issue resolved
Thank you so much
9 Wednesday, 11 October 2017 15:59
Quy
You are the best
Issue solved
8 Thursday, 24 August 2017 00:58
Jack
Thank you so much
Firefox-Error code: SSL_ERROR_WEAK_SERVER_EPHEMERAL_DH_KEY
7 Thursday, 08 June 2017 05:31
Sreekumar
It works, very nice. Thank you!
SSL
6 Tuesday, 09 May 2017 16:12
james
it works. thank you,
I had a similar issue
5 Wednesday, 29 March 2017 05:25
Jimnix
Thank you
SSL
4 Thursday, 23 March 2017 06:34
Faouzi
Merci pour votre aide
error in the web site
3 Monday, 06 March 2017 00:15
hh580mandakolathur paccs
SSL_ERROR_WEAK_SERVER_EPHEMERAL_DH_KEY
Thanks
2 Thursday, 29 October 2015 14:53
kat
Thank you it worked!
dd
1 Wednesday, 30 September 2015 01:40
mohammed
dnslkdns
yvComment v.1.24.0