Bug#792475: iceweasel: Error code: ssl_error_weak_server_ephemeral_dh_key

Daniel Kahn Gillmor dkg at fifthhorseman.net
Wed Aug 5 05:28:12 UTC 2015


On Wed 2015-07-15 03:08:54 -0400, Daniel Harrison wrote:

> I received this error while trying to connect to a server and the connection to
> the server failed. wget 1.16 seems to make the connection successfully, but not
> this package.

I'm assuming you mean this error from iceweasel:

  Error code: ssl_error_weak_server_ephemeral_dh_key

you don't mention which server you experienced this with.

This aborted connection is iceweasel protecting you from a TLS
connection that is insufficiently secure.  see https://weakdh.org/ for
more details.

If you can identify the server, we should inform the administrators that
they're not properly configured.

Perhaps this bug should be reassigned to wget, since wget is making an
ostensibly secure connection using weak handshake parameters?

           --dkg



More information about the pkg-mozilla-maintainers mailing list