09-08-2015 02:40 PM - edited 03-01-2019 06:22 AM
We were recently blessed with the latest chrome update which rendered the UCSD inaccessible to our chrome users due to the following error - Server has a weak ephemeral Diffie-Hellman public key. We were able to resolve the issue by updating the ciphers that are currently utilized by tomcat.
09-09-2015 06:48 AM
This worked perfect, thanks! One small edit, though, it is server.xml that needs to be edited and not servers.xml.
09-09-2015 12:12 PM
I've also been told that upgrading to, I believe, 5.3 should resolve the issue. I know I did something similar to this on 5.2.0.1, but upgrading my test environment to 5.3.1.2 from 5.2.0.1 seemed to correct this as well.
09-09-2015 12:52 PM
I'm currently running 5.3.0.1 and was having the issue. I also ran this by cisco and they said a fix would be coming in 5.3.2.0.
09-09-2015 12:54 PM
Good to know. After all the changes I did to the environment, I just figured the upgrade fixed it. I was also told by a Cisco contact that it should have been fixed already. So much for that.
09-17-2015 09:44 AM
There is a bug fixed for this in the just released 5.3.2.0 version: CSCuv34350: UCSD failed on Cipher Suite checking with Firefox v39.
So anyone just facing this issue, two options:
1. Fix server.xml as described above (workaround)
2. Update to 5.3.2.0 (official bugfix)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide