cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
54584
Views
25
Helpful
23
Replies

Server has a weak ephemeral Diffie-Hellman public key ERR_SSL_WEAK_SERVER_EPHEMERAL_DH_KEY

karinn001
Level 1
Level 1

Hi,

 

I have Cisco Prime and i am getting the following error when i am going to login. I have used IE,Chrome, Firefox but have the same condition.Kindly let me the solution.

 

Server has a weak ephemeral Diffie-Hellman public key

ERR_SSL_WEAK_SERVER_EPHEMERAL_DH_KEY
1 Accepted Solution

Accepted Solutions

Create a new shortcut and use the link provided to run the program.  Make sure Chrome is in the right location of the folder.

View solution in original post

23 Replies 23

Leo Laohoo
Hall of Fame
Hall of Fame

This is due to Bug ID CSCuj42438 & CSCuv21820.  

 

IE works.  There are workarounds to use Firefox & Chrome.  

Hi all,

can anyone point to the workaround for Chrome?

For Mozilla I have found this:

on the url type:

about:config


Here in this config page, you will find a list of boolean entries. Search for below two entries,
 

security.ssl3.dhe_rsa_aes_128_sha

security.ssl3.dhe_rsa_aes_256_sha 


By default, these are set to TRUE. But you have to set them to FALSE in order to allow the less secured pages.

For Chrome, use this shortcut: 

 

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --cipher-suite-blacklist=0x0088,0x0087,0x0039,0x0038,0x0044,0x0045,0x0066,0x0032,0x0033,0x0016,0x0013

Hi Leo,

 

i have run above command but result has not change. Still getting the same message. 

Create a new shortcut and use the link provided to run the program.  Make sure Chrome is in the right location of the folder.

Issue resolved. Thanks Leo

Thanks for taking the time to rate our posts.  :)

Hi Leo,

 

Is there a risk for the browser's security if we create thos shortcut ?

 

AL

Maybe I'm just really missing something, but when I try to create a new shortcut with the following path it says it can't find C:\Program application. 

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --cipher-suite-blacklist=0x0088,0x0087,0x0039,0x0038,0x0044,0x0045,0x0066,0x0032,0x0033,0x0016,0x0013

However, if I just enter C:\Program Files (x86)\Google\Chrome\Application\chrome.exe the shortcut will work fine. So I definitely have the correct path to the chrome app. What am I missing? 

To make it work you need to put quotes around the file path and name. So put a " in front of C: and replace the " right after the .exe with another double quote character.

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --cipher-suite-blacklist=0x0088,0x0087,0x0039,0x0038,0x0044,0x0045,0x0066,0x0032,0x0033,0x0016,0x0013

Ah, thanks kconrad01 that worked! 

So.. im still getting the error after adding the cipher suites blacklist..

Here is a straight paste of my target destination.

 

"C:\Program Files\Google\Chrome\Application\chrome.exe" --cipher-suite-blacklist=0x0088,0x0087,0x0039,0x0038,0x0044,0x0045,0x0066,0x0032,0x0033,0x0016,0x0013

 

It open's Chrome but when i visit Cisco Prime still get the lovely error... any thoughts?

Had the same issue when I created the shortcut.  Make sure that after you've created the shortcut, go to task manager and ensure all chrome.exe processes are terminated.

As soon as I terminated all the running chrome processes, the next time I used the modified shortcut the pages loaded fine.  (Accessing UCCX Admin Pages)

Works great for me.

Thanks

Review Cisco Networking for a $25 gift card