4 ms·
I don't know about you people but I can't access this site in latest firefox: Secure Connection Failed An error occurred during a connection to po
by diaz 13y ago
I don't know about you people but I can't access this site in latest firefox:
Secure Connection Failed
An error occurred during a connection to pond.imperialviolet.org.
Peer attempted old style (potentially vulnerable) handshake.
(Error code: ssl_error_unsafe_negotiation)
The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.
Please contact the website owners to inform them of this problem. Alternatively, use the command found in the help menu to report this broken site.
- agwa 13y agoThis is kind of ironic considering it's Adam Langley's website, but it appears his server is not indicating that it supports secure renegotiation, and apparently in the latest Firefox that's grounds to refuse a connection[1]. See: https://www.ssllabs.com/ssltest/analyze.html?d=pond.imperialviolet.org https://www.ssllabs.com/ssltest/analyze.html?d=pond.imperial... https://wiki.mozilla.org/Security:Renegotiation https://wiki.mozilla.org/Security:Renegotiation https://community.qualys.com/blogs/securitylabs/2010/10/06/disabling-ssl-renegotiation-is-a-crutch-not-a-fix https://community.qualys.com/blogs/securitylabs/2010/10/06/d... If you set security.ssl.require_safe_negotiation to false in about:config you should be able to establish a connection. [1] Edit: actually it's not; the parent poster had tweaked settings in about:config ;-)
- diaz 13y agoIt seems to be that. I had initializaed a new profile in firefox and played with some options in about:config and somehow the option security.ssl.require_safe_negotiation was set to true. All this week this was the first website to fail because of that. It works with it set to false.
- agl 13y agoGood to know. I knew that I needed to do it, but I'll be sure to add support for this prior to Go 1.2. (The TLS stack doesn't support renegotiation at all, so it's not vulnerable, but a client can't know that unless it echos the extension in question.)
- agwa 13y agoAh, you're using the Go TLS package? That makes sense ;-). As it turns out the latest version of Firefox still connects to servers which don't indicate secure renegotiation; the parent poster caused the problem by mucking around with the TLS settings in about:config.
- nitrogen 13y agoWell, it looks like he wrote the Go TLS package.
- conformal 13y agoiirc renegotiation in openssl is mad broken, in which case, mad props to adam :)