Error code: SSL_ERROR_NO_CYPHER_OVERLAP Topic is solved

Users and developers helping users with generic and technical Pale Moon issues on all operating systems.

Moderator: trava90

Forum rules
This board is for technical/general usage questions and troubleshooting for the Pale Moon browser only.
Technical issues and questions not related to the Pale Moon browser should be posted in other boards!
Please keep off-topic and general discussion out of this board, thank you!
f-117
Moonbather
Moonbather
Posts: 72
Joined: 2017-02-04, 20:41

Error code: SSL_ERROR_NO_CYPHER_OVERLAP

Unread post by f-117 » 2019-03-28, 14:51

I am trying to access the NJDMV site to renew my registration. I keep getting this error (https://emvc.state.nj.us/mvc/emvc_vehrr.shtml)

I have read the FAQ topic on this (viewtopic.php?f=24&t=6262). I have been trying to make the suggested changes to Cypher's 1/2, as mentioned in the FAQ, but nothing works.

I have tried to contact them but got no answer.

I get this error in both PM 28.4.1 and the latest Basilisk.

I understand that the error may be on their end, but is there anything I can do in PM Commander?

Thanks for your help.

Scott

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35575
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Error code: SSL_ERROR_NO_CYPHER_OVERLAP

Unread post by Moonchild » 2019-03-28, 15:10

The site only supports 3DES and RC4 ciphers. Both of those are marked weak and need specific overrides as outlined in the FAQ.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

f-117
Moonbather
Moonbather
Posts: 72
Joined: 2017-02-04, 20:41

Re: Error code: SSL_ERROR_NO_CYPHER_OVERLAP

Unread post by f-117 » 2019-03-28, 15:27

Ok, I got it to work in PM by adding the url to "security.tls.insecure_fallback_hosts". That seems to work, but this change does not work in Basilisk.

Still trying...

Scott

f-117
Moonbather
Moonbather
Posts: 72
Joined: 2017-02-04, 20:41

Re: Error code: SSL_ERROR_NO_CYPHER_OVERLAP

Unread post by f-117 » 2019-03-28, 15:34

Ok, I think it works in Basilisk now.

I changed the value in "security.ssl3.rsa_rc4_128_md5" to true. It seems to work now.

Scott

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35575
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Error code: SSL_ERROR_NO_CYPHER_OVERLAP

Unread post by Moonchild » 2019-03-28, 15:53

Please contact them and let them know their server needs to be looked at.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

New Tobin Paradigm

Re: Error code: SSL_ERROR_NO_CYPHER_OVERLAP

Unread post by New Tobin Paradigm » 2019-03-28, 15:55

Enabling insecure cyphers is NOT "working now". Please do as instructed above.

User avatar
gepus
Keeps coming back
Keeps coming back
Posts: 941
Joined: 2017-12-14, 12:59

Re: Error code: SSL_ERROR_NO_CYPHER_OVERLAP

Unread post by gepus » 2019-03-29, 10:58

New Tobin Paradigm wrote:Enabling insecure cyphers is NOT "working now". Please do as instructed above.
Your goal is to protect the user and at the same time to enforce protection.
Most probable effect - the user will open such sites with another browser.

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35575
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Error code: SSL_ERROR_NO_CYPHER_OVERLAP

Unread post by Moonchild » 2019-03-29, 12:14

gepus wrote:
New Tobin Paradigm wrote:Enabling insecure cyphers is NOT "working now". Please do as instructed above.
Your goal is to protect the user and at the same time to enforce protection.
Most probable effect - the user will open such sites with another browser.
I'll do you a favor and remove all safety rails from bridges so you can fall off. After all, it's your choice to kill yourself. Right?

But in all seriousness: enabling known insecure ciphers to access any website should be a temporary exception only. If you prefer to throw all caution to the wind and you don't care that you think your connection is secure while it is not, then indeed, your choice should be clear: stop using Pale Moon. Its balanced and common-sense security profile clearly doesn't match what you expect from a web browser and you should instead choose one that will connect to sites at all costs, throwing your security and privacy to the wind.

So, make a choice, gepus: either switch browser (and get out of our hair) or stop trying to accuse our community of enforcing something that is in the user's best interest.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
gepus
Keeps coming back
Keeps coming back
Posts: 941
Joined: 2017-12-14, 12:59

Re: Error code: SSL_ERROR_NO_CYPHER_OVERLAP

Unread post by gepus » 2019-03-29, 13:13

Moonchild wrote:I'll do you a favor and remove all safety rails from bridges so you can fall off. After all, it's your choice to kill yourself. Right?
I didn't ask you for any favor. You might reread my post.
Moonchild wrote: But in all seriousness: enabling known insecure ciphers to access any website should be a temporary exception only.
There is no visible option for a temporary exception in the above case.

Don't get me wrong, I couldn't care less. My remark was considered to be a hint (accusation???) regarding the consequences.
Moonchild wrote: So, make a choice, gepus: either switch browser (and get out of our hair) or stop trying to accuse our community of enforcing something that is in the user's best interest.
Don't worry, there won't be any other hints in future so you can keep your hair clean. :)

rmbowie

Re: Error code: SSL_ERROR_NO_CYPHER_OVERLAP

Unread post by rmbowie » 2019-04-18, 17:27

There are cases when you need to use unsafe ciphers and unsafe plugins(java) that have nothing to do accessing a public website..

For example I'm able to get into an HP ILO3 session on an older server with Firefox but not with Pale Moon even if I use Pale Moon Commander to drop all ciphers down to exactly the same as the firefox connection (TLS1.1 RSA_WITH_3DES_EDE_CBC_SHA).

Of course with current firefox versions I hit the no java wall unless I install an old ESR version.

It would be nice to have some sort of expert toggle, or exception by IP/FQHN, on pale moon so that I can stop dragging around a Windows 7 VM.

Just a feature request for what could be an awesome web browser for sys admins..

Randy

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35575
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Error code: SSL_ERROR_NO_CYPHER_OVERLAP

Unread post by Moonchild » 2019-04-18, 17:48

If you read the instructions in the relevant FAQ carefully, you will see that this is exactly the way Pale Moon works: 3DES is considered a weak cypher and will need an entry in the "fallback hosts" preference to allow it to be used.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

Locked