X
Thinta lapha ukuze uye kuveshini yamakhalekhukhwini kusayithi.

Isithangami Sabeseki

Lolu chungechunge lwabekwa kunqolobane. Uyacelwa ubuze umbuzo omusha uma udinga usizo.

My site will work in all other browers but firefox.

Kuphostiwe

https://www.aibonline.org/en/

You can open this link in chrome, IE and safari but not firefox. Firefox can't seem to find our security certificate but all the other bowers can. Is there something we're missing?

https://www.aibonline.org/en/ You can open this link in chrome, IE and safari but not firefox. Firefox can't seem to find our security certificate but all the other bowers can. Is there something we're missing?
FredMcD
  • Top 10 Contributor
4255 izisombululo 59592 izimpendulo
Kuphostiwe

Firefox: The connection to the server was reset while the page was loading.

Win IE: No problem.

I called for more help. As a test. Disable your protection programs.

Firefox: The connection to the server was reset while the page was loading. Win IE: No problem. I called for more help. As a test. Disable your protection programs.
philipp
  • Top 25 Contributor
  • Moderator
5315 izisombululo 23464 izimpendulo
Kuphostiwe

there seem to be no overlapping cipher suites between what your server offers and current firefox builds support.

according to www.howsmyssl.com you can speak to firefox with one of the following cipher suites:

  • TLS_AES_128_GCM_SHA256
  • TLS_CHACHA20_POLY1305_SHA256
  • TLS_AES_256_GCM_SHA384
  • TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
  • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
  • TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256
  • TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
  • TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
  • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
  • TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
  • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
  • TLS_RSA_WITH_AES_128_CBC_SHA
  • TLS_RSA_WITH_AES_256_CBC_SHA
  • TLS_RSA_WITH_3DES_EDE_CBC_SHA
there seem to be no overlapping cipher suites between what your server offers and current firefox builds support. according to www.howsmyssl.com you can speak to firefox with one of the following cipher suites: * TLS_AES_128_GCM_SHA256 * TLS_CHACHA20_POLY1305_SHA256 * TLS_AES_256_GCM_SHA384 * TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 * TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 * TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 * TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 * TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 * TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 * TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA * TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA * TLS_RSA_WITH_AES_128_CBC_SHA * TLS_RSA_WITH_AES_256_CBC_SHA * TLS_RSA_WITH_3DES_EDE_CBC_SHA

Umnikazi wombuzo

@philipp So are we missing the correct cipher suite to work with firefox? If we update it so we have one of those listed cipher suites it should work?

@philipp So are we missing the correct cipher suite to work with firefox? If we update it so we have one of those listed cipher suites it should work?
philipp
  • Top 25 Contributor
  • Moderator
5315 izisombululo 23464 izimpendulo
Kuphostiwe

yes, that's my understanding :-)

yes, that's my understanding :-)

Umnikazi wombuzo

We have these suites installed. Are they not showing up?

We have these suites installed. Are they not showing up?

Okulungisiwe ngu Amy9

Shadow110 1072 izisombululo 14836 izimpendulo
Kuphostiwe

Hi, no certificate being shown yet,

Hi, no certificate being shown yet,
jscher2000
  • Top 10 Contributor
8758 izisombululo 71665 izimpendulo
Kuphostiwe

This test page only shows a handful enabled:

TLS 1.2 (suites in server-preferred order) TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 TLS_RSA_WITH_AES_256_GCM_SHA384 (0x9d) TLS_RSA_WITH_AES_128_GCM_SHA256 (0x9c) TLS_RSA_WITH_AES_256_CBC_SHA256 (0x3d) TLS_RSA_WITH_AES_128_CBC_SHA256 (0x3c)

https://www.ssllabs.com/ssltest/analyze.html?d=www.aibonline.org

I don't know why that is so different from your screenshot.

This test page only shows a handful enabled: '''TLS 1.2 (suites in server-preferred order) ''' TLS_ECDHE_RSA_WITH_AES_256_'''CBC'''_SHA384 TLS_ECDHE_RSA_WITH_AES_128_'''CBC'''_SHA256 TLS_RSA_WITH_AES_256_GCM_SHA384 (0x9d) TLS_RSA_WITH_AES_128_GCM_SHA256 (0x9c) TLS_RSA_WITH_AES_256_CBC_SHA256 (0x3d) TLS_RSA_WITH_AES_128_CBC_SHA256 (0x3c) https://www.ssllabs.com/ssltest/analyze.html?d=www.aibonline.org I don't know why that is so different from your screenshot.