Subject: SSL_connect returned=1 errno=0 state=error: dh key too small

Marcelo Lauxen marcelolauxen16 at gmail.com
Thu Aug 29 17:14:18 UTC 2019


Thank you guys for the answers!

I've another question, based on your suggestion Salz Rich, this
config @SECLEVEL can be set per host/domain, or is it impossible?

On Thu, Aug 29, 2019 at 12:38 PM Salz, Rich <rsalz at akamai.com> wrote:

>
>    - We haven't control of the server who are using DH key size of 1048
>    bits.
>
> In order to work with this kind of server (terribly poor security
> characteristics), you need to add “@SECLEVEL=0” to your OpenSSL
> configuration.
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.openssl.org/pipermail/openssl-users/attachments/20190829/fc1cb084/attachment.html>


More information about the openssl-users mailing list