Subject: SSL_connect returned=1 errno=0 state=error: dh key too small

Marcelo Lauxen marcelolauxen16 at
Thu Aug 29 17:14:18 UTC 2019

Thank you guys for the answers!

I've another question, based on your suggestion Salz Rich, this
config @SECLEVEL can be set per host/domain, or is it impossible?

On Thu, Aug 29, 2019 at 12:38 PM Salz, Rich <rsalz at> wrote:

>    - We haven't control of the server who are using DH key size of 1048
>    bits.
> In order to work with this kind of server (terribly poor security
> characteristics), you need to add “@SECLEVEL=0” to your OpenSSL
> configuration.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>

More information about the openssl-users mailing list