CTX202036
2016-04-20
2005-06-06
Launching Command Center management website fails with error message - SSL received a weak ephemeral Diffie-Hellman key in Server Key Exchange ...

Symptoms or Error

Launching Command Center management website fails with the following error message on few??browsers (Firefox/Chrome):??SSL received a weak ephemeral Diffie-Hellman key in Server Key Exchange handshake message. (Error code: ssl_error_weak_server_ephemeral_dh_key)


Solution

Complete the following steps to configure/remove weak??ciphers:

  1. Stop the Citrix Command Center service.

  2. Back up the following files - "/apache/tomcat/conf/backup/server.xml" and "/conf/ transportProvider.conf".

  3. Edit the file server.xml and set only the required ciphers with comma separator in the line.
    For example: ciphers="SSL_RSA_WITH_3DES_EDE_CBC_SHA,SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA".

  4. Configure the same ciphers in transportProvider.conf where it is tagged with SSL_RSA_WITH_3DES_EDE_CBC_SHA,SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA.
    5. Start the Citrix Command Center service.

To remove these ciphers from a Command Center HA pair

  1. Stop the Command Center service on the secondary node and then stop the Command Center service on the primary node.
  2. Remove these ciphers from the following files on both the primary and secondary o????????<CC_Homel>/apache/tomcat/conf/backup/server.xml ??and o????<CC_Home>/conf/ transportProvider.conf
  3. Start the Command Center service on the primary node and the start the Command Center service on the secondary node.
Note: If the configured ciphers are not supported by the browser then Command Center client cannot be accessed.
??

Problem Cause

This issue is caused because of??weak ciphers. Now a days most of the browsers detect weak ciphers and donot allow SSL connections to go through.


Additional Resources

From Command Center version 5.2.44.11 builds the following are incorporated:

The following weak ciphers have now been removed from the cipher list:
TLS_DHE_RSA_WITH_AES_128_CBC_SHA and TLS_DHE_RSA_WITH_AES_256_CBC_SHA.

Command Center now supports the?? following strong ciphers:
TLS_RSA_WITH_AES_128_CBC_SHA,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_DHE_DSS_WITH_AES_128_CBC_SHA,TLS_DHE_DSS_WITH_AES_256_CBC_SHA,SSL_RSA_WITH_3DES_EDE_CBC_SHA,SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA,SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA,TLS_EMPTY_RENEGOTIATION_INFO_SCSV

More information:
http://docs.citrix.com/en-us/command-center/5-2/cc-faq-wrapper-50-con.html??

Applicable Products


 

Join the conversation

Citrix Discussions

Open a case

Citrix Support

特别说明


本文来源为Citrix.com所有,翻译后版权归翻译者所有.如需转载请注明出处.

文档版本


.

广告招租


最新留言


.

广告招租


.