Airline Pilot Central Forums

Airline Pilot Central Forums (https://www.airlinepilotforums.com/)
-   United (https://www.airlinepilotforums.com/united/)
-   -   Server has a weak ephemeral..." (https://www.airlinepilotforums.com/united/90406-server-has-weak-ephemeral.html)

steve0617 09-04-2015 01:03 PM

Server has a weak ephemeral..."
 
More often then not in the last few weeks, with Chrome or Firefox, when attempting to access anything Skynet/UAL related (CCS seems fine), I get this: 'Server has a weak ephemeral Diffie-Hellman public key.'

Neither browser will let me through. Says it's a 'disastrous misconfiguration' on the server (UAL) side and stops my login to protect myself.

Anybody else gotten that over the last few weeks?

F15andMD11 09-04-2015 02:54 PM

Funny, I was going to ask the same question today! Safari has been working.

steve0617 09-04-2015 03:01 PM


Originally Posted by Thor (Post 1964163)
Clear your browsing history/cache, if that doesn't work install this:

https://addons.mozilla.org/en-us/fir...n/disable-dhe/

Strangely, clearing cookies/clearing the cache is what started it (it first came up on my phone at the WORST possible time while in DIA trying to nonrev). IE/Win 10 Edge works fine. But Chrome and FF screw up now.

I'll try the FF extension. I have no idea where to email UAL's Skynet IT to let them know this continues to happen.

Cruz Clearance 09-05-2015 09:49 PM

Farabi connection error

full of luv 09-06-2015 09:35 AM


Originally Posted by Cruz Clearance (Post 1965043)
Farabi connection error

IT company with wings....

BMEP100 09-06-2015 09:43 AM


Originally Posted by steve0617 (Post 1964150)
More often then not in the last few weeks, with Chrome or Firefox, when attempting to access anything Skynet/UAL related (CCS seems fine), I get this: 'Server has a weak ephemeral Diffie-Hellman public key.'

Neither browser will let me through. Says it's a 'disastrous misconfiguration' on the server (UAL) side and stops my login to protect myself.

Anybody else gotten that over the last few weeks?

Do you know if you have updated your browsers, or are they set to auto update.

You may try uninstalling Firefox and downloading an earlier version.

Boulderian 09-06-2015 11:46 AM

Here is the quick fix for Firefox that does not require installing anything.

In address line in Firefox browser type: about:config
In the page that opens up, look for these two entries:

security.ssl3.dhe_rsa_aes_128_sha
security.ssl3.dhe_rsa_aes_256_sha

Toggle to FALSE for both

horrido27 09-06-2015 06:39 PM


Originally Posted by Boulderian (Post 1965386)
Here is the quick fix for Firefox that does not require installing anything.

In address line in Firefox browser type: about:config
In the page that opens up, look for these two entries:

security.ssl3.dhe_rsa_aes_128_sha
security.ssl3.dhe_rsa_aes_256_sha

Toggle to FALSE for both

Dude.. owe you a Bier! Thanks~ Works like a charm.

Always
Motch

UAL T38 Phlyer 09-06-2015 08:34 PM

I called ipad support out of desperation a month ago when my laptop wouldn't connect to Flying Together.

The gal who helped me was extremely helpful, had seen it before, knew exactly what to do, and walked me through what Bouldarian posted.

The week before I had called them for ipad support, and that guy was super helpful, too.

While much of the IT here is a train wreck, the support people for the ipad are awesome, and have knowledge beyond just the ipad.

bigfatdaddy 09-07-2015 07:12 AM


Originally Posted by UAL T38 Phlyer (Post 1965730)
I called ipad support out of desperation a month ago when my laptop wouldn't connect to Flying Together.

The gal who helped me was extremely helpful, had seen it before, knew exactly what to do, and walked me through what Bouldarian posted.

The week before I had called them for ipad support, and that guy was super helpful, too.

While much of the IT here is a train wreck, the support people for the ipad are awesome, and have knowledge beyond just the ipad.

Good to know!......thanks!

steve0617 09-07-2015 09:19 AM

Thanks for the help. I installed the FF plugin. That way, I could easily undo it since that plugin defeats the security stuff that both FF and Chrome have created specifically to protect the end users against badly configured servers. I see in the ALPA Scheduling Committee brief that UAL knows something is wrong. Hopefully it gets fixed shortly so this workaround isn't needed.

Thanks again!

krudawg 09-07-2015 12:40 PM


Originally Posted by steve0617 (Post 1965988)
Thanks for the help. I installed the FF plugin. That way, I could easily undo it since that plugin defeats the security stuff that both FF and Chrome have created specifically to protect the end users against badly configured servers. I see in the ALPA Scheduling Committee brief that UAL knows something is wrong. Hopefully it gets fixed shortly so this workaround isn't needed.

Thanks again!

The best way to put the company on notice is to have the MEC demand an extension to the bidding window another 10 days! They'll fix it quick.

rickair7777 09-07-2015 01:10 PM


Originally Posted by Boulderian (Post 1965386)
Here is the quick fix for Firefox that does not require installing anything.

In address line in Firefox browser type: about:config
In the page that opens up, look for these two entries:

security.ssl3.dhe_rsa_aes_128_sha
security.ssl3.dhe_rsa_aes_256_sha

Toggle to FALSE for both

Might consider resetting those to "true" when you're done on the UAL site.

UAL T38 Phlyer 09-07-2015 03:59 PM

Rick:

What are the repercussions if you don't?

Boulderian 09-08-2015 08:47 AM


Originally Posted by UAL T38 Phlyer (Post 1966187)
Rick:

What are the repercussions if you don't?

With it set to FALSE Firefox will still warn you that you are connecting to a dangerous or weak server (UAL) and ask if you wish to continue at your own risk. With it set to TRUE, it forbids you from connecting to such server - it makes the decision for you.

The danger of having it set to FALSE is that you could potentially try connecting to a phishing server unintentionally (a server pretending to be your bank and try to steal you login credentials), and even after being warned by Firefox, agree to continue putting your identity and computer at risk.

If you choose to have it set to FALSE just be sure that you never ignore the server security warning and only agree to continue if you are certain that you are connecting to your intended server (connecting via CCS link or such.)

I use Firefox only for company business (CCS & Skynet); Apple Safari with high security restrictions for all Banking; and Chrome for general goofing around the web - that way even if some malicious tracker sneaks by Chrome, it will remain isolated from my work or banking.


All times are GMT -8. The time now is 07:05 AM.


Website Copyright © 2026 MH Sub I, LLC dba Internet Brands