• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

Openssl problem

ErwanG

Regular Pleskian
Hello,

We have a problem with the last release of "openssl": some emails are not delivery.
Log message: SSL_routines:SSL3_CHECK_CERT_AND_ALGORITHM:dh_key_too_small;_connected_toX.X.X.X

1) We have updated distrib: #yum update
2) After this, we have: Openssl 1.0.1e-42.el6 (CentOS release 6.6)
Plesk12 on the server.

We have the problem with the 10 servers we have updated.
All of them with Plesk 12.

How can we resolve that?
 
It seems that the problem is servers (not ours, but mail to) vulnerable to Logjam TLS vulnerability.
I search a solution for Qmail...
 
Last edited:
Generating DH parameters, 2048 bit long safe prime, generator 2
This is going to take a long time


..............................+...

Since 20 minutes.... is it normal?
 
We have now in the log:
sslv3_alert_handshake_failure;_connected_toX.X.X.X

Mails stays in the queue...
 
Back
Top