• Debian 11 has reached its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.81 is the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Openssl problem

ErwanG

Regular Pleskian
Hello,

We have a problem with the last release of "openssl": some emails are not delivery.
Log message: SSL_routines:SSL3_CHECK_CERT_AND_ALGORITHM:dh_key_too_small;_connected_toX.X.X.X

1) We have updated distrib: #yum update
2) After this, we have: Openssl 1.0.1e-42.el6 (CentOS release 6.6)
Plesk12 on the server.

We have the problem with the 10 servers we have updated.
All of them with Plesk 12.

How can we resolve that?
 
It seems that the problem is servers (not ours, but mail to) vulnerable to Logjam TLS vulnerability.
I search a solution for Qmail...
 
Last edited:
Generating DH parameters, 2048 bit long safe prime, generator 2
This is going to take a long time


..............................+...

Since 20 minutes.... is it normal?
 
We have now in the log:
sslv3_alert_handshake_failure;_connected_toX.X.X.X

Mails stays in the queue...
 
Back
Top