此站点需要基于DHE的SSL密码套件。这些已被弃用,将于2016年7月左右在M52中删除

时间:2016-09-15 10:34:18

标签: apache google-chrome ssl apache2

我在Chrome中发现了此错误(版本52.0.2743.82(64位)) "此站点需要基于DHE的SSL密码套件。这些已弃用,将于2016年7月左右在M52中删除"

https://s13.postimg.org/5stng8o4n/login.png

无法在Chrome Canary(54.0.2835.0)中加载该页面

这是错误(但不是网址)

https://s4.postimg.org/puwyrgfct/687474703a2f2f692e696d6775722e636f6d2f584c444c4c.png

我的Apache Web服务器版本为2.2.22,SSL conf通常用于那些网站,

 SSLEngine On

 SSLCertificateKeyFile /etc/ssl/mycerts/mycert.key
 SSLCertificateFile /etc/ssl/mycerts/mycert.crt
 SSLCACertificateFile /etc/ssl/mycerts/myca.crt
 SSLProtocol all -SSLv2 -SSLv3
 SSLHonorCipherOrder on
 SSLCipherSuite "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRSA+SHA384 EECDH+aRSA+SHA256 EECDH+aRSA EECDH EDH+aRSA !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS"

在Firefox,Safari或Opera中没有失败。以前在Chrome中都没有加入Canary更新。

有人能指出我正确的方向来解决Chrome Canary的SSL限制吗?

由于

1 个答案:

答案 0 :(得分:0)

<强>解决即可。在apache2虚拟主机中,您必须汇总所有这些 SSLCipherSuite

SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA

谢谢大家的支持! 希望它可以帮助处于相同情况的任何人。问候。