Connectrix B-Series: The Web Browsers Report "Cipher Mismatch, No Matching Ciphers" When Accessing WebTools UI Using HTTPS

Сводка: AES256-SHA256 (0x3d) and AES128-SHA256 (0x3c) is blocked for TLS.

Данная статья применяется к Данная статья не применяется к Эта статья не привязана к какому-либо конкретному продукту. В этой статье указаны не все версии продуктов.

Симптомы

The web browsers (Chrome, New Edge, or Firefox) refused to open the WebTools using HTTPS.

The error message contains "Cipher Mismatch" or "No Matching Ciphers."
 
Screenshot of Error Message Showing Connection Not Secure, Unsupported Protocol
Figure 1: Screenshot of Error Message Showing Connection Not Secure, Unsupported Protocol

The switch is running in FOS 8.1 or 8.2 firmware.
 

Причина

The switch HTTPS cipher setting only allows AES256-SHA256 and AES128-SHA256 for TLS 1.2 (the "default_generic" or "default_strong templates" of FOS 8.1 or 8.2).
<switchname>:root> seccryptocfg --show | grep HTTPS
HTTPS                    : !ECDH:!DH:HIGH:-MD5:!CAMELLIA:!SRP:!PSK:!AESGCM:!SSLv3
HTTPS                    : TLSv1.2

<switchname:root> openssl ciphers -v '!ECDH:!DH:HIGH:-MD5:!CAMELLIA:!SRP:!PSK:!AESGCM:!SSLv3'
AES256-SHA256           TLSv1.2 Kx=RSA      Au=RSA  Enc=AES(256)  Mac=SHA256
AES128-SHA256           TLSv1.2 Kx=RSA      Au=RSA  Enc=AES(128)  Mac=SHA256

The Wireshark dump shows that the client does not accept AES256-SHA256 (0x3d) or AES128-SHA256 (0x3c), hence the TLS handshake fails.
 
Screenshot of Wireshark Dump Showing Handshake Failure
Figure 2: Screenshot of Wireshark Dump Showing Handshake Failure

Разрешение

Modify the switch HTTPS cipher setting to cover the client. 

Example:
In this example, the current HTTPS cipher setting is "!ECDH:!DH:HIGH:-MD5:!CAMELLIA:!SRP:!PSK:!AESGCM:!SSLv3"

To enable AES256-GCM-SHA384 (0x9d) and AES128-GCM-SHA256 (0x9c), remove "!AESGCM" from the setting with the command:
seccryptocfg --replace -type https -cipher '!ECDH:!DH:HIGH:-MD5:!CAMELLIA:!SRP:!PSK:!SSLv3'

Дополнительная информация

Map OpenSSL cipher names (displayed in the OpenSSL command) with IANA cipher names (displayed in Wireshark dump) using the Mozilla document, Security/Cipher Suites - MozillaWiki This hyperlink is taking you to a website outside of Dell Technologies.

Затронутые продукты

Connectrix B-Series
Свойства статьи
Номер статьи: 000213633
Тип статьи: Solution
Последнее изменение: 18 May 2026
Версия:  6
Получите ответы на свои вопросы от других пользователей Dell
Услуги технической поддержки
Проверьте, распространяются ли на ваше устройство услуги технической поддержки.