Discussion:
what is "Error code: ssl_error_no_cypher_overlap" ?
Gabriel
2014-10-26 19:09:43 UTC
Permalink
This is weird! Trying to access: https://www.norse-corp.com/careers.html
I see the error "Cannot communicate securely with peer: no common encryption
algorithm(s). (Error code: ssl_error_no_cypher_overlap)"

User agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:33.0)
Gecko/20100101 Firefox/33.0 SeaMonkey/2.30
Build identifier: 20141014004953


It works with Firefox 33.0.1 but it shows an alert sign in the URL bar (I think
about mixed content).

G.
Ray_Net
2014-10-26 23:23:48 UTC
Permalink
Post by Gabriel
This is weird! Trying to access: https://www.norse-corp.com/careers.html
I see the error "Cannot communicate securely with peer: no common
encryption algorithm(s). (Error code: ssl_error_no_cypher_overlap)"
User agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:33.0)
Gecko/20100101 Firefox/33.0 SeaMonkey/2.30
Build identifier: 20141014004953
It works with Firefox 33.0.1 but it shows an alert sign in the URL bar
(I think about mixed content).
G.
No problem with my SM: User agent: Mozilla/5.0 (Windows NT 6.1; rv:29.0)
Gecko/20100101 Firefox/29.0 SeaMonkey/2.26.1

Except that the padlock is broken

http://www.norse-corp.com/careers.html without the "S" at the end if
http gives no problem at all
NoOp
2014-10-27 01:27:31 UTC
Permalink
Post by Gabriel
This is weird! Trying to access: https://www.norse-corp.com/careers.html
I see the error "Cannot communicate securely with peer: no common encryption
algorithm(s). (Error code: ssl_error_no_cypher_overlap)"
User agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:33.0)
Gecko/20100101 Firefox/33.0 SeaMonkey/2.30
Build identifier: 20141014004953
It works with Firefox 33.0.1 but it shows an alert sign in the URL bar (I think
about mixed content).
G.
Works for me.
User agent: Mozilla/5.0 (X11; Linux x86_64; rv:33.0) Gecko/20100101
Firefox/33.0 SeaMonkey/2.30
NoOp
2014-10-27 01:41:04 UTC
Permalink
Post by Gabriel
This is weird! Trying to access: https://www.norse-corp.com/careers.html
I see the error "Cannot communicate securely with peer: no common encryption
algorithm(s). (Error code: ssl_error_no_cypher_overlap)"
User agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:33.0)
Gecko/20100101 Firefox/33.0 SeaMonkey/2.30
Build identifier: 20141014004953
It works with Firefox 33.0.1 but it shows an alert sign in the URL bar (I think
about mixed content).
G
The issue is that the site uses SSL 3.0. Please see:

<http://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting-ssl-30.html>
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3566>
<https://bugzilla.mozilla.org/show_bug.cgi?id=1076983>
<http://threatpost.com/browser-vendors-move-to-disable-sslv3-in-wake-of-poodle-attack/108852>
<https://blog.mozilla.org/security/2014/10/14/the-poodle-attack-and-the-end-of-ssl-3-0/>

Worked for me with SSL 3 enabled. Does not work when I turn off SSL 3.0
(Edit|Preferences|Privacy & Security|SSL|) Enable SSL 3.0 if you want to
view/use the site. Probably a good idea to send the links to the
webmaster of that site...
WaltS48
2014-10-27 02:25:42 UTC
Permalink
Post by Gabriel
This is weird! Trying to access: https://www.norse-corp.com/careers.html
I see the error "Cannot communicate securely with peer: no common
encryption algorithm(s). (Error code: ssl_error_no_cypher_overlap)"
User agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:33.0)
Gecko/20100101 Firefox/33.0 SeaMonkey/2.30
Build identifier: 20141014004953
It works with Firefox 33.0.1 but it shows an alert sign in the URL bar
(I think about mixed content).
G.
Works in my SeaMonkey 2.30 with SSL3 enabled, works in Firefox 33.0 and
Chromium 38.0.2125.104 out of the box, and doesn't work with 34.0b3
because SSL3 is disabled by default.
NoOp
2014-10-27 02:54:49 UTC
Permalink
Post by WaltS48
Post by Gabriel
This is weird! Trying to access: https://www.norse-corp.com/careers.html
I see the error "Cannot communicate securely with peer: no common
encryption algorithm(s). (Error code: ssl_error_no_cypher_overlap)"
User agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:33.0)
Gecko/20100101 Firefox/33.0 SeaMonkey/2.30
Build identifier: 20141014004953
It works with Firefox 33.0.1 but it shows an alert sign in the URL bar
(I think about mixed content).
G.
Works in my SeaMonkey 2.30 with SSL3 enabled, works in Firefox 33.0 and
Chromium 38.0.2125.104 out of the box, and doesn't work with 34.0b3
because SSL3 is disabled by default.
:-)

Oh the ironey:

"About Norse

Norse is the global leader in live attack intelligence. Norse delivers
continuously updated and unique Internet and darknet intel that helps
organizations detect and block attacks that other systems miss. The
Norse DarkMatterâ„¢ platform detects new threats and tags nascent hazards
long before they are spotted by traditional threat intelligence tools."
Desiree
2014-10-27 10:20:08 UTC
Permalink
Post by Gabriel
This is weird! Trying to access: https://www.norse-corp.com/careers.html
I see the error "Cannot communicate securely with peer: no common encryption
algorithm(s). (Error code: ssl_error_no_cypher_overlap)"
User agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:33.0)
Gecko/20100101 Firefox/33.0 SeaMonkey/2.30
Build identifier: 20141014004953
It works with Firefox 33.0.1 but it shows an alert sign in the URL bar (I think
about mixed content).
G.
No one should have SSL 3 enabled! POODLE vulnerability has killed SSL 3.

I get the same message at your site on SeaMonkey 2.30, Pale Moon 25.0.2
(where the dev has disabled SSL 3) and Fx 24.8 ESR.

Qualys report
https://www.ssllabs.com/ssltest/analyze.html?d=norse-corp.com on that
site indicates that ONLY SSL 3 is used! The site claims they have
mitigated the POODLE risk but that site should be reported as broken.
Mozilla will be permanently disabling SSL3 soon and Mozilla blog
recommends that everyone in the meantime install their new addon SSL
Version control which works on Fx, Sea Monkey, Thunderbird and sets the
lowest SSL accepted to TLS 1.0. This addon is great because with a very
backward and dangerous server like that at norse-corp.com you can
temporarily enable SSL3 when you absolutely must visit that site amd
then disable SSL 3 again as soon as you leave the site. Still, you need
to report the site and also complain to the site's webmaster because you
won't be able to visit the site when Mozilla permanently disables SSL 3.
Plus, no site should be using only SSL 3 these days.

SSL Version Control extension by Mozilla will show grayed out install
button for SeaMonkey but ignore it and click to install anyway. It will
install just fine.
https://addons.mozilla.org/en-US/firefox/addon/ssl-version-control/


There is a separate problem with SeaMonkey 2.3. Even if that site was
using TLS 1.0, SeaMonkey 2.3 uses ONLY TLS 1.2 (the newest and
strongest protocol). At least, this is what Qualys reports when I run
SeaMonkey 2.3 through their analysis.
https://www.ssllabs.com/ssltest/viewMyClient.html

I have SeaMonkey set to use TLS 1.0, 1.1 and 1.2 inPreferences/Privacy
and Security/SSL but it is only using TLS 1.2. No browser currently has
proper fallback from TLS 1.2 to TLS 1.0 and on some sites (like my ISP's
crappy old server) SeaMonkey will fall back to TLS 1.0 (which is what
the server supports) but it is INSECURE fallback. On your site, SM
tries to use TLS 1.2 and doesn't try to fall back when that doesn't work
which is better than what happens on my ISP's website on many of their
secure pages.

The best current solution (not a good solution but the best that can be
had currently until the servers update to be able to use TLS 1.2 and/or
until the browsers finally properly support correct fallback from TLS
1.2 on servers that cannot use it to TLS 1.0) is to set
"security.tls.version.min" to the value "1" and set
"security.tls.version.max" to the value "1". Also install the Mozilla
extension SSL Version control. Here's a good reference article:
http://kb.mozillazine.org/Security.tls.version.*#Caveats
Gabriel
2014-10-27 12:18:59 UTC
Permalink
Post by Desiree
Post by Gabriel
This is weird! Trying to access: https://www.norse-corp.com/careers.html
I see the error "Cannot communicate securely with peer: no common encryption
algorithm(s). (Error code: ssl_error_no_cypher_overlap)"
User agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:33.0)
Gecko/20100101 Firefox/33.0 SeaMonkey/2.30
Build identifier: 20141014004953
It works with Firefox 33.0.1 but it shows an alert sign in the URL bar (I think
about mixed content).
G.
No one should have SSL 3 enabled! POODLE vulnerability has killed SSL 3.
I get the same message at your site on SeaMonkey 2.30, Pale Moon 25.0.2 (where
the dev has disabled SSL 3) and Fx 24.8 ESR.
Qualys report https://www.ssllabs.com/ssltest/analyze.html?d=norse-corp.com on
that site indicates that ONLY SSL 3 is used! The site claims they have
mitigated the POODLE risk but that site should be reported as broken. Mozilla
will be permanently disabling SSL3 soon and Mozilla blog recommends that
everyone in the meantime install their new addon SSL Version control which
works on Fx, Sea Monkey, Thunderbird and sets the lowest SSL accepted to TLS
1.0. This addon is great because with a very backward and dangerous server
like that at norse-corp.com you can temporarily enable SSL3 when you absolutely
must visit that site amd then disable SSL 3 again as soon as you leave the
site. Still, you need to report the site and also complain to the site's
webmaster because you won't be able to visit the site when Mozilla permanently
disables SSL 3. Plus, no site should be using only SSL 3 these days.
[CUT]

Thank you very much for all these informations!
I sent a message to Norse Corp. about this matter.

G.
WaltS48
2014-10-27 12:40:38 UTC
Permalink
Post by Desiree
SSL Version Control extension by Mozilla will show grayed out install
button for SeaMonkey but ignore it and click to install anyway. It
will install just fine.
https://addons.mozilla.org/en-US/firefox/addon/ssl-version-control/
Why would you need to install it on SeaMonkey, when SeaMonkey has a
check box for SSL3 here <http://imgur.com/lbYZnf5>.

Loading...