<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How to disable weak ephemeral Diffie-Hellman public key error]]></title><description><![CDATA[<p dir="auto">Starting in Opera 30, Opera prevents the HTTPS connection to servers with the D-H group lower than 1024 bits (susceptible to "logjam" attacks). When attempted to connect, you receive this message:</p>
<p dir="auto">"Server has a weak ephemeral Diffie-Hellman public key.<br />
This error can occur when connecting to a secure (HTTPS) server. It means that the server is trying to set up a secure connection but, due to a disastrous misconfiguration, the connection wouldn't be secure at all!<br />
In this case the server needs to be fixed. Opera won't use insecure connections in order to protect your privacy."</p>
<p dir="auto">This is nice, but there needs to be a way (via developers flags, for example) to disable the enforcement. I am aware of weakened security for some sites but need to connect to them anyways - locking the users out is not a solution because we do not control the server settings! Warning is fine, but locking out is unacceptable - besides, on some sites I may not even care that much about perfect security in the first place.</p>
<p dir="auto">Is there a workaround solution to get around this - short of downgrading to Opera 29, or using other browsers, ALL of which still allow the connections (at least for now)?</p>
]]></description><link>https://forums.opera.com/topic/10383/how-to-disable-weak-ephemeral-diffie-hellman-public-key-error</link><generator>RSS for Node</generator><lastBuildDate>Sun, 10 May 2026 02:36:01 GMT</lastBuildDate><atom:link href="https://forums.opera.com/topic/10383.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 15 Jun 2015 19:24:52 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Mon, 16 Nov 2015 09:10:26 GMT]]></title><description><![CDATA[<blockquote>
<blockquote>
<p dir="auto">Oops! Looks like Firefox will be going this way at the end of June. See:<br />
<a href="https://addons.mozilla.org/en-us/firefox/addon/disable-dhe/" target="_blank" rel="noopener noreferrer nofollow ugc">https://addons.mozilla.org/en-us/firefox/addon/disable-dhe/</a></p>
</blockquote>
<p dir="auto">My Firefox is at version 38.0.5, and I can still connect to <a href="http://Freephoneline.ca" target="_blank" rel="noopener noreferrer nofollow ugc">Freephoneline.ca</a> site normally. But I still cannot connect with Opera.<br />
Opera is trying to be a nanny-browser when no one asks it to. Logjam is not an easy exploit to, well, exploit, and it's not like I'm trying to connect to a compromised banking site. With this enforcement policy, Opera found a way to drive its single-digit market share even lower.<br />
Every good security policy states that at the end of the day security should be in the hands of customers. The product must provide all the tools to enable "perfect" security and flag all known issues, but it must be up to the end user to make the ultimate decision whether to take a perceived risk.</p>
</blockquote>
<p dir="auto">I have no problem connecting <a href="http://freephone.ca" target="_blank" rel="noopener noreferrer nofollow ugc">freephone.ca</a> using the latest stable version of Opera (33)looks like they may have fixed the problem</p>
]]></description><link>https://forums.opera.com/post/87960</link><guid isPermaLink="true">https://forums.opera.com/post/87960</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Mon, 16 Nov 2015 09:10:26 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Sun, 15 Nov 2015 04:10:40 GMT]]></title><description><![CDATA[<p dir="auto">I have also had this issue on my Galaxy S5. My Galaxy S4 gave me the option to continue and the 5 won't. I also was a network administer so it's really frustrating. I had to sites that I needed to get access to and I found an internet that allows you to. I hope this helps you all out. Download the Dolphin browser and no more headaches.</p>
]]></description><link>https://forums.opera.com/post/87887</link><guid isPermaLink="true">https://forums.opera.com/post/87887</guid><dc:creator><![CDATA[iwashereonce]]></dc:creator><pubDate>Sun, 15 Nov 2015 04:10:40 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Wed, 08 Jul 2015 17:02:24 GMT]]></title><description><![CDATA[<p dir="auto">Whenever I try contacting support for <a href="http://www.tutor.com" target="_blank" rel="noopener noreferrer nofollow ugc">www.tutor.com</a>, I get that message. But when I use another browser like Google Chrome for the same site, everything is OK.</p>
]]></description><link>https://forums.opera.com/post/79549</link><guid isPermaLink="true">https://forums.opera.com/post/79549</guid><dc:creator><![CDATA[msubulldog]]></dc:creator><pubDate>Wed, 08 Jul 2015 17:02:24 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Wed, 08 Jul 2015 13:53:55 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">I can't access https websites even in local network.</p>
</blockquote>
<p dir="auto">Sounds to me like you have Turbo enabled.</p>
]]></description><link>https://forums.opera.com/post/79540</link><guid isPermaLink="true">https://forums.opera.com/post/79540</guid><dc:creator><![CDATA[lando242]]></dc:creator><pubDate>Wed, 08 Jul 2015 13:53:55 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Wed, 08 Jul 2015 13:51:19 GMT]]></title><description><![CDATA[<p dir="auto">It's ridiculous. To implement the things people don't ask, as ignore real necessary requests (or even omit them).<br />
I can't access https websites even in local network.<br />
There always must be a choice for every security issues, e.g. for developers.</p>
<p dir="auto">I was using and recommending Opera since 2003, once was Opera Campus Crew evangelist, but sorry, can't go anymore with browser stubborn on dumb inflexibility.</p>
]]></description><link>https://forums.opera.com/post/79539</link><guid isPermaLink="true">https://forums.opera.com/post/79539</guid><dc:creator><![CDATA[cibron]]></dc:creator><pubDate>Wed, 08 Jul 2015 13:51:19 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Mon, 06 Jul 2015 09:15:41 GMT]]></title><description><![CDATA[<p dir="auto">Firefox 39 do the same now.</p>
]]></description><link>https://forums.opera.com/post/79445</link><guid isPermaLink="true">https://forums.opera.com/post/79445</guid><dc:creator><![CDATA[byakuichi]]></dc:creator><pubDate>Mon, 06 Jul 2015 09:15:41 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Tue, 30 Jun 2015 19:13:53 GMT]]></title><description><![CDATA[<p dir="auto">Totally unacceptable! I need to access a school site to take a quiz and opera is blocking my login. Warning is acceptable but not allowing me to connect to a known site is an unwarranted intrusion.</p>
]]></description><link>https://forums.opera.com/post/79111</link><guid isPermaLink="true">https://forums.opera.com/post/79111</guid><dc:creator><![CDATA[zrqmlao]]></dc:creator><pubDate>Tue, 30 Jun 2015 19:13:53 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Sun, 28 Jun 2015 18:40:45 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">Oops! Looks like Firefox will be going this way at the end of June. See:<br />
<a href="https://addons.mozilla.org/en-us/firefox/addon/disable-dhe/" target="_blank" rel="noopener noreferrer nofollow ugc">https://addons.mozilla.org/en-us/firefox/addon/disable-dhe/</a></p>
</blockquote>
<p dir="auto">My Firefox is at version 38.0.5, and I can still connect to <a href="http://Freephoneline.ca" target="_blank" rel="noopener noreferrer nofollow ugc">Freephoneline.ca</a> site normally. But I still cannot connect with Opera.</p>
<p dir="auto">Opera is trying to be a nanny-browser when no one asks it to. Logjam is not an easy exploit to, well, exploit, and it's not like I'm trying to connect to a compromised banking site. With this enforcement policy, Opera found a way to drive its single-digit market share even lower.</p>
<p dir="auto">Every good security policy states that at the end of the day security should be in the hands of customers. The product must provide all the tools to enable "perfect" security and flag all known issues, but it must be up to the end user to make the ultimate decision whether to take a perceived risk.</p>
]]></description><link>https://forums.opera.com/post/78953</link><guid isPermaLink="true">https://forums.opera.com/post/78953</guid><dc:creator><![CDATA[vikont]]></dc:creator><pubDate>Sun, 28 Jun 2015 18:40:45 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Fri, 26 Jun 2015 13:43:12 GMT]]></title><description><![CDATA[<p dir="auto">This is utter horseshit.  This error should absolutely appear by default to protect the average user, but to not even provide a means by which to bypass it is absurd.  I am a network/systems administrator - I know exactly what the hell I'm doing, and if I want to run the risks associated with a weak security key when using my own computer, the browser had better get the fuck out of my way.</p>
<p dir="auto">I have been recommending Opera to my end users for quite some time, and I had intended to make the switch from Chrome to Opera for all of my browsing and resource management needs, but at this point I refuse to support Opera in any way, if only out of principal.  Back to Google's memory hogging BS, I guess.  Opera is officially uninstalled from my machine, and I will start vehemently discouraging my end users from using it.</p>
<p dir="auto">Bye, Felicia.</p>
]]></description><link>https://forums.opera.com/post/78810</link><guid isPermaLink="true">https://forums.opera.com/post/78810</guid><dc:creator><![CDATA[Deleted User]]></dc:creator><pubDate>Fri, 26 Jun 2015 13:43:12 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Sun, 21 Jun 2015 03:14:27 GMT]]></title><description><![CDATA[<p dir="auto">At root, this breaks down to a question of convenience versus security, which is an age old conflict. Ultimately, employing any degree of security protection inherently implies a corresponding degree of inconvenience. Some of those software makers who supply a communications portal for users believe they have an obligation to protect user security to the best degree possible, even if that means breaking communications paths for those link partners not employing up-to-date security protocols (and hence certificates). Because any user setting that allows the user to bypass a portal security protection opens up the possibility of exploitation, either directly or inadvertantly and either immediately or later on, some security-conscious software makers elect not to provide user bypass options for their built-in security protection elements. Opera is such a maker. Possibly Mozilla will be as well, depending on how they implement their DH fix.</p>
<p dir="auto">One can argue endlessly about whether a software maker should protect a user from himself, or to what degree. Experienced users may indeed be wise enough to intelligently and carefully relax certain security settings for certain situations; but all too often, either those settings are neglected to be reversed thereafter or inexperienced users relax the settings just to make some favorite 'trivial' site work properly and never think to reverse them for sites where true security/privacy really matter.</p>
<p dir="auto">In any case, the ultimate industry goal is that all websites and all browsers be upgraded to omit such evident https encryption and secure protocol weaknesses. One of the few practical ways to push that to happen is to migrate browser designs to become incompatible with weak encryption techniques, which in turn will deprive offending sites of visitors and deluge them with user complaints. Ultimately, those sites will have to update their servers and certs if they want to continue supplying https connections; otherwise, they will either drop back to the http level of protection they are in reality offering by weak encryption/protocols or go extinct.</p>
<p dir="auto">One can elect to use a browser that still allows weak DH encryption for https connections, of course, and run the various risks entailed in keeping the connection private or exploit-free. But it's my belief that fewer such browsers will remain available for much longer.</p>
]]></description><link>https://forums.opera.com/post/78384</link><guid isPermaLink="true">https://forums.opera.com/post/78384</guid><dc:creator><![CDATA[blackbird71]]></dc:creator><pubDate>Sun, 21 Jun 2015 03:14:27 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Fri, 19 Jun 2015 16:49:14 GMT]]></title><description><![CDATA[<p dir="auto">Last week, I started getting the Diffie-Hellman error when logging into my online softphone. Opera  was the <em>only</em> browser that correctly enabled the phone. I worked-around the problem by deleting browsing data. At first a day would work. Then, I had to delete a week, then a month. Now even a month won't work. I managed to login by opening a private window. That stopped working today.</p>
]]></description><link>https://forums.opera.com/post/78278</link><guid isPermaLink="true">https://forums.opera.com/post/78278</guid><dc:creator><![CDATA[markrcarterjdphd]]></dc:creator><pubDate>Fri, 19 Jun 2015 16:49:14 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Fri, 19 Jun 2015 14:19:48 GMT]]></title><description><![CDATA[<p dir="auto">Oops! Looks like Firefox will be going this way at the end of June. See:</p>
<p dir="auto"><a href="https://addons.mozilla.org/en-us/firefox/addon/disable-dhe/" target="_blank" rel="noopener noreferrer nofollow ugc">https://addons.mozilla.org/en-us/firefox/addon/disable-dhe/</a></p>
]]></description><link>https://forums.opera.com/post/78263</link><guid isPermaLink="true">https://forums.opera.com/post/78263</guid><dc:creator><![CDATA[jm4444]]></dc:creator><pubDate>Fri, 19 Jun 2015 14:19:48 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Thu, 18 Jun 2015 11:40:37 GMT]]></title><description><![CDATA[<p dir="auto">This is very severe. Users should be able to choose what they want to do.</p>
<p dir="auto">I was the only guy here at an industrial software company that was a defender for Opera. Not anymore.</p>
<p dir="auto">60% of the sites I am using to work are returning this message. I can't stay all day long copying and pasting the links from Opera to Chrome.</p>
<p dir="auto">Unfortunately, I will stop using Opera. Hope the developers fix this issue asap.</p>
]]></description><link>https://forums.opera.com/post/78194</link><guid isPermaLink="true">https://forums.opera.com/post/78194</guid><dc:creator><![CDATA[slovardzen]]></dc:creator><pubDate>Thu, 18 Jun 2015 11:40:37 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Tue, 16 Jun 2015 23:02:46 GMT]]></title><description><![CDATA[<p dir="auto">I don't think you will be able to disable the block: <a href="http://blogs.opera.com/security/2015/06/unjam-the-logjam/" target="_blank" rel="noopener noreferrer nofollow ugc">http://blogs.opera.com/security/2015/06/unjam-the-logjam/</a></p>
]]></description><link>https://forums.opera.com/post/78054</link><guid isPermaLink="true">https://forums.opera.com/post/78054</guid><dc:creator><![CDATA[leocg]]></dc:creator><pubDate>Tue, 16 Jun 2015 23:02:46 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Tue, 16 Jun 2015 22:32:39 GMT]]></title><description><![CDATA[<p dir="auto">Here you are: <a href="https://www.freephoneline.ca" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.freephoneline.ca</a></p>
<p dir="auto">Surprisingly enough, this site allows for a non-encrypted http connection (that's bad!), and Opera is perfectly OK with it...</p>
]]></description><link>https://forums.opera.com/post/78048</link><guid isPermaLink="true">https://forums.opera.com/post/78048</guid><dc:creator><![CDATA[vikont]]></dc:creator><pubDate>Tue, 16 Jun 2015 22:32:39 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Tue, 16 Jun 2015 21:25:45 GMT]]></title><description><![CDATA[<p dir="auto">If you post a link to a page that throws that error, someone here might be able to help (maybe).</p>
]]></description><link>https://forums.opera.com/post/78038</link><guid isPermaLink="true">https://forums.opera.com/post/78038</guid><dc:creator><![CDATA[jm4444]]></dc:creator><pubDate>Tue, 16 Jun 2015 21:25:45 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Tue, 16 Jun 2015 16:45:05 GMT]]></title><description><![CDATA[<p dir="auto">I agree with vikont - There needs to be a way for the user to make the choice whether to proceed or not. I'm an Instructor of Web Development at a local University and I can't get to the University web site using Opera - I can with every other browser, but not Opera! I certainly will tell all my students not to go near the Opera browser in my class if this isn't fixed.</p>
]]></description><link>https://forums.opera.com/post/77998</link><guid isPermaLink="true">https://forums.opera.com/post/77998</guid><dc:creator><![CDATA[charlieb3]]></dc:creator><pubDate>Tue, 16 Jun 2015 16:45:05 GMT</pubDate></item><item><title><![CDATA[Reply to How to disable weak ephemeral Diffie-Hellman public key error on Mon, 15 Jun 2015 20:21:09 GMT]]></title><description><![CDATA[<p dir="auto">Not that I know.</p>
]]></description><link>https://forums.opera.com/post/77918</link><guid isPermaLink="true">https://forums.opera.com/post/77918</guid><dc:creator><![CDATA[leocg]]></dc:creator><pubDate>Mon, 15 Jun 2015 20:21:09 GMT</pubDate></item></channel></rss>