This site will have limited functionality while we undergo maintenance to improve your experience. If an article doesn't solve your issue and you want to ask a question, we have our support community waiting to help you at @FirefoxSupport on Twitter and/r/firefox on Reddit.

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

Secure Connection/SSL Handshake Issues on IIS Servers after being remediated with custom IIS Crypto settings

more options

We're having issues connecting via Firefox 61 and at least FF60 (possibly earlier) to systems which we have remediated with IIS Crypto (SCHANNEL remediation) using an altered version of their PCI 3.1 template (screen shots of settings attached).

IE 11 and Chrome 68 seem to work without issue, and when we check for like Cipher Suites, it seems to line up on at least one, but FF still fails to connect.

IIS Crypto Enabled settings: TLS 1.2 AES 128/128 and AES 256/256 SHA 256/384/512 PKCS and ECDH

I have included screen shots of the SCHANNEL config and the expected Cipher Suite order we have applied to the servers.

Any thoughts?

We're having issues connecting via Firefox 61 and at least FF60 (possibly earlier) to systems which we have remediated with IIS Crypto (SCHANNEL remediation) using an altered version of their PCI 3.1 template (screen shots of settings attached). IE 11 and Chrome 68 seem to work without issue, and when we check for like Cipher Suites, it seems to line up on at least one, but FF still fails to connect. IIS Crypto Enabled settings: TLS 1.2 AES 128/128 and AES 256/256 SHA 256/384/512 PKCS and ECDH I have included screen shots of the SCHANNEL config and the expected Cipher Suite order we have applied to the servers. Any thoughts?
Attached screenshots

All Replies (1)

more options

The specific error message we're getting in Firefox:


Secure Connection Failed

The connection to the server was reset while the page was loading.

   The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.
   Please contact the website owners to inform them of this problem.

Modified by jlucas.plumchoice