Jump to content

I booted up my R510 and can't log in to esxi, I get the notification that the connection is insecure and I'm pretty sure it's due to SSL.  It has always been an insecure connection but I always had the option to go to the page anyways.  Now I can't.  Any ideas of how I can log in without going through the certification process?

Audio go Brrrrrr

Link to comment
https://linustechtips.com/topic/998749-esxi-login-ssl-issue/
Share on other sites

Link to post
Share on other sites

Try a different browser?

PC Specs - AMD Ryzen 7 5800X3D MSI B550M Mortar - 32GB Corsair Vengeance RGB DDR4-3600 @ CL16 - ASRock RX7800XT 660p 1TBGB & Crucial P5 1TB Fractal Define Mini C CM V750v2 - Windows 11 Pro

 

Link to comment
https://linustechtips.com/topic/998749-esxi-login-ssl-issue/#findComment-11997039
Share on other sites

Link to post
Share on other sites

Just now, Psittac said:

did edge chrome and firefox

And you can't skip/add exception on any of them?

 

Is the time and date the same on the host and your PC?

PC Specs - AMD Ryzen 7 5800X3D MSI B550M Mortar - 32GB Corsair Vengeance RGB DDR4-3600 @ CL16 - ASRock RX7800XT 660p 1TBGB & Crucial P5 1TB Fractal Define Mini C CM V750v2 - Windows 11 Pro

 

Link to comment
https://linustechtips.com/topic/998749-esxi-login-ssl-issue/#findComment-11997052
Share on other sites

Link to post
Share on other sites

Did you enable hsts or something?

 

It will always show insecure with a self signed certificate, although things like hsts prevent you from ignoring that.  The error should include more information.

PC : 3600 · Crosshair VI WiFi · 2x16GB RGB 3200 · 1080Ti SC2 · 1TB WD SN750 · EVGA 1600G2 · Define C 

Link to comment
https://linustechtips.com/topic/998749-esxi-login-ssl-issue/#findComment-11998343
Share on other sites

Link to post
Share on other sites

This site can’t provide a secure connection

xxx.xxx.xxx.xxx uses an unsupported protocol.

ERR_SSL_VERSION_OR_CIPHER_MISMATCH
HIDE DETAILS
Unsupported protocol
The client and server don't support a common SSL protocol version or cipher suite.

Audio go Brrrrrr

Link to comment
https://linustechtips.com/topic/998749-esxi-login-ssl-issue/#findComment-12004404
Share on other sites

Link to post
Share on other sites

it does this on my desktop and my laptop.  I have the ip white listed in mbam but also have bitdefender which I can't figure out a whitelist on.  But in the notifications I'm not getting any warning or notice about something being blocked.  I just spent an hour trying to research this and it's way above my pay grade.  I got into the certificates but don't know what I'm doing so I left that alone.

 

edit: normally I would log into the server locally but I no longer have a vga/dsub monitor to do so.  I guess I can come up with one if I need to.  maybe the server time and date is wrong?

Audio go Brrrrrr

Link to comment
https://linustechtips.com/topic/998749-esxi-login-ssl-issue/#findComment-12004413
Share on other sites

Link to post
Share on other sites

Kaspersky block my connection, I need to add an exception, then once again refresh login page.

Go there chrome://flags/#ssl-version-min

Setup SSLv3 than restart your browser.

Case: Corsair iCUE 7000X RGB Black

Motherboard: Asus ROG CROSSHAIR VIII FORMULA

CPU: AMD Ryzen 9 3900X running at 4.5GHz

RAM 64GB G.SKILL TridentZ RGB Neo AMD DDR4 3200MHz

GPU: MSI Nvidia RTX 3080 TI Suprim X 12GB

Sound: Sound Blaster Audigy Rx

Storage: 2x Samsung NVMe 256GB  2x 256GB Samsung SSD PRO

Storage:  2x 8TB Seagate HDD

Cooling: NZXT KRAKEN Z73

PSU: ROG THOR 1200W Platinum

Monitor: LG 32UD99-W 4K + LG OLED 55" 120HZ 4K

Speakers Set: Logitech Z-906 THX 5.1

 

Laptop:

MacbookPro 13 (2016)  || MacbookPro 16 Core i9 2.4 and 32 GB DDR4 on 1TB SSD || Lenovo Legion Y540-17IRH with i7-9750H 32GB QVO2TB GTX1650-4GB

Server Lab:

Lenovo ThinkServer RD350 with 120GB DDR4 on 2x Intel Xeon E5-2609 v4 on Esexi or Proxmox

Network:

Hitron CGNv4 modem (Stock) || Linksys WRT32X (OpenWRT) || Mikrotik RB2011UiAS-2HnD-IN (OpenWRT)  || UniFi Security Gateway PRO USG‑PRO‑4 || UniFi Cloud Key Gen2 Plus || UniFi Switch 48 US-48-500W POE

Link to comment
https://linustechtips.com/topic/998749-esxi-login-ssl-issue/#findComment-12005404
Share on other sites

Link to post
Share on other sites

it was bit defender, I did everything I could to add exclusions or white list but it didn't work.  Had to uninstall it then it worked.  They must have made some update to bitdefender recently.

 

Also I saw that Avast anti-virus was on my system and I know I didn't put it there since I've been using bit defender since before I did a fresh install, there would have been no reason to install it.

Audio go Brrrrrr

Link to comment
https://linustechtips.com/topic/998749-esxi-login-ssl-issue/#findComment-12005802
Share on other sites

Link to post
Share on other sites

9 hours ago, Psittac said:

This site can’t provide a secure connection

xxx.xxx.xxx.xxx uses an unsupported protocol.

ERR_SSL_VERSION_OR_CIPHER_MISMATCH
HIDE DETAILS
Unsupported protocol
The client and server don't support a common SSL protocol version or cipher suite.

The web server has the 0 matching SSL settings or 0 matching ciphers to your local system.

 

Not sure about what web server ESXi uses, but i'd assume you can change that via the CLI on the system locally (or via SSH).

Otherwise change your local security ciphers / SSL settings.

 

It'd recommend reading: https://blog.pcisecuritystandards.org/are-you-ready-for-30-june-2018-sayin-goodbye-to-ssl-early-tls

the disabling SSL (all versions) and TLSv1.0 and change the ciphers used. Not that windows and linux (i.e. apache, etc) will often call the same cipher something different, even though they are the same.

Link to comment
https://linustechtips.com/topic/998749-esxi-login-ssl-issue/#findComment-12006540
Share on other sites

Link to post
Share on other sites

On 11/26/2018 at 7:50 AM, Mikensan said:

What version of ESXi are you running? Beyond the hostname not matching the SNI the crypto used should be acceptable to almost everything.

I just use a local IP address.  I'm not into the world of networking, I have some of the equipment but haven't done anything related to it.

Audio go Brrrrrr

Link to comment
https://linustechtips.com/topic/998749-esxi-login-ssl-issue/#findComment-12015427
Share on other sites

Link to post
Share on other sites

On 11/28/2018 at 12:21 AM, Psittac said:

I just use a local IP address.  I'm not into the world of networking, I have some of the equipment but haven't done anything related to it.

What version of ESXi are you running? Might be as simple as an update.

Link to comment
https://linustechtips.com/topic/998749-esxi-login-ssl-issue/#findComment-12020449
Share on other sites

Link to post
Share on other sites

Spoiler

Desktop: Ryzen9 5950X | ASUS ROG Crosshair VIII Hero (Wifi) | EVGA RTX 3080Ti FTW3 | 32GB (2x16GB) Corsair Dominator Platinum RGB Pro 3600Mhz | EKWB EK-AIO 360D-RGB | EKWB EK-Vardar RGB Fans | 1TB Samsung 980 Pro, 4TB Samsung 980 Pro | Corsair 5000D Airflow | Corsair HX850 Platinum PSU | Asus ROG 42" OLED PG42UQ + LG 32" 32GK850G Monitor | Roccat Vulcan TKL Pro Keyboard | Logitech G Pro X Superlight  | MicroLab Solo 7C Speakers | Audio-Technica ATH-M50xBT2 LE Headphones | TC-Helicon GoXLR | Audio-Technica AT2035 | LTT Desk Mat | XBOX-X Controller | Windows 11 Pro

 

Spoiler

Server: Fractal Design Define R6 | Ryzen 3950x | ASRock X570 Taichi | Asus RTX 4060 Dual OC | 64GB (4x16GB) Corsair Vengeance LPX 3000Mhz | Corsair RM850v2 PSU | Fractal S36 Triple AIO + 4 Additional Venturi 120mm Fans | 8 x 20TB Seagate Exos X22 | 4 x 16TB Seagate Exos X18 | 3 x 2TB Samsung 970 Evo Plus NVMe | LSI 9211-8i HBA

 

Spoiler

NAS: Innovision 4U 24-bay chassis (12GB MiniHD SGIO Backplane) | Intel Core i9-10980xe | EVGA X299 FTW-K | EVGA RTX 2080Ti Super FTW3 | 128GB (8x16GB) Corsair Vengeance LPX 3200Mhz | DEEPCOOL PN1000M PSU| Noctua NH-D12L Chromax Black | 16 x 16TB Seagate Exos X18 | 2 x 2TB Samsung 990 Pro | 2 x 2TB Intel U.2 P4510 | LSI 9305-24i HBA

 

Link to comment
https://linustechtips.com/topic/998749-esxi-login-ssl-issue/#findComment-12021933
Share on other sites

Link to post
Share on other sites

There is a large range of different cipher suites that can be used for SSL. I am not sure which one ESXI uses exactly. However, if a security solution doesn't have the ability to handle a specific cipher being requested by a service, they will attempt to downgrade the connection to a lower (less secure) cipher that they can work with. For example, an ECDHE cipher might be downgraded to RSA 128. This then allows the security solution to decrypt the traffic and inspect the traffic to make sure there is no malicious content. 

This is what I assume is happening in your scenario. Unfortunately some services will not accept a downgrade in the cipher suite used in order to maintain security. Lower grade ciphers are also easier for criminals to break, so if a MITM attack is in play, a weak cipher can make it easier for them to view/change the traffic. 

 

With most consumer based security solutions, its often the case that exclusions don't actually completely exclude traffic. Or, in order for it to be successful, exclusions need to set up in multiple sections of the settings. E.g. Exclusions may be set for file anti virus activities, but still be enabled for IPS or Firewall components. Which means it will still intercept traffic for some of the functionality. You can usually get it to an operational point but it can require a lot of tweaking. Keep an eye out for browser plugins too. 

 

Hope this helps. 

Link to comment
https://linustechtips.com/topic/998749-esxi-login-ssl-issue/#findComment-12024476
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×