How to Fix SSL_ERROR_NO_CYPHER_OVERLAP in Firefox
VigilDog Team · September 21, 2026 · 6 min read
SSL_ERROR_NO_CYPHER_OVERLAP is Firefox telling you it could not agree on how to encrypt the connection, the browser and the server share no common cipher suite or TLS version. It is a handshake failure, not a certificate error, and the fix depends entirely on whether you are the visitor or the person who runs the server. Here is how to diagnose and fix ssl_error_no_cypher_overlap either way.
What the error actually means
Every HTTPS connection starts with a TLS handshake. The browser sends a list of the protocol versions and cipher suites it supports; the server picks one they have in common and the encrypted session begins. SSL_ERROR_NO_CYPHER_OVERLAP means that list came back empty, there was no overlap, so Firefox refused to continue.
The word "overlap" is the key. Nothing is broken about the certificate itself; the two sides simply cannot find a mutually supported way to talk. In practice that happens for one of a few reasons: the server only offers ancient, insecure ciphers that modern Firefox has removed, the server only speaks an old TLS version (1.0 or 1.1) that Firefox has disabled, or something on the client, a hardened config or an antivirus proxy, has narrowed what Firefox will accept.
Quick checks if you're just a visitor
If you are hitting this on a site you don't control, work through the client-side possibilities first. Most of the time it is either an out-of-date browser or a locally modified security setting.
Run through these in order:
- Update Firefox to the latest version and restart it, cipher support changes between releases.
- Open about:config and check security.tls.version.min and security.tls.version.max. Reset them (min 3 = TLS 1.2, max 4 = TLS 1.3) if they've been changed.
- In about:config, make sure you haven't manually disabled cipher suites (search security.ssl3.*), right-click and Reset anything modified.
- Temporarily disable your antivirus/security suite's HTTPS or SSL scanning, which can intercept and mangle the handshake.
- Try the site in a fresh Firefox profile or another browser to confirm whether the problem is your Firefox or the server.
Diagnose the server
If the site is yours, or the checks above rule out the client, the server is offering nothing Firefox will accept. Confirm it directly instead of guessing. From any machine with OpenSSL, negotiate explicitly and see what the server supports:
openssl s_client -connect example.com:443 -tls1_2, if this fails but the server works elsewhere, TLS 1.2 support may be missing or the cipher list is too narrow. To enumerate every protocol and cipher the server offers, use nmap: nmap --script ssl-enum-ciphers -p 443 example.com. That output tells you exactly which TLS versions and cipher suites are enabled, and whether they're all the outdated ones Firefox has dropped.
You can also confirm the certificate and configuration at a glance with the free SSL checker, which flags weak or outdated setups without you needing the command line.
Fix the server configuration
The root-cause fix is almost always the same: enable modern TLS and offer at least a few current cipher suites. Support TLS 1.2 and TLS 1.3, and include ECDHE key-exchange ciphers with AES-GCM (for example ECDHE-RSA-AES128-GCM-SHA256). Remove reliance on RC4, 3DES, and export-grade ciphers, those are exactly what modern Firefox refuses.
In practice that means editing your web server's TLS settings, the ssl_protocols and ssl_ciphers directives in nginx, or SSLProtocol and SSLCipherSuite in Apache, and reloading. A well-known good baseline is Mozilla's own SSL Configuration Generator, which produces a copy-paste config for common servers. After reloading, re-run the openssl or nmap check to confirm the overlap now exists, then retry in Firefox.
Note this is distinct from an expired certificate, which throws a different error entirely, if that's what you're actually seeing, follow the steps for a certificate that has expired instead.
Keep it from coming back
Cipher and protocol support isn't set-and-forget. Browsers keep tightening what they accept, so a config that works today can start throwing SSL_ERROR_NO_CYPHER_OVERLAP a year from now when the last old cipher your server relied on gets dropped from a Firefox release. The failure mode is quiet: the site keeps loading for older clients while newer ones start bouncing.
That is worth monitoring rather than rediscovering through a support ticket. VigilDog's SSL/TLS monitoring watches your certificates and configuration continuously and warns you before a weak or outdated setup turns into a visitor-facing error, so you fix it on your schedule, not during an outage.
