How to Fix SSL_ERROR_NO_CYPHER_OVERLAP in Firefox

VigilDog Team · September 21, 2026 · 6 min read

SSL_ERROR_NO_CYPHER_OVERLAP is Firefox telling you it could not agree on how to encrypt the connection, the browser and the server share no common cipher suite or TLS version. It is a handshake failure, not a certificate error, and the fix depends entirely on whether you are the visitor or the person who runs the server. Here is how to diagnose and fix ssl_error_no_cypher_overlap either way.

What the error actually means

Every HTTPS connection starts with a TLS handshake. The browser sends a list of the protocol versions and cipher suites it supports; the server picks one they have in common and the encrypted session begins. SSL_ERROR_NO_CYPHER_OVERLAP means that list came back empty, there was no overlap, so Firefox refused to continue.

The word "overlap" is the key. Nothing is broken about the certificate itself; the two sides simply cannot find a mutually supported way to talk. In practice that happens for one of a few reasons: the server only offers ancient, insecure ciphers that modern Firefox has removed, the server only speaks an old TLS version (1.0 or 1.1) that Firefox has disabled, or something on the client, a hardened config or an antivirus proxy, has narrowed what Firefox will accept.

Quick checks if you're just a visitor

If you are hitting this on a site you don't control, work through the client-side possibilities first. Most of the time it is either an out-of-date browser or a locally modified security setting.

Run through these in order:

  • Update Firefox to the latest version and restart it, cipher support changes between releases.
  • Open about:config and check security.tls.version.min and security.tls.version.max. Reset them (min 3 = TLS 1.2, max 4 = TLS 1.3) if they've been changed.
  • In about:config, make sure you haven't manually disabled cipher suites (search security.ssl3.*), right-click and Reset anything modified.
  • Temporarily disable your antivirus/security suite's HTTPS or SSL scanning, which can intercept and mangle the handshake.
  • Try the site in a fresh Firefox profile or another browser to confirm whether the problem is your Firefox or the server.

Diagnose the server

If the site is yours, or the checks above rule out the client, the server is offering nothing Firefox will accept. Confirm it directly instead of guessing. From any machine with OpenSSL, negotiate explicitly and see what the server supports:

openssl s_client -connect example.com:443 -tls1_2, if this fails but the server works elsewhere, TLS 1.2 support may be missing or the cipher list is too narrow. To enumerate every protocol and cipher the server offers, use nmap: nmap --script ssl-enum-ciphers -p 443 example.com. That output tells you exactly which TLS versions and cipher suites are enabled, and whether they're all the outdated ones Firefox has dropped.

You can also confirm the certificate and configuration at a glance with the free SSL checker, which flags weak or outdated setups without you needing the command line.

Fix the server configuration

The root-cause fix is almost always the same: enable modern TLS and offer at least a few current cipher suites. Support TLS 1.2 and TLS 1.3, and include ECDHE key-exchange ciphers with AES-GCM (for example ECDHE-RSA-AES128-GCM-SHA256). Remove reliance on RC4, 3DES, and export-grade ciphers, those are exactly what modern Firefox refuses.

In practice that means editing your web server's TLS settings, the ssl_protocols and ssl_ciphers directives in nginx, or SSLProtocol and SSLCipherSuite in Apache, and reloading. A well-known good baseline is Mozilla's own SSL Configuration Generator, which produces a copy-paste config for common servers. After reloading, re-run the openssl or nmap check to confirm the overlap now exists, then retry in Firefox.

Note this is distinct from an expired certificate, which throws a different error entirely, if that's what you're actually seeing, follow the steps for a certificate that has expired instead.

Keep it from coming back

Cipher and protocol support isn't set-and-forget. Browsers keep tightening what they accept, so a config that works today can start throwing SSL_ERROR_NO_CYPHER_OVERLAP a year from now when the last old cipher your server relied on gets dropped from a Firefox release. The failure mode is quiet: the site keeps loading for older clients while newer ones start bouncing.

That is worth monitoring rather than rediscovering through a support ticket. VigilDog's SSL/TLS monitoring watches your certificates and configuration continuously and warns you before a weak or outdated setup turns into a visitor-facing error, so you fix it on your schedule, not during an outage.

Questions

Frequently asked

Is SSL_ERROR_NO_CYPHER_OVERLAP a certificate problem?

No. It's a handshake failure, the browser and server share no common cipher suite or TLS version. The certificate may be perfectly valid. Expired certificates produce a different, distinct error.

Why does the site work in Chrome but not Firefox?

Browsers ship slightly different cipher and protocol support and update on different schedules. A server offering only borderline-old ciphers may still satisfy one browser while another has already removed them, producing the overlap error in Firefox only.

I changed about:config settings, how do I undo them?

In about:config, search for the setting (for example security.tls.version.min), right-click it, and choose Reset to restore the default. Resetting security.tls.version.min/max and any modified security.ssl3.* entries fixes most client-side cases.

Catch weak TLS before your visitors do

VigilDog monitors your SSL/TLS configuration and certificate health continuously and alerts you before an outdated cipher setup turns into a handshake error. Start watching your endpoints in minutes.

Your first domain is free forever