{"id":7832,"date":"2018-10-30T13:14:17","date_gmt":"2018-10-30T17:14:17","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=7832"},"modified":"2023-05-25T11:52:13","modified_gmt":"2023-05-25T15:52:13","slug":"ssl_error_rx_record_too_long","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/ssl_error_rx_record_too_long\/","title":{"rendered":"How to fix the SSL_ERROR_RX_RECORD_TOO_LONG Firefox Error"},"content":{"rendered":"<h2>There\u2019s a lot of really bad advice on this, so be careful what you trust.<\/h2>\n<p>In addition to my daily screeds on Hashed Out, I also tackle a range of other SSL-related writing tasks throughout my day-to-day\u2014one of those is troubleshooting articles. Yesterday I was doing research for a <a href=\"https:\/\/www.thesslstore.com\/knowledgebase\/\">knowledgebase article<\/a> on how to solve a Firefox error message: SSL_ERROR_RX_RECORD_TOO_LONG.<\/p>\n<p>The problem with these articles is that they\u2019re written to check boxes on an SEO checklist instead of written from a security-first standpoint. And in this context that\u2019s dangerous because Google\u2019s algorithm rewards the SEO-optimized misinformation over more accurate descriptions that weren\u2019t necessarily meant to rank well.<\/p>\n<p>So, today we\u2019ll use our own SEO powers for good and talk about the SSL_ERROR_RX_RECORD_TOO_LONG Firefox error. There seems to be a lot of confusion over what this error actually is. What it means. How to fix it. And apparently we also need to outline some things that you definitely shouldn\u2019t do.<\/p>\n<p>So, let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n<h2>What is SSL_ERROR_RX_RECORD_TOO_LONG?<\/h2>\n<p>The SSL_ERROR_RX_RECORD_TOO_LONG message from Firefox typically comes as a result of a misconfiguration on the server side. Contrary to what a lot of these guides will tell you, there usually isn\u2019t a whole lot that a regular internet user can do to overcome the SSL_ERROR_RX_RECORD_TOO_LONG message. Most of the advice is dangerous. It asks the user to adjust something to accommodate what is, in all reality, bad security on the part of the website you\u2019re trying to visit.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-7836\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Error-Browser-Vector-Icon-Fil-242176321-e1540917868244-300x300.jpg\" alt=\"SSL_ERROR_RX_RECORD_TOO_LONG \" width=\"300\" height=\"300\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Error-Browser-Vector-Icon-Fil-242176321-e1540917868244-300x300.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Error-Browser-Vector-Icon-Fil-242176321-e1540917868244-768x768.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Error-Browser-Vector-Icon-Fil-242176321-e1540917868244.jpg 900w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>Let\u2019s start by covering the two most predominant causes of the SSL_ERROR_RX_RECORD_TOO_LONG message from the server side:<\/p>\n<ul>\n<li>You\u2019ve got the listening port misconfigured \u2013 If you want your website to establish secure connections you must configure it to use Port 443.<\/li>\n<li>You don\u2019t support an adequate TLS version \u2013 This problem arose ten years ago with the advent of TLS 1.2 and is appearing again with <a href=\"https:\/\/www.thesslstore.com\/blog\/tls-1-3-everything-possibly-needed-know\/\">TLS 1.3<\/a>.<\/li>\n<\/ul>\n<p>The vast majority of the time, the SSL_ERROR_RX_RECORD_TOO_LONG message occurs because of one of those two issues on the server-side. Let\u2019s go over how to fix both of these, and then we\u2019ll go over some possible other fixes from the client side\u2014as well as what not to do from the client side. Let\u2019s start with the simplest of the two\u2026<\/p>\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n<h2>Upgrade TLS Version Support to fix SSL_ERROR_RX_RECORD_TOO_LONG<\/h2>\n<p>TLS 1.3 was formally published in the middle of August as <a href=\"https:\/\/www.thesslstore.com\/blog\/tls-1-3-approved\/\">RFC 8446<\/a>. It\u2019s not exactly new though, over about 28 drafts the standard was debated and refined, but plenty of major industry players knew enough of what would be in the standard to <a href=\"https:\/\/www.thesslstore.com\/blog\/firefox-61-launches\/\">begin rolling out support for it<\/a>. As such, most major browsers <a href=\"https:\/\/www.thesslstore.com\/blog\/security-changes-in-chrome-63\/\">already have TLS 1.3 active<\/a> and many servers have already begun to upgrade.<\/p>\n<p>So, what do you need to do to improve TLS version support? <strong>You\u2019re going to need to update your SSL\/TLS library<\/strong>. The majority of servers and systems use the Open SSL library, <a href=\"https:\/\/www.openssl.org\/blog\/blog\/2018\/09\/11\/release111\/\">which pushed out its 1.1.1 update in September<\/a> and supports TLS 1.3.<\/p>\n<p>If you\u2019re not ready to support TLS 1.3 for whatever reason, at least make sure you\u2019re supporting TLS 1.2. <a href=\"https:\/\/www.thesslstore.com\/blog\/june-30-to-disable-tls-1-0\/\">Support for TLS 1.0 and SSL 3.0 should now be fully deprecated<\/a> and <a href=\"https:\/\/www.thesslstore.com\/blog\/apple-microsoft-google-disable-tls-1-0-tls-1-1\/\">disabling TLS 1.1 is also strongly advised<\/a>. So, to recap:<\/p>\n<ul>\n<li>Add support for TLS 1.3 as soon as possible<\/li>\n<li>Make sure you\u2019re supporting TLS 1.2 at the very least<\/li>\n<li>Turn off support for SSL 3.0, TLS 1.0 and (highly suggested) TLS 1.1<\/li>\n<\/ul>\n<p>Upgrading Open SSL is going to vary from server to server, <a href=\"https:\/\/www.openssl.org\/blog\/blog\/2018\/09\/11\/release111\/\">but there\u2019s plenty of documentation to help you with it<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-7839 size-full\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/OpenSSL.jpeg\" alt=\"OpenSSL\" width=\"670\" height=\"283\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/OpenSSL.jpeg 670w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/OpenSSL-300x127.jpeg 300w\" sizes=\"auto, (max-width: 670px) 100vw, 670px\" \/><\/p>\n<h2>Configuring the correct listening port to fix SSL_ERROR_RX_RECORD_TOO_LONG<\/h2>\n<p>As we mentioned earlier, the correct listening port for HTTPS traffic is 443. So if you\u2019re using an irregular port or you don\u2019t have a <a href=\"https:\/\/www.thesslstore.com\/blog\/risks-of-using-self-signed-certificates\/\">trusted SSL\/TLS certificate<\/a> on that port, you\u2019re potentially going to trigger the SSL_ERROR_RX_RECORD_TOO_LONG message.<\/p>\n<p>Again, the exact way to fix this is going to vary based on server type, but if you just Google: Server Name + Port 443 + HTTPS, you should be fine.<\/p>\n<p>One more thing: be extra careful to get the exact nomenclature correct, too. For instance on NGinX servers \u201clisten 443\u201d won\u2019t work like you want, but \u201clisten 443 ssl\u201d will.<img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-7835 size-medium\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Lan-Port-Icon-In-Outline-Style-262876930-e1540918005927-300x300.jpg\" alt=\"Clear Firefox Cache\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Lan-Port-Icon-In-Outline-Style-262876930-e1540918005927-300x300.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Lan-Port-Icon-In-Outline-Style-262876930-e1540918005927.jpg 700w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<h2>Fixing SSL_ERROR_RX_RECORD_TOO_LONG for Regular Users<\/h2>\n<p>Now let\u2019s talk about what can be done from a user standpoint\u2026<\/p>\n<h2>Clear your Cache<\/h2>\n<p>In some rare cases, clearing or bypassing the cache can fix this issue. The easiest way to test this is to just open up an Incognito or Private Window and trying to access the website that way\u2014sans cache and cookies. In addition to going incognito, you can also use:<\/p>\n<ul>\n<li>Ctrl + Shift + R<\/li>\n<li>Shift + click Reload<\/li>\n<\/ul>\n<p>This probably won\u2019t work, but it might. At least it\u2019s not actively dangerous.<\/p>\n<h2>Change the security.tls.version.max preference<\/h2>\n<p>This is the point where we officially begin approaching the dangerous advice. Here\u2019s the thing, right now Microsoft has yet to roll out full support for TLS 1.3. So, if you\u2019re a Microsoft user, <a href=\"https:\/\/www.thesslstore.com\/blog\/tls-version-intolerance-pose-problem\/\">it might help to drop the TLS version support down by one<\/a>. It could be a case where a website supports TLS 1.3 and Firefox thinks it does, too. But the Operating System running Firefox can\u2019t and it creates the SSL_ERROR_RX_RECORD_TOO_LONG error.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-7838 size-medium\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/TLS-1.3-300x283.jpg\" alt=\"TLS 1.3\" width=\"300\" height=\"283\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/TLS-1.3-300x283.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/TLS-1.3.jpg 457w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>So, if you are a Microsoft user, and only if, you may want to drop support for TLS 1.3 temporarily. Here\u2019s how:<\/p>\n<ol>\n<li>Open a new tab and type \u201cabout:config\u201d into the address bar<\/li>\n<li>In the search field, type \u201cTLS\u201d and filter the list<\/li>\n<li>Double-click security.tld.version.max<\/li>\n<li>Change the 4 to a 3<\/li>\n<\/ol>\n<p>The way Firefox numbers its version support can be confusing. 1 is for TLS 1.0, so 4 is TLS 1.3 and 3 is TLS 1.2.<\/p>\n<p>I can\u2019t reiterate this enough, <strong>do not go further back than TLS 1.2<\/strong>.<\/p>\n<p>At this point TLS 1.2 has been out ten years, its successor has been published. There is almost no excuse for websites not to support at least 1.2. Previous TLS versions\u00a0 have known vulnerabilities.<\/p>\n<h2>Some other things that might fix SSL_ERROR_RX_RECORD_TOO_LONG but probably won\u2019t<\/h2>\n<p>Here are a few other pieces of non-dangerous advice that could potentially solve Firefox\u2019s SSL_ERROR_RX_RECORD_TOO_LONG message. They probably won\u2019t, because most of them don\u2019t actually deal with the source of the problem, but give them a try because who knows\u2026<\/p>\n<ul>\n<li><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-7834 size-medium\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-210378274-300x300.jpg\" alt=\"SSL_ERROR_RX_RECORD\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-210378274-300x300.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-210378274-768x768.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-210378274-1024x1024.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-210378274.jpg 1600w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>Try browsing in Incognito mode \u2013 We touched on this earlier, but sometimes this can fix the issue.<\/li>\n<li>Try using a VPN \u2013 Again, this could work in some situations but it\u2019s not a surefire solution by any means.<\/li>\n<li>Check your Proxy settings \u2013 Sometimes a misconfigured proxy can cause issues. Unless you\u2019re an IT admin, don\u2019t mess with yourself though. And don\u2019t disable the Proxy\u2014despite what some articles might suggest.<\/li>\n<li>Update your Browser \u2013 It shouldn\u2019t take getting a SSL_ERROR_RX_RECORD_TOO_LONG message to remind you to update your browser regularly, but if it did, start keeping up with updates moving forward.<\/li>\n<li>Reinstall your Browser \u2013 This could work, or it could waste ten minutes of your time.<\/li>\n<\/ul>\n<h2>What you definitely SHOULDN\u2019T do to fix SSL_ERROR_RX_RECORD_TOO_LONG<\/h2>\n<p>Now let\u2019s talk about some things that you definitely shouldn\u2019t do if you\u2019re an internet user dealing with the Firefox SSL_ERROR_RX_RECORD_TOO_LONG message. A lot of these are just bad advice, and even if they would work to solve your problem they would also open up a bunch of attack vectors. You almost have to ask yourself, is going to this site worth risking an infected computer or worse? The answer is almost always no.<\/p>\n<p>So here are a few suggestions of what NOT to do:<\/p>\n<h2>Don\u2019t switch to HTTP<\/h2>\n<p>There\u2019s a reason that <a href=\"https:\/\/www.thesslstore.com\/blog\/google-chrome-68-https-mandatory\/\">Google is twisting the entire internet\u2019s arm to get it to migrate to HTTPS<\/a>. HTTP has faithfully served the internet for about two decades, but it was never designed for secure transmission of data. HTTP was designed back in a time when commercial activity was banned and the internet was solely intended for sharing information between the government and academia. HTTPS was created out of necessity when commercial activity eventually did become part of the internet.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-7837 size-medium\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/HTTP-Icon-300x237.jpg\" alt=\"HTTP\" width=\"300\" height=\"237\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/HTTP-Icon-300x237.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/HTTP-Icon.jpg 654w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>Today, in 2018, it\u2019s the standard. The default. You should expect your communication with websites to be encrypted as a matter of course. <a href=\"https:\/\/www.auslogics.com\/en\/articles\/fix-ssl_error_rx_record_too_long-firefox-error\/\">So advice like this<\/a>\u2026<\/p>\n<blockquote><p>The quickest way to access the website that is being blocked by the irksome Secure Connection Failed message is to replace https:\/\/ with http:\/\/ at the beginning of the URL. This workaround has proved useful to many users, so you are free to give it a try.<\/p><\/blockquote>\n<p>\u2026is retrograde and needs to be called out. Not only is this bad advice in this very specific context, but teaching people that reverting back to HTTP is just bad for cybersecurity in general. The idea is that HTTPS should become so commonplace that it\u2019s an afterthought, it\u2019s not something that should be positioned as hindrance to visiting your favorite websites.<\/p>\n<p>Don\u2019t revert to HTTP. If this is the only way you can reach a website that\u2019s a sign right there.<\/p>\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n<h2>Don\u2019t Turn off your Antivirus<\/h2>\n<p>This is <a href=\"https:\/\/www.auslogics.com\/en\/articles\/fix-ssl_error_rx_record_too_long-firefox-error\/\">another piece of absolutely terrible advice<\/a>:<\/p>\n<blockquote><p>Unfortunately, some lines of action performed by powerful antivirus solutions may be a little too harsh. This might be your case since your security tool might have taken against certain SSL certificates or your Firefox on the whole. With that said, we believe you might need to temporarily disable your antivirus software and see if it is indeed the evil behind your issue.<\/p><\/blockquote>\n<p>No, no, no. First of all, if your antivirus is fighting with your Firefox browser, that\u2019s because it\u2019s misconfigured and you \u2013 or somebody with the wherewithal \u2013 should definitely look into that. But just turning it off is ridiculous advice. That would be like calling the security company because your house alarm goes off sometimes when you try to open your front door and being told, \u201cjust disable the alarm system. Problem solved.\u201d<\/p>\n<h2>If you\u2019re not a site owner, the best way to fix SSL_ERROR_RX_RECORD_TOO_LONG is to contact the site owner<\/h2>\n<p>The best advice I can give you, if you\u2019re not the site owner, is to respond to the Firefox SSL_ERROR_RX_RECORD_TOO_LONG by notifying the site owner. As we discussed, this is almost always a result of a server-side error and not something a regular internet user can fix.<\/p>\n<p>Either way, definitely don\u2019t disable your antivirus, turn TLS version support down to 0 or revert to HTTP.<\/p>\n<p><em>As always, leave any comments or questions below\u2026<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7276\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg\" alt=\"Hashed Out by The SSL Store is the voice of record in the SSL\/TLS industry.\" width=\"1559\" height=\"407\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg 1559w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-300x78.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-768x200.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg 1024w\" sizes=\"auto, (max-width: 1559px) 100vw, 1559px\" \/><\/p>\n<span style=\"--tl-form-height-m:801.312px;--tl-form-height-t:638.344px;--tl-form-height-d:638.344px;\" class=\"tl-placeholder-f-type-shortcode_12763 tl-preload-form\"><span><\/span><\/span>\n","protected":false},"excerpt":{"rendered":"<p>There\u2019s a lot of really bad advice on this, so be careful what you trust. In addition to my daily screeds on Hashed Out, I also tackle a range of&#8230;<\/p>\n","protected":false},"author":6,"featured_media":7833,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[9174],"class_list":["post-7832","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-ssl-errors","post-with-tags"],"views":482893,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Error-Page-Not-Found-Conce-243784411.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/7832","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=7832"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/7832\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/7833"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=7832"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=7832"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=7832"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}