# Huawei HG8245W5 SSL handshake failure

**URL:** <https://forum.genieacs.com/t/huawei-hg8245w5-ssl-handshake-failure/4126>\
**Category:** Uncategorized\
**Created:** [June 27, 2023, 6:43am UTC](https://forum.genieacs.com/t/huawei-hg8245w5-ssl-handshake-failure/4126 "2023-06-27T06:43:00Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![akcoder](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.genieacs.com/akcoder/32/11_2.png) [@akcoder](https://forum.genieacs.com/u/akcoder)\
**Post date:** [June 27, 2023, 4:16pm UTC](https://forum.genieacs.com/t/huawei-hg8245w5-ssl-handshake-failure/4126/2 "2023-06-27T16:16:58Z")

</div>

> [@husain](#):
>
> no shared cipher

This right there tells you what the issue is. The NodeJS server (and the ha proxy) do not have a cipher that overlaps with what the Huawei can do. So you will either need to add a bunch of old and insecure ciphers, upgrade the firmware on the CPE to support newer/better cipher suites, or trick the box to switching to http.

If the cpe gets an IP via DHCP you can try and see if DHCP option 43 is enabled in the CPE. DHCP option 43 allows you to send the ACS URL via DHCP.

> [@Huawei ONU + DHCP Option 43](https://forum.genieacs.com/t/huawei-onu-dhcp-option-43/3298):
>
> Good day, Has anyone from you guys know the the HEX values to be encoded in DHCP to provide the ACS URL to ONU + the ACS credential, we were able to figure out to send the ACS url but not the username and password, thanks in advance The full URL needs to be converted to hex so [http://10.10.25.6:7457](http://10.10.25.6:7457/) becomes 68 74 74 70 3a 2f 2f 31 30 2e 31 30 2e 32 35 2e 36 3a 37 35 34 37 That’s 22 bytes and for Option 43 it’s Code 1, so I needed to add the hex for “1” (01) and “22” (16) in front of the str…

---

_[View the full topic](https://forum.genieacs.com/t/huawei-hg8245w5-ssl-handshake-failure/4126)._
