150520.16:12+0400 freenode -- : irc: connecting to server chat.freenode.net/7000 (SSL)... 150520.16:12+0400 freenode -- : gnutls: connected using 2048-bit Diffie-Hellman shared secret exchange 150520.16:12+0400 freenode -- : gnutls: receiving 2 certificates 150520.16:12+0400 freenode -- : - certificate[1] info: 150520.16:12+0400 freenode -- : - subject `OU=Domain Control Validated,OU=Gandi Standard Wildcard SSL,CN=*.freenode.net', issuer `C=FR,O=GANDI SAS,CN=Gandi Standard SSL CA', RSA key 2048 : bits, signed using RSA-SHA1, activated `2015-01-03 00:00:00 UTC', expires `2016-01-15 23:59:59 UTC', SHA-1 fingerprint `1beef688a9641fdfd511282b668be200320a317b' 150520.16:12+0400 freenode -- : - certificate[2] info: 150520.16:12+0400 freenode -- : - subject `C=FR,O=GANDI SAS,CN=Gandi Standard SSL CA', issuer `C=US,ST=UT,L=Salt Lake City,O=The USERTRUST : Network,OU=http://www.usertrust.com,CN=UTN-USERFirst-Hardware', RSA key 2048 bits, signed using RSA-SHA1, activated `2008-10-23 00:00:00 UTC', expires : `2020-05-30 10:48:38 UTC', SHA-1 fingerprint `a9f79883a075ce82d20d274d1368e876140d33b3' 150520.16:12+0400 freenode -- : gnutls: peer's certificate is trusted 150520.16:12+0400 freenode =!= : irc: TLS handshake failed 150520.16:12+0400 freenode =!= : irc: error: The Diffie-Hellman prime sent by the server is not acceptable (not long enough). 150520.16:12+0400 freenode =!= : irc: you should play with option irc.server.freenode.ssl_dhkey_size (current value is 2048, try a lower value like 1024 or 512) 150520.16:12+0400 freenode -- : irc: reconnecting to server in 10 seconds