Sonos: incomplete TLS handshake: no shared cipher

Server Version#: 1.25.3.5409 (docker)
Sonos Version#: S1 11.2.13

My issue is the same as the ones shown in these threads:

Starting yesterday (right after Plex updated to 1.25.3.5385) I am getting a message in the Plex log like this whenever I try to play something from Plex via Sonos:
CERT: incomplete TLS handshake from [::ffff:192.168.2.254]:41209 no shared cipher

Disabling TLS on the Plex server works, but I would prefer not to leave that off. Does anyone have any other ideas? There was a comment in an old thread about Plex changing certificates to be RSA based, but I don’t know what ever happened with that. @johnclayton Any update on that?

I updated the Plex container to 1.25.3.5409 this morning, but unfortunately that didn’t seem to help. I have an old Play:5 Gen 1 so I can’t switch to the Sonos S2 app.

Something else I just noticed when digging through my logs. It looks like the port requested in the error message is random and changes for each request. Is that expected? I noticed it’s not the 32400 that’s required to be open for remote access to work.

The IP address appears to be the IPv6 version of my gateway’s IP.

In your server settings, Network, make sure that Strict TLS configuration is disabled. If that doesn’t do the trick after restarting PMS we’ll probably have to wait and see if @vanstinator has any input.

Yes, I know that disabling TLS will make it work. I just don’t feel that “turn off the security” is an acceptable solution.

This isn’t turning off security. Hell, I don’t even allow non-secure connections for my parents’ crappy old “smart” TVs. This just allows a more permissive secure connections for clients that don’t support current standards. IIRC Sonos and some other clients were the reason this setting was added.

More info on it here.

Ah, I thought you were referring to changing Secure Connections to “Preferred” or “Disabled”. Disabling “Strict TLS configuration” doesn’t let Sonos work, same errors as I posted above.

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.