diff --git a/core/java/src/net/i2p/util/I2PSSLSocketFactory.java b/core/java/src/net/i2p/util/I2PSSLSocketFactory.java
index 4761ac710..774415f4d 100644
--- a/core/java/src/net/i2p/util/I2PSSLSocketFactory.java
+++ b/core/java/src/net/i2p/util/I2PSSLSocketFactory.java
@@ -204,7 +204,15 @@ public class I2PSSLSocketFactory {
"TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA",
"TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA",
"TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA",
- "TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA"
+ "TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA",
+ // following is disabled because it is weak
+ // see e.g. https://bugzilla.mozilla.org/show_bug.cgi?id=1107787
+ "TLS_DHE_DSS_WITH_AES_128_CBC_SHA"
+ // ??? "TLS_DHE_DSS_WITH_AES_256_CBC_SHA"
+ //
+ // NOTE:
+ // If you add anything here, please also add to installer/resources/eepsite/jetty-ssl.xml
+ //
}));
/**
diff --git a/installer/resources/eepsite/jetty-ssl.xml b/installer/resources/eepsite/jetty-ssl.xml
index 7562828cc..b14ca0976 100644
--- a/installer/resources/eepsite/jetty-ssl.xml
+++ b/installer/resources/eepsite/jetty-ssl.xml
@@ -248,6 +248,8 @@
- TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA
- TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA
- TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA
+ - TLS_DHE_DSS_WITH_AES_128_CBC_SHA
+