Re: Certificate exception for github.com not working with built-in root CAs removed
David Keeler <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
HSTS is most likely the issue. If the browser notes a site as HSTS and later encounters an error when attempting to verify the site's certificate (such as not being able to find a trusted issuer), the spec mandates that the connection not be allowed. See https://tools.ietf.org/html/rfc6797#section-12.1 Cheers, David On 09/08/2015 01:46 PM, [email protected] wrote: > Hello everybody, > > I'm seeing following issue on current releases of both, Firefox and > Thunderbird: If one removes all built-in root CAs in the Certificate > Manager and adds a server exception for github.com, no connection is > possible (Error code: sec_error_unknown_issuer). > > While other servers, e.g., www.joomla.org, www.auswaertiges-amt.de can > be connected to without problems. What can be seen on > https://www.ssllabs.com/ssltest/analyze.html?d=github.com is that it > supports HSTS, while the two working above don't. Could there be an > issue with that here? > > Many more details on https://bugzilla.mozilla.org/show_bug.cgi?id=1202511 > > Best, > > Joe > _______________________________________________ > dev-security mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-security _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security
signature.asc
(application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJV70t7AAoJEJBTbq/bQjV9IQ0QAMy89PdjUaLyF+GDWnGcj/TW Lfg/7iUbi8tkTsoaNsxAnjuwi8gGdkyFRLyxxh/9f6N9GaBOux/OWNLqt1iJeppk p5yzEuqUcCzfTEYU3fNiE9wiFRHQxV0TEiqL7flv1KvUAw2jKtvbpy59gXiql7FT /mRSqEMtDzGRCvaVdCUQIT4mRi4kzXqXD3VguQhs2XQBge0El4wRLaULg9Y0KxyK iTAMJBMQPqsUgNPeRg43besU255dhQ6ve+B+DiwRZGeCUZYKi53Aix6o4PxbCNsX 6CIZEWIcfhbYp86sz2M3m+CgFELghoQZJWuJqgkLf8OO4sPLtCOihMCveloSW7KA 9McEmJiFggiRcHy8tfXOa55JYcY1C8x0rmVdE1JL/nI4lcUYI8pZmk1DDfFZT5CL N4FP/UTxamsgJNVBuH7ih1x4zFw5qdRQQNvhxrhkP5CjqKJ3U4G6CHfZzcbQWgZK s+NxEIXbYpMmokUhcoQJ7Wze1+NHWUmAh/QrknHZuW/3CoG/YHk7l3BwwunTHVN5 Ww+cIOu1WQ6tHn58KlC+2NI5pPqvd6saIkOXyREhemQvdx22nCaAENe1q9v4lZuA ajXXF98G2KDWWi2Sbwr7QxO+acjtsz50Jbr/vVU1VtpnZ8TC3M2RWNKEfTXgKVIj ssikzxQlG0GDYMiUdriO =rzW0 -----END PGP SIGNATURE-----