Closed
Bug 1095507
Opened 11 years ago
Closed 10 years ago
Cannot enter on Kredobank online banking page (www.kredodirect.com.ua), when TLS non-secure fallback is disabled
Categories
(Web Compatibility :: Site Reports, defect)
Web Compatibility
Site Reports
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: unghost, Unassigned)
References
()
Details
(Keywords: regression, Whiteboard: [country-ua] [ssl] [contactready])
Steps to reproduce:
go to https://www.kredodirect.com.ua/
Actual results:
An error occurred during a connection to www.kredodirect.com.ua. Cannot communicate securely with peer: no common encryption algorithm(s). (Error code: ssl_error_no_cypher_overlap)
Expected results:
Show web-page of bank
Reporter | ||
Comment 1•11 years ago
|
||
Kredobank's twitter is https://twitter.com/Kredobank_ua
Reporter | ||
Updated•11 years ago
|
Summary: Cannot enter on www.kredodirect.com.ua bank when SSLv3 is disabled → Cannot enter on Kredobank online banking page (www.kredodirect.com.ua), when SSLv3 is disabled
![]() |
||
Updated•11 years ago
|
Whiteboard: [country-ua] [ssl] → [country-ua] [ssl] [contactready]
Updated•11 years ago
|
Summary: Cannot enter on Kredobank online banking page (www.kredodirect.com.ua), when SSLv3 is disabled → Cannot enter on Kredobank online banking page (www.kredodirect.com.ua), when SSLv3 or TLS non-secure fallback is disabled
Comment 3•11 years ago
|
||
https://www.ssllabs.com/ssltest/analyze.html?d=www.kredodirect.com.ua
Server is SSL3 only & 3DES only. It's insecure and incompatible with about half of the clients listed in SSL Labs' test.
Comment 4•11 years ago
|
||
Now uses TLS 1.0, but still is TLS version intolerant.
Reporter | ||
Updated•11 years ago
|
Summary: Cannot enter on Kredobank online banking page (www.kredodirect.com.ua), when SSLv3 or TLS non-secure fallback is disabled → Cannot enter on Kredobank online banking page (www.kredodirect.com.ua), when TLS non-secure fallback is disabled
Reporter | ||
Updated•11 years ago
|
Updated•11 years ago
|
Blocks: TLS-Intolerance
Comment 5•11 years ago
|
||
Minor mass change for dependencies of bug 1126620.
(filter on {bf0YGqIfJDgVDlKn3zYc})
As of bug 1114816, these sites are now whitelisted to allow for insecure fallback due to TLS version intolerance. Whilst these sites should now work with the patch applied, these bugs themselves are not actually FIXED until the server is. Moving all of these into the TE product for tracking.
Version: unspecified → Trunk
Comment 6•10 years ago
|
||
This appears to be fixed.
![]() |
||
Updated•10 years ago
|
Status: NEW → RESOLVED
Closed: 10 years ago
Resolution: --- → FIXED
Assignee | ||
Updated•7 years ago
|
Product: Tech Evangelism → Web Compatibility
You need to log in
before you can comment on or make changes to this bug.
Description
•