Open
Bug 1151376
Opened 11 years ago
Updated 10 years ago
adding SSL certificate exception does not work
Categories
(SeaMonkey :: General, defect)
Tracking
(Not tracked)
UNCONFIRMED
People
(Reporter: alana, Unassigned)
Details
Attachments
(3 files)
User Agent: Mozilla/5.0 (Windows NT 5.1; rv:36.0) Gecko/20100101 Firefox/36.0 SeaMonkey/2.33.1
Build ID: 20150321194901
Steps to reproduce:
attempt to add SSL certificate exception after any SSL error [tried for self signed certificate, certificate for different domain name than used in cert]
Actual results:
"get certificate" button does not do anything as if mozilla could not get certificate info and other buttons are grayed out [pic attached], problem exists both in www and mail and newsgroups component
Expected results:
adding SSL security exception worked fine in version 2.24
I had exactly the same problem in firefox starting with version 37.0.1 and also still in 37.0.2
The page I trying to access is our internal Watchguard Spam Quarantine Server.
IE let me load the site after displaying a warning.
The difference (for my case, shown by IE) to other intranet sites with self signed certificates (where the certificate is invalid) is, that the WatchGuard certificat IS indeed valid, but cannot verified against its Root CA, because the Root CA is not stored als trusted CA certificate.
Hope this info helps to find the problem.
Screenshot from IE showing the certificate chain of our WatchGuard Quarantine server. In firefox it is not possible to add an exception.
Screenshot from IE showing the certificate chain of an other Intranet server with self signed certificate. In firefox it IS possible to add an exception.
I think the bug should be flagged as confirmed.
I'm getting the same problem with my email accounts (they use SSL/TLS at port 995) after the certificate of the mail server expired. Hosting company renew it but even after that the override certificate window keeps on poping up with the "No info available" messages and greyed buttons that Alana explained when opened this bug.
I'm using Seamonkey 2.33.1 on Ubuntu.
TESTS DONE:
1) I've configured a new account for that server with Thunbird and the bug was not present.
2) I've added that same new account to Seamonkey, and the bug appears.
It seems that the bug is fired after a SSL error happens, maybe only with self-signed certificates.
HINTS:
Bugs possibly related?
https://bugzilla.mozilla.org/show_bug.cgi?id=533744
https://bugzilla.mozilla.org/show_bug.cgi?id=403220
Another test done, following this workaround http://forums.mozillazine.org/viewtopic.php?f=38&t=1160375&start=0&st=0&sk=t&sd=a
cert_override.txt renamed (instead of deleting it)
Result of the test: no changes, bug still present.
cert_override.txt renamed (instead of deleting it)
cert8.db renamed (instead of deleting it)
Result of the test: no changes, bug still present.
Same problem here - TB 38.1.0 in Windows 8.1 and BitDefender Antivirus 2015 with SSL scanning activated, which injects an invalid certificate (MITM scan).
The problem only occurs with gmail mailservers and everything was fine until around the beginning of July.
Prior to that, the warning about the invalid gmail cert due to Bitdefender interception popped up, but chosing to store the exception permanently once would fix the problem for a few weeks (presumably until something in the certificate changed).
Now, I get the warning all the time, pretty much any time I haven't checked emails for an hour or so...
The exceptions seem to be stored in the TB certificate store as far as I can tell, but the dialog still keeps popping up every time.
Other servers (both IMAP and POP) are not affected although they are being scanned the same way.
Comment 7•10 years ago
|
||
Please test with the latest release SeaMonkey 2.35
Flags: needinfo?(philip.chee)
works with my debian wheezy server but crashes ssl/tls connection completely to my debian jessie server
Updated•10 years ago
|
Flags: needinfo?(philip.chee)
You need to log in
before you can comment on or make changes to this bug.
Description
•