Closed
Bug 1151990
Opened 8 years ago
Closed 7 years ago
https://www.openwebosproject.org/ only uses RC4 ciphersuites
Categories
(Web Compatibility :: Desktop, defect, P5)
Web Compatibility
Desktop
Tracking
(Not tracked)
RESOLVED
WORKSFORME
People
(Reporter: jrmuizel, Unassigned)
References
()
Details
This page works fine in Chrome.
Reporter | ||
Comment 1•8 years ago
|
||
I was also not able to find any to get more information about what was happening other than the error page containing ssl_error_no_cypher_overlap. Is there a way to get the offending certificate?
According to https://www.ssllabs.com/ssltest/analyze.html?d=openwebosproject.org that site only advertises a single RC4 ciphersuite. It also has SSL 3 enabled, which is insecure. It also neglects to send any intermediate certificates, which can mean clients won't find a path to a trusted root.
Blocks: RC4-Dependence
Component: Security → Desktop
Product: Firefox → Tech Evangelism
Summary: https://www.openwebosproject.org/ is blocked by Firefox → https://www.openwebosproject.org/ only uses RC4 ciphersuites
Reporter | ||
Comment 3•8 years ago
|
||
(In reply to David Keeler [:keeler] (use needinfo?) from comment #2) > According to > https://www.ssllabs.com/ssltest/analyze.html?d=openwebosproject.org that > site only advertises a single RC4 ciphersuite. It also has SSL 3 enabled, > which is insecure. It also neglects to send any intermediate certificates, > which can mean clients won't find a path to a trusted root. Do you know why Chrome still accepts the cert?
![]() |
||
Comment 4•8 years ago
|
||
(In reply to Jeff Muizelaar [:jrmuizel] from comment #3) > Do you know why Chrome still accepts the cert? I believe Chrome fetches intermediates based on cert AIA information, but I could be wrong.
Comment 6•8 years ago
|
||
Still expired. Seems nobody is maintaining or using this anyway, so low pri. We might even close it..
Severity: normal → trivial
Priority: -- → P5
Still no new cert. I'll close it for now.
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → WORKSFORME
Assignee | ||
Updated•4 years ago
|
Product: Tech Evangelism → Web Compatibility
You need to log in
before you can comment on or make changes to this bug.
Description
•