Closed Bug 1217902 Opened 9 years ago Closed 7 years ago

Show "Could not verify this certificate because the issuer is unknown." in Certificate Viewer

Categories

(Core :: Security: PSM, defect)

41 Branch
x86
Windows 7
defect
Not set
normal

Tracking

()

RESOLVED WORKSFORME

People

(Reporter: super.dukefb1, Unassigned)

Details

(Whiteboard: [psm-backlog])

User Agent: Mozilla/5.0 (Windows NT 6.1; rv:41.0) Gecko/20100101 Firefox/41.0
Build ID: 20151014143721

Steps to reproduce:

Visit https://wikidevi.com/wiki/Main_Page
Then open the Certificate Viewer dialog.


Actual results:

The page shown correctly but the Certificate Viewer shows "Could not verify this certificate because the issuer is unknown." and only the server certificate shows in the Certificate Hierarchy.

I use "openssl s_client -showcerts -connect wikidevi.com:https" to dump the certificates and it lists 1 server certificate and 3 intermediate CA certificates. I also go to the https://www.sslshopper.com/ to check the site, it found the same result as openssl. I also learned that the final root CA certificate is "AddTrust External CA Root" is the built-in certificate in firefox. Below is the dump of the openssl command:

CONNECTED(00000003)
depth=4 C = SE, O = AddTrust AB, OU = AddTrust External TTP Network, CN = AddTrust External CA Root
verify return:1
depth=3 C = US, ST = UT, L = Salt Lake City, O = The USERTRUST Network, OU = http://www.usertrust.com, CN = UTN - DATACorp SGC
verify return:1
depth=2 C = GB, ST = Greater Manchester, L = Salford, O = COMODO CA Limited, CN = COMODO Certification Authority
verify return:1
depth=1 C = GB, ST = Greater Manchester, L = Salford, O = COMODO CA Limited, CN = EssentialSSL CA
verify return:1
depth=0 OU = Domain Control Validated, OU = EssentialSSL, CN = wikidevi.com
verify return:1
---
Certificate chain
 0 s:/OU=Domain Control Validated/OU=EssentialSSL/CN=wikidevi.com
   i:/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=EssentialSSL CA
-----BEGIN CERTIFICATE-----
MIIFEDCCA/igAwIBAgIQMVpyN8gORMewkk8sCt1FfjANBgkqhkiG9w0BAQUFADBy
MQswCQYDVQQGEwJHQjEbMBkGA1UECBMSR3JlYXRlciBNYW5jaGVzdGVyMRAwDgYD
VQQHEwdTYWxmb3JkMRowGAYDVQQKExFDT01PRE8gQ0EgTGltaXRlZDEYMBYGA1UE
AxMPRXNzZW50aWFsU1NMIENBMB4XDTE0MDEyODAwMDAwMFoXDTE2MDEyODIzNTk1
OVowUTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRUwEwYDVQQL
EwxFc3NlbnRpYWxTU0wxFTATBgNVBAMTDHdpa2lkZXZpLmNvbTCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAO8yGcem6GqlnpTxt4ihUx/TzUnp3vkKIiYP
TaWFr2WwrvvCR2CL9DH79k2w0MIkDxvKshpzYZr4kJEJxhL2RdvAwdhCy1RFzAa8
Mwkvc7wsEvrAtSz0a3Pau6ytFulGOTTu7t1/O/hre6194HN/6zCCjYyMbOh5P4Me
/zNMrdG9hu41c3BPWkv9faS+4h7GieF3Gi2N2uq86udrr98OWgx/CjjCG7BxwxwF
PZ1Nmps6HGsscQ3Cbv9FIJmQNfdt+cpV1Ij8MBPzXub1AJWlvTP5p7DJ22E+y6U/
4yQOECJMyc9zdjOI6yhZGSzygxaAtDLYWOagKZMwpB1IAhXmYWkCAwEAAaOCAcEw
ggG9MB8GA1UdIwQYMBaAFNrL6q1bCF3M//wmVM5J5VXGOPT4MB0GA1UdDgQWBBTe
RZp1bta1Uzq/m+ZWeS2jNEYJgzAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIw
ADA0BgNVHSUELTArBggrBgEFBQcDAQYIKwYBBQUHAwIGCisGAQQBgjcKAwMGCWCG
SAGG+EIEATBPBgNVHSAESDBGMDoGCysGAQQBsjEBAgIHMCswKQYIKwYBBQUHAgEW
HWh0dHBzOi8vc2VjdXJlLmNvbW9kby5jb20vQ1BTMAgGBmeBDAECATA7BgNVHR8E
NDAyMDCgLqAshipodHRwOi8vY3JsLmNvbW9kb2NhLmNvbS9Fc3NlbnRpYWxTU0xD
QS5jcmwwbgYIKwYBBQUHAQEEYjBgMDgGCCsGAQUFBzAChixodHRwOi8vY3J0LmNv
bW9kb2NhLmNvbS9Fc3NlbnRpYWxTU0xDQV8yLmNydDAkBggrBgEFBQcwAYYYaHR0
cDovL29jc3AuY29tb2RvY2EuY29tMCkGA1UdEQQiMCCCDHdpa2lkZXZpLmNvbYIQ
d3d3Lndpa2lkZXZpLmNvbTANBgkqhkiG9w0BAQUFAAOCAQEAn/zJKxNjMIyHrbx2
mbVMIfotzto0+Nf2WFitY9BbDsiwfEEhGOjZesu19XtGVIV6fCfH/5gpqAYIdnTy
Hq/vBSgHiPs/8Mex7E5niipMiBQy9cfoNnlo40it5f2iOyj+stmMUPklPmHe8jpf
F5HmESiiczxj/FklbxIrNoMZyJizlWkNoSQB/hXfPS0fRysGYW9osIevnwlw5QiA
I6FwDBQCPnZNdEtKfs1MGn8pPslqHm2rLavSyN6vSeit0ZxNWGeTVe3F41hKNYqO
JGoejW9xpsWHEJ+pNiZN/1wm0mOevGyMVjDvU/V6d6ChG0XAEu3qv8Me8VMHtFKw
RBH0JQ==
-----END CERTIFICATE-----
 1 s:/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=EssentialSSL CA
   i:/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO Certification Authority
-----BEGIN CERTIFICATE-----
MIIFAzCCA+ugAwIBAgIQGLLLuqME8aAPwfLzJkYqSjANBgkqhkiG9w0BAQUFADCB
gTELMAkGA1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4G
A1UEBxMHU2FsZm9yZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxJzAlBgNV
BAMTHkNPTU9ETyBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNjEyMDEwMDAw
MDBaFw0xOTEyMzEyMzU5NTlaMHIxCzAJBgNVBAYTAkdCMRswGQYDVQQIExJHcmVh
dGVyIE1hbmNoZXN0ZXIxEDAOBgNVBAcTB1NhbGZvcmQxGjAYBgNVBAoTEUNPTU9E
TyBDQSBMaW1pdGVkMRgwFgYDVQQDEw9Fc3NlbnRpYWxTU0wgQ0EwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQCt8AiwcsargxIxF3CJhakgEtSYau2A1NHf
5I5ZLdOWIY120j8YC0YZYwvHIPPlC92AGvFaoL0dds23Izp0XmEbdaqb1IX04XiR
0y3hr/yYLgbSeT1awB8hLRyuIVPGOqchfr7tZ291HRqfalsGs2rjsQuqag7nbWzD
ypWMN84hHzWQfdvaGlyoiBSyD8gSIF/F03/o4Tjg27z5H6Gq1huQByH6RSRQXScq
oChBRVt9vKCiL6qbfltTxfEFFld+Edc7tNkBdtzffRDPUanlOPJ7FAB1WfnwWdsX
Pvev5gItpHnBXaIcw5rIp6gLSApqLn8tl2X2xQScRMiZln5+pN0vAgMBAAGjggGD
MIIBfzAfBgNVHSMEGDAWgBQLWOWLxkwVN6RAqTCpIb5HNlpW/zAdBgNVHQ4EFgQU
2svqrVsIXcz//CZUzknlVcY49PgwDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQI
MAYBAf8CAQAwIAYDVR0lBBkwFwYKKwYBBAGCNwoDAwYJYIZIAYb4QgQBMD4GA1Ud
IAQ3MDUwMwYEVR0gADArMCkGCCsGAQUFBwIBFh1odHRwczovL3NlY3VyZS5jb21v
ZG8uY29tL0NQUzBJBgNVHR8EQjBAMD6gPKA6hjhodHRwOi8vY3JsLmNvbW9kb2Nh
LmNvbS9DT01PRE9DZXJ0aWZpY2F0aW9uQXV0aG9yaXR5LmNybDBsBggrBgEFBQcB
AQRgMF4wNgYIKwYBBQUHMAKGKmh0dHA6Ly9jcnQuY29tb2RvY2EuY29tL0NvbW9k
b1VUTlNHQ0NBLmNydDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuY29tb2RvY2Eu
Y29tMA0GCSqGSIb3DQEBBQUAA4IBAQAtlzR6QDLqcJcvgTtLeRJ3rvuq1xqo2l/z
odueTZbLN3qo6u6bldudu+Ennv1F7Q5Slqz0J790qpL0pcRDAB8OtXj5isWMcL2a
ejGjKdBZa0wztSz4iw+SY1dWrCRnilsvKcKxudokxeRiDn55w/65g+onO7wdQ7Vu
F6r7yJiIatnyfKH2cboZT7g440LX8NqxwCPf3dfxp+0Jj1agq8MLy6SSgIGSH6lv
+Wwz3D5XxqfyH8wqfOQsTEZf6/Nh9yvENZ+NWPU6g0QO2JOsTGvMd/QDzczc4BxL
XSXaPV7Od4rhPsbXlM1wSTz/Dr0ISKvlUhQVnQ6cGodWaK2cCQBk
-----END CERTIFICATE-----
 2 s:/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO Certification Authority
   i:/C=US/ST=UT/L=Salt Lake City/O=The USERTRUST Network/OU=http://www.usertrust.com/CN=UTN - DATACorp SGC
-----BEGIN CERTIFICATE-----
MIIEqzCCA5OgAwIBAgIQLnmDLpCIh+qLjvMabuZ6RDANBgkqhkiG9w0BAQUFADCB
kzELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAlVUMRcwFQYDVQQHEw5TYWx0IExha2Ug
Q2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3JrMSEwHwYDVQQLExho
dHRwOi8vd3d3LnVzZXJ0cnVzdC5jb20xGzAZBgNVBAMTElVUTiAtIERBVEFDb3Jw
IFNHQzAeFw0wNjEyMDEwMDAwMDBaFw0yMDA1MzAxMDQ4MzhaMIGBMQswCQYDVQQG
EwJHQjEbMBkGA1UECBMSR3JlYXRlciBNYW5jaGVzdGVyMRAwDgYDVQQHEwdTYWxm
b3JkMRowGAYDVQQKExFDT01PRE8gQ0EgTGltaXRlZDEnMCUGA1UEAxMeQ09NT0RP
IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA0ECLi3LjkRv3UcEbVASY06m/weaKXTuH+7uIzg3jLz8GlvCiKVCZ
rts7oVewdFFxze1CkU1B/qnI2GqGd0S7WWaXUF601CxwRM/aN5VCaTwwxHGzUvAh
TaHYujl8HJ6jJJ3ygxaYqhZ8Q5sVW7euNJH+1GImGEaaP+vB+fGQV+useg2L23Iw
ambV4EajcNxo2f8ESIl33rXp+2dtQem8Ob0y2WIC8bGoPW43nOIv4tOiJovGuFVD
iOEjPqXSJDlqR6sA1KGzqSX+DT+nHbrTUcELpNqsOO9VUCQFZUaTNE8tja3G1CEZ
0o7KBWFxB3NH5YoZEr0ETc5OnKVIrLsm9wIDAQABo4IBCTCCAQUwHwYDVR0jBBgw
FoAUUzLRs89/+uDxoF2FTpLSnkUdtE8wHQYDVR0OBBYEFAtY5YvGTBU3pECpMKkh
vkc2Wlb/MA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MCAGA1UdJQQZ
MBcGCisGAQQBgjcKAwMGCWCGSAGG+EIEATARBgNVHSAECjAIMAYGBFUdIAAwbQYD
VR0fBGYwZDAxoC+gLYYraHR0cDovL2NybC5jb21vZG9jYS5jb20vVVROLURBVEFD
b3JwU0dDLmNybDAvoC2gK4YpaHR0cDovL2NybC5jb21vZG8ubmV0L1VUTi1EQVRB
Q29ycFNHQy5jcmwwDQYJKoZIhvcNAQEFBQADggEBANheksSuFNxDrcKkw2dFBx35
N6IZxxw3NZETHAfEfUKmDvCGXENrDkTPviRhOkKpzp1Mr3k5cN0OBCBOlZw83rdg
umNDQO1qD4FJRrsek8BL8/jhNkkbb7YMDfKQV4r8bZPyKMf6hgoosxcOWYoutr/N
4axMZmzyVZFWtzK/seR9teg6ti/bspzaUJOOTsWsmn5cnhI8O03GUHCzZSuO92uh
uyXAALv17BZlgQ771KMhlneaqHS8U6rCOVD/CwIJYcyVt9eIavZcxWjTFJUaR1/Z
+y3kL48ThqsxE0ATrG7ttRAwixtQqc7ujMrrfLW5Fj3U+m+SbR6ivfsCSsVwvvE=
-----END CERTIFICATE-----
 3 s:/C=US/ST=UT/L=Salt Lake City/O=The USERTRUST Network/OU=http://www.usertrust.com/CN=UTN - DATACorp SGC
   i:/C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root
-----BEGIN CERTIFICATE-----
MIIEpjCCA46gAwIBAgIQRurwlgVMxeP6Zepun0LGZDANBgkqhkiG9w0BAQUFADBv
MQswCQYDVQQGEwJTRTEUMBIGA1UEChMLQWRkVHJ1c3QgQUIxJjAkBgNVBAsTHUFk
ZFRydXN0IEV4dGVybmFsIFRUUCBOZXR3b3JrMSIwIAYDVQQDExlBZGRUcnVzdCBF
eHRlcm5hbCBDQSBSb290MB4XDTA1MDYwNzA4MDkxMFoXDTIwMDUzMDEwNDgzOFow
gZMxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJVVDEXMBUGA1UEBxMOU2FsdCBMYWtl
IENpdHkxHjAcBgNVBAoTFVRoZSBVU0VSVFJVU1QgTmV0d29yazEhMB8GA1UECxMY
aHR0cDovL3d3dy51c2VydHJ1c3QuY29tMRswGQYDVQQDExJVVE4gLSBEQVRBQ29y
cCBTR0MwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDf7lgQoituVcSO
vy5GCefgCA8uK3oTlBu99raAjmUFkwAevK/iD44ZDRJH7Kyto/oucPjebvtWQhWe
LlzvI94huQV2JxkPT9bDnLS+lBlj8qYRCutTSJy+8ik7FugaoEymyfQYWWjAcPJT
AMBeUIKlVm82+UrgRIagTU7WR25JSstn16bEBbmOHvT8/83nNuCcBWyyMyIV0LTg
zBfAssD0/jI/KSqVe9jyp04PVHyhDYCzCQPB/1zdXpo+vK68R4pqrnHKH7EquF9C
BQvsRjDRcgvK6VZt9e/feL5hurKlrgRMvKisaRWXve/rtIy/NfjUw9EoDlw6n3AY
MyB3xKKvAgMBAAGjggEXMIIBEzAfBgNVHSMEGDAWgBStvZh6NLQm9/rEJlTvA73g
JMtUGjAdBgNVHQ4EFgQUUzLRs89/+uDxoF2FTpLSnkUdtE8wDgYDVR0PAQH/BAQD
AgEGMA8GA1UdEwEB/wQFMAMBAf8wIAYDVR0lBBkwFwYKKwYBBAGCNwoDAwYJYIZI
AYb4QgQBMBEGA1UdIAQKMAgwBgYEVR0gADB7BgNVHR8EdDByMDigNqA0hjJodHRw
Oi8vY3JsLmNvbW9kb2NhLmNvbS9BZGRUcnVzdEV4dGVybmFsQ0FSb290LmNybDA2
oDSgMoYwaHR0cDovL2NybC5jb21vZG8ubmV0L0FkZFRydXN0RXh0ZXJuYWxDQVJv
b3QuY3JsMA0GCSqGSIb3DQEBBQUAA4IBAQBjhpIQsRP6N76OKrYbikP1XK4OFN/3
aUB/vxpxAAnYv9QkSr/gk/8B2AvGD+x+R5ywXfd8FJ38wDOShFvSg/RS4iJYdPxD
Gz+no1jaA/288Drk7cwSu8m5rnsEoARyv+neLdKnUWYAc9K9fqqeU5Z9abIYPo6t
VlB+99Ww/zliZYKMllfDj/dg9sKNNIf8T0Pl278cqvaGzebfET+NB/dtgxPAOIg5
YKF+MOHjiD6ku2NvLOmKaCzulmmsBGHhT04OnXJM9nk4yMdIaW+UD3S0vMjPV025
dXGWDYoGC+vd0PA8fcYumEZqOMcCtci4smV13tqQCLZ3uFMAJctHynNf
-----END CERTIFICATE-----
---
Server certificate
subject=/OU=Domain Control Validated/OU=EssentialSSL/CN=wikidevi.com
issuer=/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=EssentialSSL CA
---
No client certificate CA names sent
Peer signing digest: SHA512
Server Temp Key: ECDH, P-256, 256 bits
---
SSL handshake has read 5648 bytes and written 444 bytes
---
New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES256-GCM-SHA384
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol  : TLSv1.2
    Cipher    : ECDHE-RSA-AES256-GCM-SHA384
    Session-ID: DD980DB0EA3ECAEA356483CDC1A883986E7CAF2B79A42E661ADE886377010F48
    Session-ID-ctx:
    Master-Key: C9C42FFA4D4CD2E07C2792DE00EB0594FFE1A26C7F3D4DD2BC4F2EBE33D41BE9F76FA7EA5BC021FD84F8F118F2E416C2
    Key-Arg   : None
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 300 (seconds)
    TLS session ticket:
    0000 - 48 4f f1 1e e2 9a 11 29-53 3e 45 11 18 91 18 8c   HO.....)S>E.....
    0010 - 02 97 a2 89 08 be b3 38-54 d5 b8 99 1d bf bd 53   .......8T......S
    0020 - 39 0a 13 7c 12 fa 13 5f-e9 44 b0 93 67 5c 0f 98   9..|..._.D..g\..
    0030 - c8 a6 1e 98 cd c5 9b c2-60 9d 21 c7 7a cc 44 f2   ........`.!.z.D.
    0040 - 72 cb 16 a2 8d 67 55 5b-72 bd 92 59 af d8 46 4f   r....gU[r..Y..FO
    0050 - fd 2a c1 a2 c1 af aa c2-c6 61 55 73 61 9b 52 ed   .*.......aUsa.R.
    0060 - 5d 06 b1 b8 67 63 d8 b3-95 e1 fa dc b8 a1 c1 44   ]...gc.........D
    0070 - 87 80 b9 d4 b0 99 40 5f-f8 67 4c 62 92 fd ce 5d   ......@_.gLb...]
    0080 - 59 1e 96 e1 8c e4 c1 41-51 57 59 52 43 15 87 69   Y......AQWYRC..i
    0090 - ef 43 61 77 47 90 29 8c-43 9b 9f 2d 85 03 97 3c   .CawG.).C..-...<

    Start Time: 1445613942
    Timeout   : 300 (sec)
    Verify return code: 0 (ok)
---



Expected results:

The Certificate Viewer should not show "Could not verify this certificate because the issuer is unknown." and the Certificate Hierarchy should list complete certificate chain.
OS: Unspecified → Windows 7
Hardware: Unspecified → x86
Component: Untriaged → Security
What happens if you visit the site with a new profile?
Flags: needinfo?(super.dukefb1)
I found the problem may relate to the Private Mode. Below is my trials
1. Same profile with Private Mode, the problem occured.
2. Same profile with normal mode, no problem (*)
3. New profile with Private Mode, the problem occured.
4. New profile with normal mode, no problem (*)

(*) But firefox displays only 3 certificates in the Certificate Hierarchy:
COMODO Certificate Authority (Certificate Fields displays Builtin Object Token:COMODO Certi...)
  EssentialSSL CA (Certificate Fields no refresh the content)
    wikidevi.com (Certificate Fields displays wikidevi.com)

So, maybe there are another 2 problems
i. Firefox should completely display 5 certificates in the Certificate Hierarchy.
ii. Firefox should display the details for EssentialSSL CA in the Certificate Fields.
Flags: needinfo?(super.dukefb1)
I have additional information and correct one point of previous post.

Once I visited the site in normal mode, the Software Security Devices "EssentialSSL CA" and "DigiCert SHA2 Extended Validation Server CA" will be installed in the Authorities of the Certificate Manager. And then when I use Privete Mode to visit the site, it will be normal.

In the previous post, in the normal mode, it's no problem in the EssentialSSL CA's Certificate Fields. But the problem is that after I removed the "EssentialSSL CA" and "DigiCert SHA2 Extended Validation Server CA" from the Certificate Manager, close firefox, run firefox in Private Mode then visit the site. At this time, firefox seems normal, but when I check the "EssentialSSL CA" it has no refresh the Certificate Fields. The even interesting thing is that couple minutes later (I visited other sites in new tabs) the site (wikidevi.com) fall back to "Could not verify this certificate because the issuer is unknown." and the Certificate Hierarchy shows only wikidevi.com.
Thanks for looking into that. I can now reproduce the problem. I'll investigate further when I have time (and others can feel free to look into this as well - see comment 2 for STR).
Status: UNCONFIRMED → NEW
Ever confirmed: true
Component: Security → Security: PSM
Product: Firefox → Core
Whiteboard: [psm-backlog]
Probably related to this bug:
Visiting some websites (e.g. https://kis.hosteurope.de/), firefox
sometimes shows a green padlock (without owner information) next to the URL.
In spite of the green padlock, the certificate viewer reports "Could not
verify this certificate because the issuer is unknown."

The same problem shows with the certificate hierachy as mentioned by the OP.

Reloading the website only sometimes reproduces this behaviour, while in 
other (apparently random) cases the green padlock plus owner information is displayed (as 
expected) and the certificate viewer does *not* show any errors/problems.

The certificate provided by the website is always the same, independently of
which case occurs.  I could live with false negatives in the certificate verification
process, but false positives (= green padlock with untrusted cert) is pretty dangerous!?

Firefox: 45.3.0esr-1~deb7u1, Debian wheezy, amd64

Previously posted: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=835476
(including screenshots), but without any replies.
Well, wikidevi.com uses Let's Encrypt now, and I can't reproduce the issue, so I'll close this as wfm for now.
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → WORKSFORME
You need to log in before you can comment on or make changes to this bug.