old client certificate used after it expired despite newer one added (ssl_error_expired_cert_alert after)
Categories
(Core :: Security: PSM, defect, P5)
Tracking
()
People
(Reporter: michael-dev, Unassigned)
References
Details
(Whiteboard: [psm-clientauth])
Reporter | ||
Comment 1•9 years ago
|
||
Updated•9 years ago
|
Comment 2•8 years ago
|
||
Comment 3•8 years ago
|
||
Updated•8 years ago
|
Reporter | ||
Updated•7 years ago
|
Reporter | ||
Comment 4•7 years ago
|
||
Updated•7 years ago
|
Comment 5•3 years ago
|
||
Anything new on this?
That problem exists or 6 years and not everyone wants to delete his old keys/certificates.
Updated•2 years ago
|
This problem persists with the Authority Decisions feature. The user has to go into the Authority Decisions window and remove the authority decision concerning the expired certificate. After that Firefox will prompt for a certificate again and the user will be able to select the new certificate.
I confirm that the problem persists after restarts (and reboots).
Firefox should not use expired certificates at all and prompt the user.
In my opinion, the Authority Decisions feature should be dropped completely. Almost no user will be able to find the window and tab and know what to do there. For those users who do know how it works, it is still a nuisance.
Description
•