Open Bug 1354227 Opened 9 years ago Updated 2 days ago

Add Security Exception page ignores Confirm Security Exception

Categories

(Thunderbird :: Security, defect)

52 Branch
defect

Tracking

(Not tracked)

UNCONFIRMED

People

(Reporter: stevet, Unassigned)

References

Details

(Whiteboard: [regression:TB??])

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0 Build ID: 20170323105023 Steps to reproduce: My email was working before I upgraded to 52.0. After upgrading, I see Add Security Exception. "This site attempts to identify itself with invalid information. The certificate is not trusted because it hasn't been verified as issued by a trusted authority using a secure signature." I leave Permanently store this exception checked, and click Confirm Security Exception. Actual results: Thunderbird doesn't fetch email, and ignores my exception confirmation. Hidden away in the error console: ibrinc.com:995 uses an invalid security certificate. The certificate is not trusted because it was signed using a signature algorithm that was disabled because that algorithm is not secure. Error code: <a id="errorCode" title="SEC_ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED">SEC_ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED</a> Expected results: Thunderbird should have excepted my exception. I was expecting Thunderbird to continue fetching email like it has for many years. Or, at the very least, display an error message as to why it was ignoring my exception request. I really don't like it when buttons I press are ignored.
Component: Untriaged → Security
Whiteboard: [regression:TB??]
Severity: normal → S3

Get error "Unknown Identity" : "The certificate is not trusted because it hasn't been verified as issued by a trusted authority using a secure signature."
I check "Permanently store this exception" and press "Confirm Security Exception"

Receive the error every time. It is almost as if the exception is not being stored.

This is repeatable. Even if logged in as root on linux system (yes, I know that's bad..I wanted to check to see if it was limited to normal users)

OS: Slackware 64-bit version 15.0
Thunderbird version: 115.4.1

Silly bit: somtimes it just works as expected; othertimes, error as above. Permanently storing an exception should actually mean permanently.

I too am experiencing a variant of this bug. I am using an email server that currently is using certificates that have expired. That problem is being worked on. In the meantime, whenever I access the server to open a folder or email, I get a pop-up notification telling me that the certificate has expired. That's expected. I go ahead and confirm the security exception and check the box to permanently store the exception. Trouble is this ISN'T being persisted, when I open a different folder or email, I keep having to go through this process again in order to access my emails or folders.

I am running version 140.6.0esr (64-bit) of Thunderbird under OpenSuSE 15.6 x64 linux. Dec 20, 2025

Hello,

Currently using the version 152.0b3-1 on Ubuntu 24.04.4 LTS, I'm on a server without a valid certificate.
When I try to add a security exception through the modal for "my-domain:143", there are two issues:

  • the button "Get the certificate" launch an infinite loading, never getting the certificate
  • the button "Confirm security exception" failed without feedback but there is an error on the debug console

(In reply to Vincent de Rousiers from comment #3)

Uncaught NS_ERROR_MALFORMED_URI: Component returned failure code: 0x804b000a (NS_ERROR_MALFORMED_URI) [nsIURIMutator.setPort]
    getURI chrome://pippki/content/exceptionDialog.js:162
    addException chrome://pippki/content/exceptionDialog.js:307
    _fireButtonEvent chrome://global/content/elements/dialog.js:538
    _doButtonCommand chrome://global/content/elements/dialog.js:517
    _handleButtonCommand chrome://global/content/elements/dialog.js:511
exceptionDialog.js:162:13
    getURI chrome://pippki/content/exceptionDialog.js:162
    addException chrome://pippki/content/exceptionDialog.js:307
    _fireButtonEvent chrome://global/content/elements/dialog.js:538
    _doButtonCommand chrome://global/content/elements/dialog.js:517
    _handleButtonCommand chrome://global/content/elements/dialog.js:511

which seems related to this test case

if (uri.port == -1) {
    mutator.setPort(443);
  }

I can check, obtain and add a security exception for other port, but not 143.

You need to log in before you can comment on or make changes to this bug.