SEC_ERROR_UNKNOWN_ISSUER on various HTTPS site after a day without restarting Firefox
Categories
(Core :: Security: PSM, defect)
Tracking
()
People
(Reporter: dev, Unassigned, NeedInfo)
Details
Attachments
(9 files)
| Reporter | ||
Comment 1•7 years ago
|
||
| Reporter | ||
Comment 2•7 years ago
|
||
Comment 6•7 years ago
|
||
Comment 7•7 years ago
|
||
| Reporter | ||
Comment 8•7 years ago
|
||
Comment 10•7 years ago
|
||
Updated•7 years ago
|
| Reporter | ||
Comment 11•7 years ago
|
||
| Reporter | ||
Comment 12•7 years ago
|
||
Updated•7 years ago
|
| Reporter | ||
Comment 13•7 years ago
|
||
| Reporter | ||
Comment 14•7 years ago
|
||
Users report they still experience this bug with current Firefox.
Comment 15•7 years ago
|
||
Can you attach the file 'pkcs11.txt' from the profile directory of a user this happens to?
Comment 16•7 years ago
|
||
I'm using ff 60.5.0esr on RHEL 7 and have the same issue.
Here it happens today, very frequently, in less than an hour.
I have removed the xdg cache, looked at some straces when reloading the page with F5.
But found nothing obvious.
Comment 17•7 years ago
|
||
Comment 18•7 years ago
|
||
Martin, on a page you're seeing the error on, can you click "Advanced", click on the blue error code, click "Copy text to clipboard", paste that in a text file, and attach it to this bug? Thanks!
Comment 19•7 years ago
|
||
Okay, if it occurs again.
Currently I'm thinking that the machine needed a reboot because afterwards it did not happen again.
Now it's working fine for two hours...
| Reporter | ||
Comment 20•7 years ago
|
||
| Reporter | ||
Comment 21•7 years ago
|
||
| Reporter | ||
Comment 22•7 years ago
|
||
Comment 23•7 years ago
|
||
Ok - so it doesn't looks like pkcs11 modules are the problem. Same question as comment 18 I guess?
| Reporter | ||
Comment 24•7 years ago
|
||
I just added 3 examples of pkcs11.txt from three profiles reported to reproduce the bug, first and second ones were running with NSS_SDB_USE_CACHE set to yes but unset with third one.
I anonymized the file server name and the user names btw.
| Reporter | ||
Comment 25•7 years ago
|
||
Hmm, cross posting, will do as Comment 18 says.
Note that there was some copy-paste in https://support.mozilla.org/en-US/questions/1226671 , perhaps what you ask for.
Comment 26•7 years ago
|
||
Ok - that helps. How about if you look in about:preferences -> search for "security devices" -> click "Security Devices". What do you see in the "Security Modules and Devices" column? (I can figure out what the translation is if that would be helpful...)
| Reporter | ||
Comment 27•7 years ago
|
||
Hi Dana, I see “NSS Internal PKCS #11 Module” and “NSS Builtin Objects”, see screenshot. Sorry for the late reply I did not receive the notification.
| Reporter | ||
Comment 28•7 years ago
|
||
Just to be sure nothing is missing, this is an example of false-positive wrong certificate given when the problem occurs while browsing https://bugzilla.mozilla.org
Note that the message says wrongly that the connection is intercepted by a TLS proxy, which is wrong.
Also, this is some info about the given certificate, everything looks legit at this point:
$ openssl x509 -in bugzilla.mozilla.org-wrong-certificate.txt -text -noout
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
09:b7:8a:c5:12:8b:f9:c4:2e:97:fd:e7:75:4f:01:73
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, O = DigiCert Inc, CN = DigiCert SHA2 Secure Server CA
Validity
Not Before: Feb 8 00:00:00 2018 GMT
Not After : May 2 12:00:00 2019 GMT
Subject: C = US, ST = California, L = Mountain View, O = Mozilla Foundation, OU = WebOps, CN = *.bugzilla.mozilla.org
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:d5:af:ca:d2:d6:38:32:70:6c:1e:0e:d9:96:34:
29:8d:22:e0:e7:0e:78:79:ee:a2:b8:c9:c8:e4:9a:
73:82:ff:d5:0f:d1:d8:ce:22:19:03:eb:bd:9e:e3:
87:51:a2:b0:8c:b0:9e:e9:a0:41:2d:44:99:f6:73:
43:cd:60:85:91:49:ca:a7:4b:af:b7:17:1e:35:55:
0c:d4:22:c3:d5:f7:f6:89:ef:bf:1e:9a:09:6d:74:
17:c9:3d:41:82:2b:eb:50:ee:b5:87:64:f2:2f:dd:
56:4b:3b:91:0b:a0:39:84:f9:f9:95:73:08:82:99:
16:78:f4:b3:08:c2:c7:55:5a:8a:ef:5e:ed:b1:81:
00:9b:d0:b3:4c:53:63:fd:5e:7c:56:21:4d:2b:29:
15:45:98:0b:88:be:e4:74:83:71:f9:cc:a0:cc:0f:
b6:ad:ae:5b:04:d4:e8:42:f6:c2:97:60:8f:fb:f6:
11:fb:36:5c:fe:d7:59:5f:c6:83:94:ee:6c:2c:96:
50:f9:8b:2e:2a:51:53:f5:86:88:85:6c:74:12:9f:
6a:d8:e5:07:68:2d:a4:a5:c4:c5:92:9a:73:73:c0:
28:8f:cd:57:ab:73:da:2d:13:f4:2d:d0:5c:83:82:
ff:b2:6c:d3:39:09:c8:c4:14:a8:ac:e3:cb:b6:bf:
7e:07
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Authority Key Identifier:
keyid:0F:80:61:1C:82:31:61:D5:2F:28:E7:8D:46:38:B4:2C:E1:C6:D9:E2
X509v3 Subject Key Identifier:
2A:8F:3F:30:BF:2F:77:E9:7C:7D:71:7F:FC:18:67:D3:4D:02:48:D0
X509v3 Subject Alternative Name:
DNS:*.bugzilla.mozilla.org, DNS:bugzilla.mozilla.org
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl3.digicert.com/ssca-sha2-g6.crl
Full Name:
URI:http://crl4.digicert.com/ssca-sha2-g6.crl
X509v3 Certificate Policies:
Policy: 2.16.840.1.114412.1.1
CPS: https://www.digicert.com/CPS
Policy: 2.23.140.1.2.2
Authority Information Access:
OCSP - URI:http://ocsp.digicert.com
CA Issuers - URI:http://cacerts.digicert.com/DigiCertSHA2SecureServerCA.crt
X509v3 Basic Constraints: critical
CA:FALSE
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : BB:D9:DF:BC:1F:8A:71:B5:93:94:23:97:AA:92:7B:47:
38:57:95:0A:AB:52:E8:1A:90:96:64:36:8E:1E:D1:85
Timestamp : Feb 8 20:48:00.733 2018 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:44:02:20:7D:E2:44:9E:D8:F9:7F:AE:11:69:3D:4D:
29:60:74:A2:DA:4E:D3:7A:89:31:84:C8:2A:07:EB:0A:
48:82:1B:EC:02:20:1F:2D:FD:E4:40:14:70:86:FF:33:
B0:C1:46:C0:5A:E2:A4:13:2E:42:58:68:E7:8B:7A:DC:
4A:BC:21:B4:18:A9
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 87:75:BF:E7:59:7C:F8:8C:43:99:5F:BD:F3:6E:FF:56:
8D:47:56:36:FF:4A:B5:60:C1:B4:EA:FF:5E:A0:83:0F
Timestamp : Feb 8 20:48:00.736 2018 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:46:02:21:00:94:91:73:82:6B:40:D5:CD:0D:78:00:
82:47:C1:F8:F5:56:B8:37:F4:B3:DC:FA:E8:29:C3:D2:
F3:61:7C:CD:52:02:21:00:BA:35:2E:C0:E4:B7:4E:38:
B6:56:DE:2E:47:D2:69:E2:67:E9:16:54:02:FC:19:82:
1F:AA:BC:68:3E:13:22:8B
Signature Algorithm: sha256WithRSAEncryption
6d:1e:af:fd:54:1b:85:47:89:e5:df:08:82:52:07:5a:62:0f:
74:94:5b:da:ec:db:5f:31:95:36:58:b5:6e:ab:a5:4e:88:9f:
ef:3e:d6:ce:13:4a:3e:52:52:cf:2b:5e:40:8a:b8:13:53:36:
52:c4:f1:95:c8:fb:ca:12:2f:ad:4e:7c:ad:a9:af:40:bf:5a:
12:19:e6:be:4a:78:a6:bb:1d:c0:83:77:4b:0d:fc:b1:1e:da:
69:67:30:7b:e6:2d:51:0e:1b:bf:4c:b4:a4:1c:3f:b2:f3:3c:
f4:aa:5e:97:4d:a0:b0:f8:04:28:bd:c4:37:94:3f:16:a5:e9:
cf:87:bb:c3:61:0a:82:fb:c1:a7:02:f1:ec:1d:81:23:dd:fc:
e1:f1:96:2d:f7:70:cd:4e:ec:71:56:9c:48:93:81:34:b7:0b:
60:0a:ef:fb:45:95:2d:80:09:dd:e1:31:2d:f3:a4:87:9a:da:
e4:bc:14:b1:c2:c6:16:91:2f:89:b8:e6:2e:f0:58:cd:b1:a1:
a6:5f:3b:1b:23:ec:e4:a1:b9:ed:c4:95:58:26:7c:af:bd:aa:
db:12:1b:d0:22:c1:0a:df:23:87:7b:5d:fa:ed:a8:2b:2d:f7:
3d:78:db:d8:71:84:97:11:a1:73:dc:97:cb:ec:25:86:8b:5f:
2b:8f:49:49
[illwieckz@gollum:/tmp] $ openssl x509 -in 20190218.false-positive-wrong-certificate.bugzilla.mozilla.org.txt -text -noout
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
09:b7:8a:c5:12:8b:f9:c4:2e:97:fd:e7:75:4f:01:73
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, O = DigiCert Inc, CN = DigiCert SHA2 Secure Server CA
Validity
Not Before: Feb 8 00:00:00 2018 GMT
Not After : May 2 12:00:00 2019 GMT
Subject: C = US, ST = California, L = Mountain View, O = Mozilla Foundation, OU = WebOps, CN = *.bugzilla.mozilla.org
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:d5:af:ca:d2:d6:38:32:70:6c:1e:0e:d9:96:34:
29:8d:22:e0:e7:0e:78:79:ee:a2:b8:c9:c8:e4:9a:
73:82:ff:d5:0f:d1:d8:ce:22:19:03:eb:bd:9e:e3:
87:51:a2:b0:8c:b0:9e:e9:a0:41:2d:44:99:f6:73:
43:cd:60:85:91:49:ca:a7:4b:af:b7:17:1e:35:55:
0c:d4:22:c3:d5:f7:f6:89:ef:bf:1e:9a:09:6d:74:
17:c9:3d:41:82:2b:eb:50:ee:b5:87:64:f2:2f:dd:
56:4b:3b:91:0b:a0:39:84:f9:f9:95:73:08:82:99:
16:78:f4:b3:08:c2:c7:55:5a:8a:ef:5e:ed:b1:81:
00:9b:d0:b3:4c:53:63:fd:5e:7c:56:21:4d:2b:29:
15:45:98:0b:88:be:e4:74:83:71:f9:cc:a0:cc:0f:
b6:ad:ae:5b:04:d4:e8:42:f6:c2:97:60:8f:fb:f6:
11:fb:36:5c:fe:d7:59:5f:c6:83:94:ee:6c:2c:96:
50:f9:8b:2e:2a:51:53:f5:86:88:85:6c:74:12:9f:
6a:d8:e5:07:68:2d:a4:a5:c4:c5:92:9a:73:73:c0:
28:8f:cd:57:ab:73:da:2d:13:f4:2d:d0:5c:83:82:
ff:b2:6c:d3:39:09:c8:c4:14:a8:ac:e3:cb:b6:bf:
7e:07
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Authority Key Identifier:
keyid:0F:80:61:1C:82:31:61:D5:2F:28:E7:8D:46:38:B4:2C:E1:C6:D9:E2
X509v3 Subject Key Identifier:
2A:8F:3F:30:BF:2F:77:E9:7C:7D:71:7F:FC:18:67:D3:4D:02:48:D0
X509v3 Subject Alternative Name:
DNS:*.bugzilla.mozilla.org, DNS:bugzilla.mozilla.org
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl3.digicert.com/ssca-sha2-g6.crl
Full Name:
URI:http://crl4.digicert.com/ssca-sha2-g6.crl
X509v3 Certificate Policies:
Policy: 2.16.840.1.114412.1.1
CPS: https://www.digicert.com/CPS
Policy: 2.23.140.1.2.2
Authority Information Access:
OCSP - URI:http://ocsp.digicert.com
CA Issuers - URI:http://cacerts.digicert.com/DigiCertSHA2SecureServerCA.crt
X509v3 Basic Constraints: critical
CA:FALSE
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : BB:D9:DF:BC:1F:8A:71:B5:93:94:23:97:AA:92:7B:47:
38:57:95:0A:AB:52:E8:1A:90:96:64:36:8E:1E:D1:85
Timestamp : Feb 8 20:48:00.733 2018 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:44:02:20:7D:E2:44:9E:D8:F9:7F:AE:11:69:3D:4D:
29:60:74:A2:DA:4E:D3:7A:89:31:84:C8:2A:07:EB:0A:
48:82:1B:EC:02:20:1F:2D:FD:E4:40:14:70:86:FF:33:
B0:C1:46:C0:5A:E2:A4:13:2E:42:58:68:E7:8B:7A:DC:
4A:BC:21:B4:18:A9
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 87:75:BF:E7:59:7C:F8:8C:43:99:5F:BD:F3:6E:FF:56:
8D:47:56:36:FF:4A:B5:60:C1:B4:EA:FF:5E:A0:83:0F
Timestamp : Feb 8 20:48:00.736 2018 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:46:02:21:00:94:91:73:82:6B:40:D5:CD:0D:78:00:
82:47:C1:F8:F5:56:B8:37:F4:B3:DC:FA:E8:29:C3:D2:
F3:61:7C:CD:52:02:21:00:BA:35:2E:C0:E4:B7:4E:38:
B6:56:DE:2E:47:D2:69:E2:67:E9:16:54:02:FC:19:82:
1F:AA:BC:68:3E:13:22:8B
Signature Algorithm: sha256WithRSAEncryption
6d:1e:af:fd:54:1b:85:47:89:e5:df:08:82:52:07:5a:62:0f:
74:94:5b:da:ec:db:5f:31:95:36:58:b5:6e:ab:a5:4e:88:9f:
ef:3e:d6:ce:13:4a:3e:52:52:cf:2b:5e:40:8a:b8:13:53:36:
52:c4:f1:95:c8:fb:ca:12:2f:ad:4e:7c:ad:a9:af:40:bf:5a:
12:19:e6:be:4a:78:a6:bb:1d:c0:83:77:4b:0d:fc:b1:1e:da:
69:67:30:7b:e6:2d:51:0e:1b:bf:4c:b4:a4:1c:3f:b2:f3:3c:
f4:aa:5e:97:4d:a0:b0:f8:04:28:bd:c4:37:94:3f:16:a5:e9:
cf:87:bb:c3:61:0a:82:fb:c1:a7:02:f1:ec:1d:81:23:dd:fc:
e1:f1:96:2d:f7:70:cd:4e:ec:71:56:9c:48:93:81:34:b7:0b:
60:0a:ef:fb:45:95:2d:80:09:dd:e1:31:2d:f3:a4:87:9a:da:
e4:bc:14:b1:c2:c6:16:91:2f:89:b8:e6:2e:f0:58:cd:b1:a1:
a6:5f:3b:1b:23:ec:e4:a1:b9:ed:c4:95:58:26:7c:af:bd:aa:
db:12:1b:d0:22:c1:0a:df:23:87:7b:5d:fa:ed:a8:2b:2d:f7:
3d:78:db:d8:71:84:97:11:a1:73:dc:97:cb:ec:25:86:8b:5f:
2b:8f:49:49
Comment 29•7 years ago
|
||
(In reply to Thomas Debesse from comment #27)
Created attachment 9044573 [details]
Firefox security devices windowsHi Dana, I see “NSS Internal PKCS #11 Module” and “NSS Builtin Objects”, see screenshot. Sorry for the late reply I did not receive the notification.
Thanks! If you open that dialog again and select the second module ("Module de base intégré") is its path ("Chemin", I gather) on a network share? Is it in the same directory as the Firefox installation? Is the file specified available when connections start failing?
| Reporter | ||
Comment 30•7 years ago
|
||
If you open that dialog again and select the second module ("Module de base intégré")
- Is its path ("Chemin", I gather) on a network share? → No
- Is it in the same directory as the Firefox installation? → Yes
- Is the file specified available when connections start failing? → Yes
Well, for the later I guess Yes since once I've noticed the failing I can read the file, by the way it's on a hard drive so I doubt the file become unavailable, this is the file path:
C:\Program Files\Mozilla Firefox\nssckbi.dll
| Reporter | ||
Comment 31•7 years ago
|
||
I noticed that since Firefox caught the bug, when I click on “Software Security Device” it can't display the content without being stuck first. The window become white-gray, Windows says the window is not responding, then a pop-up appears saying that chrome://global/content/elements/stringbundle.js:42 is busy and does not respond. Once I click on “Continue” the content is displayed.
It seems to occur any time I click on “Software Security Device” after having clicked elsewhere. The Device Manager window was already opened when the security bug happened. It was not occurring before the security bug happened (I only tested at startup by the way).
| Reporter | ||
Comment 32•7 years ago
|
||
This is how the “Software Security Device” is displayed after being stuck and having clicked on “Continue”.
Comment 33•7 years ago
|
||
Odd - can you capture a profile using https://perf-html.io/ while that is happening?
Updated•7 years ago
|
Description
•