Use the same date/time format everywhere on cert error pages
Categories
(Firefox :: Security, defect, P3)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox68 | --- | fixed |
People
(Reporter: Franpa_999, Assigned: MonikaMaheshwari)
References
(Blocks 1 open bug, )
Details
Attachments
(1 file)
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0
Steps to reproduce:
I visited https://channelawesome.com/category/videos/channelawesome/dougwalker/nostalgia-critic/
Actual results:
Firefox displays the following message, which clearly states the Security Certificate expires Monday, 25 February 2019, 12:11:10 PM and that the current time is Monday, 25 February 2019, 11:16 PM which is one hour before the certificate expires.
"channelawesome.com uses an invalid security certificate. The certificate expired on Monday, 25 February 2019, 12:11:10 pm. The current time is 25 February 2019, 11:16 pm. Error code: SEC_ERROR_EXPIRED_CERTIFICATE"
Expected results:
Firefox should not be telling me that a Security Certificate has both expired and hasn't expired. Either the Security Certificate expired or it didn't, it can't be both.
To me it seems the warning is being generated 1 hour ahead of the expiry time, which is an error.
If this has to do with timzones than the warning should mention what timezone the expiry time uses (preferably in GMT or UTC format).
| Reporter | ||
Comment 1•7 years ago
|
||
Oh also, why is the expiry time and the current time displayed in 2 different formats? Shouldn't they be displayed in the same format so you can easily compare them???
Updated•7 years ago
|
Comment 2•7 years ago
|
||
Maybe a timezone display issue? I see The certificate expired on February 24, 2019, 6:11:10 PM GMT-8. The current time is February 25, 2019, 10:58 AM.
| Reporter | ||
Comment 3•7 years ago
|
||
The website has possibly fixed its Security Certificate so I can't mess around with it anymore, but yes it looks like it isn't showing mention of a Timezone to me in the warning message.
"channelawesome.com uses an invalid security certificate. The certificate expired on Monday, 25 February 2019, 12:11:10 pm. The current time is 25 February 2019, 11:16 pm. Error code: SEC_ERROR_EXPIRED_CERTIFICATE"
is a verbatim quote of what I was shown.
Updated•7 years ago
|
| Assignee | ||
Comment 4•7 years ago
|
||
Can I work on this issue?
Comment 5•7 years ago
|
||
Hi Monika, yeah, feel free to tackle this, do you need any pointers or do you already have an idea how to start? :)
| Assignee | ||
Comment 6•7 years ago
|
||
Yes I am not able to locate where this message Firefox displays the following message, which clearly states the Security Certificate expires Monday, 25 February 2019, 12:11:10 PM and that the current time is Monday, 25 February 2019, 11:16 PM which is one hour before the certificate expires. is displayed in firefox.
Comment 7•7 years ago
|
||
Hmm, so, with the new certificate errors in 66 we removed the display of when the certificate expired from the advanced section, hence this bug is sort of invalid. But I think it's worth reconsidering that decision, since especially for advanced users there may be some merit in being able to quickly tell if the certificate has just expired, for example. Meridel, do you agree? Do you think you can modify the advanced section for expired certificates to include the expired time? (See https://expired.badssl.com/)
Assuming we do want to display both the expired time and current time, it would probably be a good idea to make this formatter be used everwhere: https://searchfox.org/mozilla-central/rev/69ace9da347adcc4a33c6fa3d8e074759b91068c/browser/actors/NetErrorChild.jsm#483-485
and maybe also switch it to "long" style to match the formatting in PSM code: https://searchfox.org/mozilla-central/rev/69ace9da347adcc4a33c6fa3d8e074759b91068c/security/manager/ssl/nsNSSCertValidity.cpp#51
Let's see what Meridel says :)
Comment 8•7 years ago
|
||
Thanks for looping me in!
I am fine with adding the certificate expiration date for messages where this appears to be the cause. I wonder if we should also then include the date for situations in which the certificate is not yet valid?
Advanced copy would look be this:
Advanced...copy:
[Display this copy if certificate is EXPIRED according to computer clock]
Websites prove their identity via certificates, which are valid for a set time period. The certificate for example.com expired on[Date, time].
[Display this copy if certificate is NOT YET VALID according to computer clock:]
Websites prove their identity via certificates, which are valid for a set time period. The certificate for example.com will not be valid until [Date, time].
I am, at the same time, rethinking the hierarchy of our copy for this entire message...can you please confirm the most likely cause for the expired certificate error? Is it MOST LIKELY an expired certificate? or most likely that the user has their clock set wrong?
Comment 9•7 years ago
|
||
Thanks, that copy sounds good to me! Monika, do you think you can update the copy here?
(In reply to Meridel from comment #8)
I am, at the same time, rethinking the hierarchy of our copy for this entire message...can you please confirm the most likely cause for the expired certificate error? Is it MOST LIKELY an expired certificate? or most likely that the user has their clock set wrong?
I would say it's most likely an expired certificate, since we already have heuristics to detect the wrong system clock and show an entirely different error message then.
| Assignee | ||
Comment 10•7 years ago
|
||
Will start working on this after Bug 1499334. Can you look into that :)
| Assignee | ||
Comment 11•7 years ago
|
||
| Assignee | ||
Updated•7 years ago
|
| Assignee | ||
Updated•7 years ago
|
| Assignee | ||
Updated•7 years ago
|
| Assignee | ||
Updated•7 years ago
|
| Assignee | ||
Updated•7 years ago
|
| Assignee | ||
Comment 14•7 years ago
|
||
Sorry didn't saw that. :)
| Assignee | ||
Updated•7 years ago
|
Comment 15•7 years ago
|
||
Pushed by ntim.bugs@gmail.com:
https://hg.mozilla.org/integration/autoland/rev/348e15018884
Use the same date/time format everywhere on cert error pages r=johannh
Comment 16•7 years ago
|
||
Failure log: https://treeherder.mozilla.org/logviewer.html#/jobs?job_id=242947931&repo=autoland&lineNumber=1693
Backout link: https://hg.mozilla.org/integration/autoland/rev/db876eab4bf0644ebdc5cae9bf726a6695cdeea0
[task 2019-04-26T18:12:13.739Z] 18:12:13 INFO - TEST-PASS | browser/base/content/test/about/browser_aboutCertError_clockSkew.js | URL found in error message -
[task 2019-04-26T18:12:13.740Z] 18:12:13 INFO - Buffered messages finished
[task 2019-04-26T18:12:13.742Z] 18:12:13 INFO - TEST-UNEXPECTED-FAIL | browser/base/content/test/about/browser_aboutCertError_clockSkew.js | Correct local date displayed -
[task 2019-04-26T18:12:13.744Z] 18:12:13 INFO - Stack trace:
[task 2019-04-26T18:12:13.745Z] 18:12:13 INFO - chrome://mochikit/content/browser-test.js:test_ok:1314
[task 2019-04-26T18:12:13.746Z] 18:12:13 INFO - chrome://mochitests/content/browser/browser/base/content/test/about/browser_aboutCertError_clockSkew.js:checkWrongSystemTimeWarning:73
[task 2019-04-26T18:12:13.748Z] 18:12:13 INFO - chrome://mochikit/content/browser-test.js:Tester_execTest/<:1116
[task 2019-04-26T18:12:13.749Z] 18:12:13 INFO - chrome://mochikit/content/browser-test.js:Tester_execTest:1144
[task 2019-04-26T18:12:13.750Z] 18:12:13 INFO - chrome://mochikit/content/browser-test.js:nextTest/<:1005
[task 2019-04-26T18:12:13.750Z] 18:12:13 INFO - chrome://mochikit/content/tests/SimpleTest/SimpleTest.js:SimpleTest.waitForFocus/waitForFocusInner/focusedOrLoaded/<:803
[task 2019-04-26T18:12:13.751Z] 18:12:13 INFO - TEST-PASS | browser/base/content/test/about/browser_aboutCertError_clockSkew.js | time-errors in the Learn More URL -
| Assignee | ||
Comment 17•7 years ago
|
||
Can you help in here :)
Comment 18•7 years ago
|
||
It seems we forgot to update the formatter in this test: https://searchfox.org/mozilla-central/rev/b2015fdd464f598d645342614593d4ebda922d95/browser/base/content/test/about/browser_aboutCertError_clockSkew.js#44
Can you do that and do a try push? :)
I'm not sure if you have access to Try yet, you can find instructions on how to get it here: https://wiki.mozilla.org/ReleaseEngineering/TryServer
I'm happy to vouch for you if you make a new bug, and please let me know if you need any help getting it running.
| Assignee | ||
Comment 19•7 years ago
•
|
||
Getting remote: Permission denied (publickey) on ./mach try empty
| Assignee | ||
Updated•7 years ago
|
Comment 20•7 years ago
|
||
Pushed by dluca@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/4bb1186d2d9e
Use the same date/time format everywhere on cert error pages r=johannh
Comment 21•7 years ago
|
||
| bugherder | ||
Comment 22•7 years ago
|
||
(In reply to Monika Maheshwari [:MonikaMaheshwari] from comment #19)
Getting remote: Permission denied (publickey) on
./mach try empty
Did you file a bug to get access to the try server? See https://wiki.mozilla.org/ReleaseEngineering/TryServer#Getting_access_to_the_Try_Server :)
Description
•