Open Bug 1550147 Opened 9 months ago Updated 5 months ago

customer.comcast.com isn't sending any intermediate certificates

Categories

(Web Compatibility :: Desktop, defect, P5)

Firefox 66
defect

Tracking

(Not tracked)

UNCONFIRMED

People

(Reporter: github, Unassigned)

References

()

Details

Attachments

(1 file)

User Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:66.0) Gecko/20100101 Firefox/66.0

Steps to reproduce:

browse to https://customer.comcast.com.

Actual results:

SEC_ERROR_UNKNOWN_ISSUER.

looks like COMODO RSA cert chain is not recognized. (see screenshot)

Expected results:

page loads.

worth noting that i tried in chrome and it works as expected, so i'm assuming it's not that the CA chain isn't being sent. (like other bug reports mention)

Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
20190507012018

Attachment 9063602 [details] shows https://api.comcast.com If I try to load that, seemingly no content loads. Browser Console shows the server responds with 404 Not Found but the address bar icon doesn't show any certificate issues.

https://customer.comcast.com fails to load with no error code and no Advanced button to reveal it. In Nightly, the error code is PR_CONNECT_RESET_ERROR. Same thing in Vivaldi: error code ERR_CONNECTION_RESET, so this appears to be a site problem.

Component: Untriaged → Security: PSM
Product: Firefox → Core

It's not sending any intermediate certificates: https://www.ssllabs.com/ssltest/analyze.html?d=customer.comcast.com
Firefox will handle this situation better once bug 1548365 ships, but in the meantime this can be an evangelism bug (they need to fix their server).

Component: Security: PSM → Desktop
Product: Core → Web Compatibility
Summary: ssl cert error SEC_ERROR_UNKNOWN_ISSUER on api.comcast.com for cert issued by comodo rsa → customer.comcast.com isn't sending any intermediate certificates
Version: 66 Branch → Firefox 66
Priority: -- → P5
You need to log in before you can comment on or make changes to this bug.