Closed Bug 1603975 Opened 6 years ago Closed 6 years ago

Unable to view self-signed certificate in Firefox 71.0 (64-bit)

Categories

(Firefox :: Security, defect)

71 Branch
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 1602622

People

(Reporter: Bugzilla, Unassigned)

Details

Attachments

(2 files)

User Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0

Steps to reproduce:

Steps to reproduce this bug:

  1. Upgrade to the latest firefox on Linux Mint Cinnamon as of Saturday, December 14, 2019 using the Linux Mint repositories.
  2. Go to https://aws.lam1.us
    a) If you have already visited the site
    i. Click the lock icon next to the URL (becasue this is a self signed certificate the lock has a yellow exclamation point triange warning component)
    ii. Click the right arrow (>} to the right of the Connection not secure line in the Site information for aws.lam1.us dialog box
    iii. Click the More information button at the bottom of the Connection Security for aws.lam1.us dialog box
    iv. Click the View Certificate button
    b) If you have never visited the site
    i. Click the Advanced ... button on the Warning: Potential Security Risk Ahead page
    ii. Click the View Certificate link at the bottom of the expanded dialog box

You don't have to install Linux Mint to test this bug.

  1. Run Linux Mint off the Latest Linux Mint Live iso as of Saturday, December 14, 2019
  2. With the version of Firefox in the Linux Mint Live iso you can view the self signed certificate
    a) The Linux Mint 19.3 "Tricia" Cinnamon Beta iso has Firefox 70.0.1 installed
    b) The Linux Mint 19.2 "Tina" Cinnamon iso has Firefox 70.0.1 installed
  3. sudo apt-get update
  4. sudo apt-get install firefox
  5. Restart Firefox and you can no longer view the self signed certificate

I have reproduced this error on multiple machines running Linux Mint and some had viewed and accepted the certificate in the past.

I first encountered this bug after installing Linux Mint on a brand new laptop I have had for less than 10 days so this was within a new Firefox profile. I reproduced the bug on my older laptop being replaced. I then reproduced the bug using the Linux Mint Live isos.

Actual results:

Instead of certificate information the following error is displayed:
Something went wrong.
We were unable to find the certificate information, or the certificate is corrupted. Please try again.
You can still Accept the Risk and continue

Expected results:

You should be able to view the certificate information before you Accept the Risk and continue.

Information about the .lam1.us self-signed certificate:
Owner: EMAILADDRESS=q.ServerAdmin@lam1.us, CN=
.lam1.us, OU=q, O=lam1.us, L=North Pole, ST=Alaska, C=US
Issuer: EMAILADDRESS=q.ServerAdmin@lam1.us, CN=*.lam1.us, OU=q, O=lam1.us, L=North Pole, ST=Alaska, C=US
Serial number: b6e7cc3dda944c93
Valid from: Mon May 20 13:26:09 AKDT 2019 until: Thu May 20 13:26:09 AKDT 2021
Certificate fingerprints:
SHA1: 7B:3F:13:CB:8F:86:88:07:7D:D0:81:D1:B6:67:84:25:A8:8F:54:6B
SHA256: 7F:18:1E:9D:F4:E5:50:ED:B3:D5:24:ED:85:33:C9:A4:84:B9:F7:8E:A7:AF:30:98:7E:B7:D3:BD:8B:7D:85:7D
Signature algorithm name: SHA256withRSA
Subject Public Key Algorithm: 1024-bit RSA key
Version: 1

Summary: Unable to view self-signed certificate in Firefox 71.0 (64-bit) for Linux Mint → Unable to view self-signed certificate in Firefox 71.0 (64-bit)

I rebooted my brand new computer to Windows 10, installed Firefox, and get the same error.

I changed the title of this bug report by eliminating "for Linux Mint".

Since it is no longer limited to Linux Mint and impacts Windows users it should get a much higher priority when someone gets to that point of addressing this bug.

Am I the only one who wants to view a self-signed certificate before accepting it?

I was thinking of testing it on an Ubuntu Live iso when I remembered that since I didn't destroy windows on my new laptop when installing Linux I could just test it there. So I booted to Windows and verified that this bug affects Windows users as well. So my keeping windows on this machine was valuable to me even though I normally do not want to run windows. O.K. back to Linux.

Even we are facing the same issue. We are unable to view self signed certificate in firefox 71.
Please use the below url:

about:certificate?cert=MIICpDCCAYygAwIBAgIEfYRfcjANBgkqhkiG9w0BAQsFADAUMRIwEAYDVQQDEwlBTktVU0hDVlAwHhcNMTkxMTE5MTIzOTE0WhcNMjQxMTE3MTIzOTE0WjAUMRIwEAYDVQQDEwlBTktVU0hDVlAwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCj7ei%2B8r5lGSP2UKUe7MQq128icGAmCNc%2Fq3yUuKkoRvoGnadJjusyzbU9Qu2zQskhNgsXPygknWPd6VglUERpp7hZYIbkOL9gR4kz5tEP%2B8KamUY4ce%2FBNEnXqzv3GoLnzEZowv0RBHSw8c8U%2FYefVtO7%2FWw17ZkymUGiGZxhg47Bmaw7EmjV6oOITya8RnpLyDeILP03S5bXjvxzJGWQiBkbTsmC9ha9cM8pC%2BArW4WdCZtU6%2BLmkvByM4RMFIULaZE%2FGog%2BGXe5wX1QGO9%2B1CeBKe3Ze8ARsfDaUWrSSqI5V5GXcM8nnfinEAOXTjtnRLWogFnnAxlfEtUd5coRAgMBAAEwDQYJKoZIhvcNAQELBQADggEBADJAxkBj4XICzpaJfdgYMPDXSru38%2BDCHEDx30%2FX28eMMlkS3a1gLEIphw8U%2FZoZrg2vRWd4l2n%2F%2FsyZVINHO44NPwVXqF3P8FRPdViC25hvEroY%2Fy%2BxsBIQgg5g9uQ9kI1hzpjFyV%2Ffu6iAiGvzyE5S%2Ba%2BEN1dP%2FHqerKoxd9ULojHDkled1vntI149UOh9SHNvsuyveTnKQlkwFx0bLebax%2BxF5Y4doxNGcbobksbrP8zzHbZ5kK9ZpZBVqf2KuBwMt7hAXx3A6%2BQ1nQUKV31eyjWf63pw7IuJ8ltu4S%2FDFFhKnCDJqWyKqlFLHyA0GDoL9D6r2oJKGcehQUay9OE%3D

Above link throws below message without any error code:
Something went wrong.
We were unable to find the certificate information, or the certificate is corrupted. Please try again.

Whereas same self signed certificates can be viewed in IE and chrome browsers.
Attached the screen shot for the same.

Steps to reproduce:

  1. open link to site which has self signed certificate
  2. Accept risk and continue
  3. click on lock icon on left side of the address bar
  4. click on the right arrow mark on the pop up window
  5. Click on more information
  6. click on View Certificate on Security tab

Expected Result:

Should be able to view the certificate

Actual Result:
Something went wrong.
We were unable to find the certificate information, or the certificate is corrupted. Please try again.

Hi, Lawrence A. Murakami and Ananth!

Thank you both for your contribution!

This issue is a duplicate of https://bugzilla.mozilla.org/show_bug.cgi?id=1602622 but I will add product and component also on this one to keep track because is way more complete and specific than the original.

Regards,

Component: Untriaged → Security
Flags: needinfo?(Bugzilla)
Status: UNCONFIRMED → RESOLVED
Closed: 6 years ago
Resolution: --- → DUPLICATE
Flags: needinfo?(Bugzilla)

I still experience this error in version 74

I can reproduce and fix the issue consistent following these steps:

  1. Create a self-signed certificate e.g. for localhost
  2. Host a site on localhost, open it in a browser tab
  3. Shutdown the service, create a new certificate for localhost
  4. Replace the old with the new self-signed certificate
  5. Host the site on localhost again, open it in another browser tab
  6. Try to view the certificate information: this will fail with the documented error
  7. Close any tab that may still be open of the site when it was first opend with the old certificate. eventually close all tabs of the localhost site
  8. Open a new tab of the localhost site and try to view the certificate information: now it will success.

Seems to be a caching issue that occures primarily in development scenarios where we quickly change/replace certificates. If the same site is still open in Firefox but with a different, 'cached', certificate, this issue will occure.

You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: