Closed Bug 1806084 Opened 3 years ago Closed 3 years ago

No way to add exception for expired certificates.

Categories

(Core :: Security: PSM, defect)

Firefox 108
defect

Tracking

()

RESOLVED INVALID

People

(Reporter: ronnyourmatrix, Unassigned)

Details

Attachments

(1 file)

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0) Gecko/20100101 Firefox/108.0

Steps to reproduce:

The development certificate for https://localhost:5001/ just expired.

Actual results:

I can no longer access the website using Firefox, because I cannot add an exception. I read something about HSTS, but I believe it is not the case since http://localhost:5000/ works fine. Also, the error message is misleading: SEC_ERROR_INADEQUATE_KEY_USAGE

Expected results:

Display proper information about the certificate problem. Provide an option to view certificate details in this case. Show the Advanced and Add Exception buttons.

The Bugbug bot thinks this bug should belong to the 'Core::Security: PSM' component, and is moving the bug to that component. Please correct in case you think the bot is wrong.

Component: Untriaged → Security: PSM
Product: Firefox → Core

That error means at least one certificate that you are using has an inadequate keyUsage extension. Can you post the certificates that you're using here? (just the public parts)

Flags: needinfo?(ronnyourmatrix)

-----BEGIN CERTIFICATE-----
MIIDDDCCAfSgAwIBAgIIbG/9W67ljogwDQYJKoZIhvcNAQELBQAwFDESMBAGA1UE
AxMJbG9jYWxob3N0MB4XDTIxMTIxNTEyNTQ1NloXDTIyMTIxNTEyNTQ1NlowFDES
MBAGA1UEAxMJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
AQEA4EMuxKXyYxunfsEw9ptlv/Xv5CXK3NQkO5XrU1SkimzXGtmIv5uUNSjvz3y8
zjnXmdYrMwZVgG4mrHlXRqVmDJHWFffsr6hiM101dQ/wviFWLAmGF5/hRIrfT1pC
E7wj50ilqxEFjyjRu1bQq7b1HK0qrRqcUnG3ckhGLmuNGUslDfT5qrPROyLAL9KL
b3CUBRXLMA/nH/uMD3s71CAFwrz4pXgFwczGT7soCyheHdflmelCwsn29p8EHJYV
1Up4Eq0XvT5YChQSpDxjlqxetoN8WKuILxpGL6m7slDzqkhhDizkh7tXOnBjWwd8
4Ov4h+ibts5qsBU5PMyPZlHP/QIDAQABo2IwYDAMBgNVHRMBAf8EAjAAMA4GA1Ud
DwEB/wQEAwIFoDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATAXBgNVHREBAf8EDTAL
gglsb2NhbGhvc3QwDwYKKwYBBAGCN1QBAQQBAjANBgkqhkiG9w0BAQsFAAOCAQEA
esP+x/9s23TC+iGujglG2bGx+p94rfn2RIzUzem+WU991QxA78hVA7dclxLA1UNS
Eydpbe4KYcd1s9HuvJuPQvNfcz8yzX0gfQFHjOvbOViUK3tRzTFFfiPryXYczz0H
hNQyCuckvOXOaRhqmRDKG8qdXDXSVOxDZk8b7baodwVSiI1XaDJAJZWv5nR1VIGt
OhR/h9ZK8ykd84XPCDYo7sKxN/GeVM56k33n8hE0XE5i+c0JJc+9Hw5atmCEWWBk
s8GqYEr0gUbmWmwF0WO629HfHIx+8QWzh5rN+H5HHAhS85HqQMTHfKzFCVCnZGtZ
3aKoRHdmcR4JTfPE8D8P7g==
-----END CERTIFICATE-----

In case I gave you the wrong info, I can also attach the certificate and provide the password here.

Flags: needinfo?(ronnyourmatrix)

That certificate is trying to be both a CA certificate and a server certificate. That's not something Firefox supports. The easiest way to fix it would be to remove the "basicConstraints" and "keyUsage" extensions. This isn't a bug in Firefox.

Status: UNCONFIRMED → RESOLVED
Closed: 3 years ago
Resolution: --- → INVALID

The statement "That's not something Firefox supports" is wrong.

Firefox successfully retrieves content over HTTPS using the following certificate:
-----BEGIN CERTIFICATE-----
MIIDDTCCAfWgAwIBAgIJAO8y9gML2sx8MA0GCSqGSIb3DQEBCwUAMBQxEjAQBgNV
BAMTCWxvY2FsaG9zdDAeFw0yMjEyMTYxMTU1MjRaFw0yMzEyMTYxMTU1MjRaMBQx
EjAQBgNVBAMTCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
ggEBAMVSkxvBy5ybon9alCj21V0BsLaxAj5+c6bJEq8LBDTd2qj0DtMlZ395T9JD
2cxK0RkpCc3upP1ziv8WRgUvAid8W4utephPXElhGS02/ioAtfCaWJZI4YdxvWK6
HGgymWgH4uGgc1Y1/IPHahCoH5Q42ofF7SgXQCQ2Y2oI2AYbDK9SjUnyTNz2ZBP+
mhB5bSQ6uJ2JQ7PYpVqI9mLzIQaXLY8zDvDU1irI9LZD3DgTaquz0FEhk7nc9d1l
g7cDotTwP8kfNTDx8qk3ADM9vRiVl3obbEQ+AmgSa/xezP6MTT9XS+u9FSeC2at5
pEIbX2gJ8Tq2V1TNTjmQ1QZ5buECAwEAAaNiMGAwDAYDVR0TAQH/BAIwADAOBgNV
HQ8BAf8EBAMCBaAwFgYDVR0lAQH/BAwwCgYIKwYBBQUHAwEwFwYDVR0RAQH/BA0w
C4IJbG9jYWxob3N0MA8GCisGAQQBgjdUAQEEAQIwDQYJKoZIhvcNAQELBQADggEB
AL7KC7i5e3U+gf82ZnjWdKF+EiW2vhU4t4ueyPodv6tWIf4Z9vh+8RqjieU/qxpl
dOZ7XRqyCkiLOjLmnWV9SyDKPDg/LSb7sgrJBWbfuMPG5y3ToYsJfFzGrUgp7559
y1QyjBEplprCYK/YboyE1NjGAbm3pll8LrbjnR62Hcf6yS3AbabqCtvlHt9RHd3D
r600JO7ys7YO9FY/wmUd2URs3d94a7Faw7IRQCFAaPg+tbQIbks33JNTBw9HjIIP
l1xOO5inWEYT9faVX5bpe8RsUpkR6dpIDc3ooGQFArwgHzlBsqWH3JxKPSjZB+33
A0WM4MFhuVB0u7v/Yf3ogFo=
-----END CERTIFICATE-----

I have checked and there are the following differences compared with the previously pasted certificate:

  • serialNumber
  • validFrom
  • validTo
  • public key

There is no problem with the certificate contents other than the fact that it is expired. My original post is about not being able to add an exception in Firefox for such an expired certificate. I can do that in Edge/Chrome.

You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: