inconsistent messaging around security of connections with certificate error overrides
Categories
(Firefox :: Security, defect)
Tracking
()
People
(Reporter: firefox, Unassigned)
Details
Attachments
(3 files)
User Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/110.0
Steps to reproduce:
- Went to Ubiquity Edge Router X that uses self-signed certificate
Actual results:
Firefox says connection is not secure, when opposite is correct. Probably due to accepted self-signed exception?
Expected results:
Connection is secure correctly stated even for self-signed accepted exceptions.
This is where mostly some UI cleanup / wording change is needed.
So this is mostly UI issue with different messages when the actual SSL is self-signed and accepted and while HTTPS connection is completely secure. Firefox states confusingly otherwise.
Comment 4•3 years ago
|
||
The Bugbug bot thinks this bug should belong to the 'Core::Security: PSM' component, and is moving the bug to that component. Please correct in case you think the bot is wrong.
Updated•3 years ago
|
Comment 5•3 years ago
|
||
Adding the Qa not actionable tag for now. We currently dont have an Ubiquity Edge Router X router in order to reach that setup page.
It should be possible to repeat and see this for any self-signed page. I haven't tried.
Comment 8•3 years ago
|
||
You can reproduce the issue with e.g. https://wrong.host.badssl.com/.
Comment 9•3 years ago
|
||
I was able to reproduce this issue using the link from Comment 8, after accepting the risk and continued it would show Connection not secure but in the panel it shows that the connection is encrypted.
Thank you @Dana for the help.
Description
•