Closed Bug 1892415 Opened 10 months ago Closed 10 months ago

Firefox is wrongfully display SSL_ERROR_BAD_CERT_DOMAIN on .onion domains even the cert domain and real domain is the same entity

Categories

(Core :: Security: PSM, defect)

Firefox 125
defect

Tracking

()

RESOLVED WONTFIX

People

(Reporter: u753276, Unassigned)

References

Details

Attachments

(1 file)

Steps to reproduce:

Visit https://ombrelo.im5wixghmfmt7gf7wb4xrgdm6byx2gj26zn47da6nwo7xvybgxnqryid.onion/ with either Firefox or the Tor Browser.

Actual results:

"..does not trust this site because it uses a certificate that is not valid for.."

Error code: SSL_ERROR_BAD_CERT_DOMAIN

Expected results:

Not a "SSL_ERROR_BAD_CERT_DOMAIN" error but only SELF_SIGN warning only, because the cert domain is identical or wildcard to the website domain.

The Bugbug bot thinks this bug should belong to the 'Core::Security: PSM' component, and is moving the bug to that component. Please correct in case you think the bot is wrong.

Component: Untriaged → Security: PSM
Product: Firefox → Core

Could you attach a copy of the certificate here?

The reporter deleted their account after filing the bug—we're unlikely to get an answer from them.

Maybe we can get this info from someone else who uses Tor; if not we'll have to close this INCOMPLETE.

The certificate doesn't have a subjectAltName extension, and we no longer support subject common name matching.

Status: UNCONFIRMED → RESOLVED
Closed: 10 months ago
Resolution: --- → WONTFIX
See Also: → 1245280
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: