Closed Bug 197450 Opened 22 years ago Closed 22 years ago

Invalid certificate message for valid certificate

Categories

(Core Graveyard :: Security: UI, defect)

Other Branch
x86
Windows 2000
defect
Not set
major

Tracking

(Not tracked)

VERIFIED INVALID

People

(Reporter: mdinowit, Assigned: ssaux)

References

()

Details

User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3) Gecko/20030312 Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3) Gecko/20030312 A new certificate from verisign was just installed and registers as legal on IE. Mozilla 1.3 throws an -8101 error every time. No changes to the webserver will cause it to work. Url is: https://secure.lotauctions.com/index.html Reproducible: Always Steps to Reproduce: 1.go to https://secure.lotauctions.com/index.html 2. see the error message 3. Actual Results: error message on each request Expected Results: a secure html page works on IE
-> PSM
Assignee: asa → ssaux
Component: Browser-General → Client Library
Product: Browser → PSM
QA Contact: asa → junruh
Version: Trunk → unspecified
c also bugs 185610, 196390
QA Contact: junruh → bmartin
This is the response from Bob Denny, author of Website: Yes, this is something I have seen. The cert does not have in its X.509V3 permission the authorized key usage needed for it to be used for "server authentication". IE will accept a server cert that is not permitted to be a server cert. Mozilla will (properly) refuse to accept it. The archaeological Netscape 4 and all versions of Opera will also ignore the X.509V3 AKI info and accept a cert that is not permitted to be used for server authentication. The problem is in the cert. I've been over this ad nauseum, but the issuer is apparently clueless. It appears that Mozilla is being more strict with certificates than IE is.
Status: UNCONFIRMED → RESOLVED
Closed: 22 years ago
Resolution: --- → INVALID
Verified.
Status: RESOLVED → VERIFIED
Product: PSM → Core
Product: Core → Core Graveyard
You need to log in before you can comment on or make changes to this bug.