Self-signed SSL certificates should not be labeled as "invalid"
Categories
(Firefox :: Security, enhancement)
Tracking
()
People
(Reporter: VanillaMozilla, Unassigned)
References
Details
(Whiteboard: PLEASE READ COMMENT 42 BEFORE COMMENTING)
Attachments
(2 files)
Updated•17 years ago
|
| Reporter | ||
Comment 3•17 years ago
|
||
Comment 7•17 years ago
|
||
Comment 8•17 years ago
|
||
Comment 9•17 years ago
|
||
Comment 10•17 years ago
|
||
Comment 11•17 years ago
|
||
Comment 12•17 years ago
|
||
Comment 13•17 years ago
|
||
Comment 14•17 years ago
|
||
Comment 15•17 years ago
|
||
Comment 16•17 years ago
|
||
Comment 17•17 years ago
|
||
Comment 18•17 years ago
|
||
Comment 19•17 years ago
|
||
Comment 20•17 years ago
|
||
Comment 21•17 years ago
|
||
Comment 22•17 years ago
|
||
Comment 23•17 years ago
|
||
Comment 24•17 years ago
|
||
Comment 25•17 years ago
|
||
Comment 26•17 years ago
|
||
Comment 27•17 years ago
|
||
Comment 28•17 years ago
|
||
Comment 29•17 years ago
|
||
Comment 30•17 years ago
|
||
Comment 31•17 years ago
|
||
| Reporter | ||
Comment 32•17 years ago
|
||
Comment 33•17 years ago
|
||
Comment 34•17 years ago
|
||
Comment 35•17 years ago
|
||
Comment 36•17 years ago
|
||
Comment 37•17 years ago
|
||
Comment 38•17 years ago
|
||
Comment 39•17 years ago
|
||
Comment 40•17 years ago
|
||
Comment 41•17 years ago
|
||
| Reporter | ||
Comment 42•17 years ago
|
||
Comment 43•17 years ago
|
||
Comment 44•17 years ago
|
||
| Reporter | ||
Comment 45•17 years ago
|
||
Comment 46•17 years ago
|
||
| Reporter | ||
Comment 47•17 years ago
|
||
Comment 48•16 years ago
|
||
Comment 49•16 years ago
|
||
Comment 50•16 years ago
|
||
Comment 51•16 years ago
|
||
Comment 53•16 years ago
|
||
| Reporter | ||
Comment 54•15 years ago
|
||
Comment 55•14 years ago
|
||
Comment 57•9 years ago
|
||
Updated•3 years ago
|
Comment 58•3 years ago
|
||
The severity field for this bug is relatively low, S3. However, the bug has 16 votes.
:serg, could you consider increasing the bug severity?
For more information, please visit auto_nag documentation.
Comment 59•3 years ago
|
||
The last needinfo from me was triggered in error by recent activity on the bug. I'm clearing the needinfo since this is a very old bug and I don't know if it's still relevant.
Comment 60•2 months ago
|
||
This bug is being addressed in the new network error page designs (Bug 1990918), that is enabled Nightly-only for now (Bug 2011043) and will at some point ride the train (Bug 1990918). The new design is gated behind security.certerrors.felt-privacy-v1 pref being set to true. Attaching a screenshot of the new design. I think we can close this bug once the new design rides the train.
Be careful. Something doesn’t look right.
Nightly spotted a potentially serious security issue with self-signed.badssl.com. Someone pretending to be the site could try to steal things like credit card info, passwords, or emails.Advanced
What makes the site look dangerous?
Because there’s an issue with the site’s certificate. Sites use certificates issued by a certificate authority to prove they’re really who they say they are. This site’s certificate is self-signed. It wasn’t issued by a recognized certificate authority – so we don’t trust it by default.
What can you do about it?
Not much. It’s likely there’s a problem with the site itself.
IMPORTANT NOTE: If you are trying to visit this site on a corporate intranet, your IT staff may use self-signed certificates. They can help you check their authenticity.
Comment 61•2 months ago
|
||
Also adding current/old design as reference.
Warning: Potential Security Risk Ahead
Nightly detected a potential security threat and did not continue to self-signed.badssl.com. If you visit this site, attackers could try to steal information like your passwords, emails, or credit card details.self-signed.badssl.com uses an invalid security certificate.
The certificate is not trusted because it is self-signed.
Description
•