Closed
Bug 744497
Opened 14 years ago
Closed 10 years ago
Visiting a site with a bad_cert_domain still shows the correct domain in the ssl part of the location bar
Categories
(Core Graveyard :: Security: UI, defect)
Tracking
(Not tracked)
RESOLVED
INVALID
People
(Reporter: quodlibetor, Assigned: michael)
Details
Attachments
(1 file)
|
5.80 KB,
image/png
|
Details |
User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:14.0) Gecko/20120409 Firefox/14.0a1
Build ID: 20120409031240
Steps to reproduce:
Visit https://campuscomputing.net/three-presidents-claim-third-ursinus-invitational
Actual results:
The "This certificate is for the wrong domain" page showed up.
The certificate was for "washjeff.edu", which is a legitimate site, and honestly it's weird that some of their content is on campuscomputing.net.
Then I went through to the page and the SSL "blue" section of the awesome bar said that I had a verified connection to "campuscomputing.net", despite the fact that the verification is for washjeff.edu.
Expected results:
I think that better behavior here would be to put "washjeff.edu" into the blue portion of the bar, to let people know that the certificate does not match the domain.
The "you have added a security exception for this site" text should probably be extended to say "because the certificate is for _________ but the page is _________".
Updated•13 years ago
|
Component: Untriaged → Security: UI
Product: Firefox → Core
Hi Brandon
I see the certificate is only valid for survey.campuscomputing.net
Could you also include a screen-shot of the explanation you made? It would be more clearer.
Flags: needinfo?(quodlibetor)
| Reporter | ||
Comment 2•10 years ago
|
||
Sorry, I can't reproduce the issue anymore, and possibly I misread it in the first place.
Flags: needinfo?(quodlibetor)
Thanks for the feedback Brandon.
Assignee: nobody → michael
Status: UNCONFIRMED → RESOLVED
Closed: 10 years ago
QA Contact: michael
Resolution: --- → INVALID
Updated•9 years ago
|
Product: Core → Core Graveyard
You need to log in
before you can comment on or make changes to this bug.
Description
•