Bug#769381: iceweasel does not report for self-signed certificate (MITM to youtube.com)

Mike Hommey mh at glandium.org
Thu Nov 13 14:50:42 UTC 2014


tag 769381 unreproducible
thanks

On Thu, Nov 13, 2014 at 06:04:53PM +0600, Stanislav Vlasov wrote:
> 2014-11-13 15:05 GMT+05:00 Mike Hommey <mh at glandium.org>:
> >> Package: iceweasel
> >> Version: 31.2.0esr-2~deb7u1
> >> Severity: normal
> >>
> >> Dear Maintainer,
> >>
> >> My internet provider add url-filtration for https by using self-signed
> >> certificates.
> >> Google Chrome (from google) and Chromium (from Debian) see it and fail.
> >> Iceweasel does nothing, as if cert is valid.
> >>
> >> I am exec openssl s_client -connect www.youtube.com:443 via filter and
> >> direct and attach output
> >
> > What does it say on
> > https://www.pcwebshop.co.uk/ ? If it shows the untrusted screen, what
> > does it say under technical details ?
> 
> Expired cert and "Parallels Panel" as CN.

Here it says:

www.pcwebshop.co.uk uses an invalid security certificate.
The certificate is not trusted because it is self-signed.
The certificate is only valid for Parallels Panel
The certificate expired on 10/09/12 19:24. The current time is (...).
(Error code: sec_error_unknown_issuer)

Can you try https://kuix.de:9453/ ?

Here it says:

kuix.de:9453 uses an invalid security certificate.
The certificate is not trusted because it is self-signed.
(Error code: sec_error_unknown_issuer)

(and I double checked with the version in wheezy because i only had
tested the version in unstable)

Mike



More information about the pkg-mozilla-maintainers mailing list