New issue
Advanced search Search tips

Issue 596894 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Revoked certificates only refreshed on browser launch

Reported by sgra...@topnotchtech.com, Mar 22 2016

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.87 Safari/537.36

Steps to reproduce the problem:
1. Visit an HTTPS site
2. Add that certificate to your computer's untrusted store
3. Close the tab and relaunch the same site

What is the expected behavior?
Should get a revoked cert error

What went wrong?
The site loads anyway. Pulling up the cert info from Chrome shows that the certificate is in fact revoked. If you close chrome and reload, only THEN does the error come up saying that the site certificate is revoked.

Did this work before? N/A 

Chrome version: 49.0.2623.87  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: Shockwave Flash 21.0 r0
 

Comment 1 by wfh@chromium.org, Mar 22 2016

Cc: rsleevi@chromium.org davidben@chromium.org
Components: Internals>Network>SSL
I think this might be working as intended based on previous bugs e.g. see  issue 496299  and  issue 133351  but adding the SSL folks to confirm.
Cc: rch@chromium.org
Status: WontFix (was: Unconfirmed)
Correct, this is WontFix/WAI. There's a short-lived cache of certificate validation results; closing and relaunching is one way to guarantee this will change, otherwise after 30 minutes it will take effect.

Comment 3 Deleted

Understood and thank you. A 30 minute timeout does seem reasonable.

Comment 5 by wfh@chromium.org, Mar 22 2016

Labels: -Restrict-View-SecurityTeam
Project Member

Comment 6 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 7 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment