New issue
Advanced search Search tips

Issue 663057 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

ERR_CERTIFICATE_TRANSPARENCY_REQUIRED error when accessing https://www.americanexpress.com/

Reported by al...@allanandshelley.ca, Nov 7 2016

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.80 Safari/537.36

Steps to reproduce the problem:
1. open chrome (beta channel)
2. www.americanexpress.com in address bar
3. see ERR_CERTIFICATE_TRANSPARENCY_REQUIRED error 

What is the expected behavior?
site should load without error.  Firefox (49.02) on same machine loads the site without error.

What went wrong?
Certificate Error
There are issues with the site's certificate chain (net::ERR_CERTIFICATE_TRANSPARENCY_REQUIRED).

Did this work before? Yes 

Chrome version: 53.0.2785.80  Channel: n/a
OS Version: ubuntu 16.04 LTS
Flash Version: Shockwave Flash 23.0 r0

Last accessed amex site Oct 11, 2016, not sure what version chrome at that point, but I was running beta channel at the time.
 
Components: Internals>Network>Certificate Internals>Network>CertTrans
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Hello! This sounds like it's probably a problem with the site's configuration. If you're able to reproduce this, could you please attach a net-internals log as described in https://dev.chromium.org/for-testers/providing-network-details?

Removing security labels since the site is failing closed.

Comment 2 by eranm@chromium.org, Nov 7 2016

FWIW I've just checked the site, the certificate used seems to have two embedded  SCTs and is valid for less than 2 years, so should be CT-compliant.
added network log as requested - from incognito window with no other activity.

Note, this is 100% reproduceable for me.  Its not clear from the last two comments whether it's loading correctly for either commenter.
net-internals-log.json
182 KB View Download
Labels: Needs-Feedback
The reporter is running an out of date Chrome version - 53.0.2785.80, when current stable is 54.0.2840.90

If you update your Chromium, does that resolve the issue?

re: Comment 2: It's likely failing because it's outside the 10 week build period to have the logs recognized, and since no logs are recognized, it's not CT compliant.
interesting. not sure why my chrome isn't auto-updating. This makes sense. Go ahead and close the ticket. I'll report again if it occurs after updating.
Status: WontFix (was: Unconfirmed)

Comment 7 by eranm@chromium.org, Nov 7 2016

Ryan, do you think we should indicate a different error if the build is not timely? The CT error is a bit of a red herring in this case.
fyi, updated to current chrome beta build (55.0.2883.35) and all is well.  

rsleevi was correct.  My bad for not realising that the beta version isn't auto-updated automatically on ubuntu (and perhaps other os), and not looking for that before reporting the issue.

Sign in to add a comment