New issue
Advanced search Search tips

Issue 664798 link

Starred by 4 users

Issue metadata

Status: Duplicate
Merged: issue 664177
Owner: ----
Closed: Nov 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Regression



Sign in to add a comment

ERR_INSECURE_RESPONSE because of BUILD_NOT_TIMELY on many SSL certs which are public

Reported by stuart.l...@gmail.com, Nov 13 2016

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/53.0.2785.143 Chrome/53.0.2785.143 Safari/537.36

Example URL:
https://ir.ebaystatic.com/rtm/3/RTMS/Image/9739_UK_Retail_Q2_RefurbishedTechHub_BREC_300x130.jpg

Steps to reproduce the problem:
1. Visit https://ir.ebaystatic.com/rtm/3/RTMS/Image/9739_UK_Retail_Q2_RefurbishedTechHub_BREC_300x130.jpg
2. Observe the Chromium "Your connection is not private" window is shown; under advanced, it says "The server presented a certificate that was not publicly disclosed using the Certificate Transparency policy. This is a requirement for some certificates, to ensure that they are trustworthy and protect against attackers."

What is the expected behavior?
The image is displayed

What went wrong?
chrome://net-internals for this request shows:
CERT_CT_COMPLIANCE_CHECKED
build_timely = false
certificate = (snip)
ct_compliance_status = "BUILD_NOT_TIMELY"

The cert for this page seems to be publicly transparent: see https://crt.sh/?q=8E+31+45+71+77+40+9F+31+FC+CE+26+09+25+8B+E7+26+8E+A2+3C+9F+D3+77+80+A2+5B+10+3E+A4+68+DD+32+E1

Did this work before? Yes don't know; recently

Chrome version: 53.0.2785.143  Channel: stable
OS Version: Ubuntu 16.04
Flash Version: Shockwave Flash 22.0 r0
 
Labels: TE-NeedsTriageHelp

Comment 3 by mmenke@chromium.org, Nov 14 2016

Components: -Internals>Network Internals>Network>SSL
Mergedinto: 664177
Status: Duplicate (was: Unconfirmed)

Sign in to add a comment