New issue
Advanced search Search tips

Issue 665484 link

Starred by 9 users

Issue metadata

Status: Duplicate
Merged: issue 664177
Owner: ----
Closed: Nov 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

certificate transparency error on several sites

Reported by mlpok...@gmail.com, Nov 15 2016

Issue description

<b>Chrome Version       : <Copy from: 'about:version'></b>
URLs (if applicable) :https://www.amazon.de/dp/B00QJDO0QC/ref=nav_shopall_k_dpmwi6
https://www.aliexpress.com/
Other browsers tested: Firefox
  Add OK or FAIL, along with the version, after other browsers where you
have tested this issue:
     Safari:N/A
    Firefox:OK
         IE:N/A

What steps will reproduce the problem?
(1) Opening amazon or aliexpress
(2)
(3)

What is the expected result?
Page to be opened

What happens instead?
Attackers might be trying to steal your information from www.amazon.de (for example, passwords, messages, or credit cards). NET::ERR_CERTIFICATE_TRANSPARENCY_REQUIRED

Please provide any additional information below. Attach a screenshot if
possible.
PC time checked, synchronized and looking correctly.

 
Screenshot from 2016-11-15 19-10-15.png
33.3 KB View Download
Same here.
53.0.2785.143 Built on Ubuntu , running on Ubuntu 14.04 (64-bit).

https://www.amazon.de/ (.com works)
https://www.aliexpress.com/
https://moneta.cz/ (a bank! parents are scared to hell)
https://www.seznam.cz/

others work, including www.amazon.com

Same for www.abnamro.com (a bank); works fine in Firefox.

Text of the error message:

Your connection is not private

Attackers might be trying to steal your information from www.abnamro.nl (for example, passwords, messages, or credit cards). NET::ERR_CERTIFICATE_TRANSPARENCY_REQUIRED
Subject: www.abnamro.nl
Issuer: Symantec Class 3 EV SSL CA - G3
Expires on: Apr 14, 2017
Current date: Nov 15, 2016
PEM encoded chain: -----BEGIN CERTIFICATE-----
MIIGjTCCBXWgAwIBAgIQPefDNO6Or+YxLblXsqkYyTANBgkqhkiG9w0BAQsFADB3
MQswCQYDVQQGEwJVUzEdMBsGA1UEChMUU3ltYW50ZWMgQ29ycG9yYXRpb24xHzAd
BgNVBAsTFlN5bWFudGVjIFRydXN0IE5ldHdvcmsxKDAmBgNVBAMTH1N5bWFudGVj
IENsYXNzIDMgRVYgU1NMIENBIC0gRzMwHhcNMTYxMDI3MDAwMDAwWhcNMTcwNDEz
MjM1OTU5WjCCAQExEzARBgsrBgEEAYI3PAIBAxMCTkwxHTAbBgNVBA8TFFByaXZh
dGUgT3JnYW5pemF0aW9uMREwDwYDVQQFEwgzNDMzNDI1OTELMAkGA1UEBhMCTkwx
DzANBgNVBBEMBjEwODJQUDEWMBQGA1UECAwNTm9vcmQgSG9sbGFuZDESMBAGA1UE
BwwJQW1zdGVyZGFtMR0wGwYDVQQJDBRHdXN0YXYgTWFobGVybGFhbiAxMDEbMBkG
A1UECgwSQUJOIEFNUk8gQmFuayBOLlYuMRkwFwYDVQQLDBBJbnRlcm5ldCBCYW5r
aW5nMRcwFQYDVQQDDA53d3cuYWJuYW1yby5ubDCCASIwDQYJKoZIhvcNAQEBBQAD
ggEPADCCAQoCggEBAMnDfDMR148itnIhMCcuxT+rHkBjB/8DyQP2i1TaxeuclSLl
1YTocwHinV93McrVgUuj2RTCaZmuBBjmmus/RcvrI6/+YxCf+1jP2cdO6xa1ooCE
69J4Vv2/y9r/SXDejXqZJ06GVfHhiw3zGMKCjdVd+KsfrUehZQXLlmMLMlHeiz5H
hBim6W2qqJvXtjjM3gJJjRiaW/00gsTuzOVDCE7b1wLT9zfw70lC2+CU16TV9i9f
ERSvBNvhPWmt7MT9dBiEzgWVsSBrJ2tRFz5e3pty45wnx7tTjszaL/axlRgrQA0L
wDrYBun4j299GZbd+w8AKskTqjtaSGz1ayBqBJ8CAwEAAaOCAocwggKDMCUGA1Ud
EQQeMByCDnd3dy5hYm5hbXJvLm5sggphYm5hbXJvLm5sMAkGA1UdEwQCMAAwDgYD
VR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjBvBgNV
HSAEaDBmMAcGBWeBDAEBMFsGC2CGSAGG+EUBBxcGMEwwIwYIKwYBBQUHAgEWF2h0
dHBzOi8vZC5zeW1jYi5jb20vY3BzMCUGCCsGAQUFBwICMBkMF2h0dHBzOi8vZC5z
eW1jYi5jb20vcnBhMB8GA1UdIwQYMBaAFAFZq+fdOgtZpmRj1s8gB1fVkedqMCsG
A1UdHwQkMCIwIKAeoByGGmh0dHA6Ly9zci5zeW1jYi5jb20vc3IuY3JsMFcGCCsG
AQUFBwEBBEswSTAfBggrBgEFBQcwAYYTaHR0cDovL3NyLnN5bWNkLmNvbTAmBggr
BgEFBQcwAoYaaHR0cDovL3NyLnN5bWNiLmNvbS9zci5jcnQwggEGBgorBgEEAdZ5
AgQCBIH3BIH0APIAdwDd6x0reg1PpiCLga2BaHB+Lo6dAdVciI09EcTNtuy+zAAA
AVgEwueAAAAEAwBIMEYCIQC6ApXGu+YeiHgRmNgQt7KzSIMqOIxkvhoSeNkgpJR6
IQIhAPB05uB68jC4VKZbd2+Jp81292CvT1oeGpOtOV/D0qYtAHcAaPaY+B9kgr46
jO65KB1M/HFRXWeT1ETRCmesu09P+8QAAAFYBMLnogAABAMASDBGAiEAndudiZve
iTO3z2WQedIdb/TJE4mDIdff6IeOCy47QW4CIQCLw28k8eZR1QGJFrJEjEYefcA+
A+cSsf8pIauwvuIlfjANBgkqhkiG9w0BAQsFAAOCAQEAjf3eT2jLL+HHAHam5g92
ypM9NALKUeNwmrCrWFdHa3WBtQCAo04LTmmyFZF/6vJIxi0dTYZvsOo2K58p/1x5
YKzz01f4bGAzIsBjQPxVj4EC5u/l4KostAHkaP8qH5f0bsViosTuuc8ZZcZZRMvG
kMR/HQI0FCeXW6rx7fgGL0VjWOIaQqiooO6gp0o+6byR8y6ApeQz8EECcfXqFV7m
8eG7sO/h9jJBQFPPJ/SOjWX9cv72BY1GnvTHQG3d8Ty6WStLlgVZbU98ijjYyc7Y
U+dMvhmxcmn37X9ChNQwHNiAx6WZe/oaSpdXuDGgRR+ntlaYEhm1mhf40aEG3j/Q
pw==
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFKzCCBBOgAwIBAgIQfuFKb2/v8tN/P61lTTratDANBgkqhkiG9w0BAQsFADCB
yjELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL
ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTowOAYDVQQLEzEoYykgMjAwNiBWZXJp
U2lnbiwgSW5jLiAtIEZvciBhdXRob3JpemVkIHVzZSBvbmx5MUUwQwYDVQQDEzxW
ZXJpU2lnbiBDbGFzcyAzIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0
aG9yaXR5IC0gRzUwHhcNMTMxMDMxMDAwMDAwWhcNMjMxMDMwMjM1OTU5WjB3MQsw
CQYDVQQGEwJVUzEdMBsGA1UEChMUU3ltYW50ZWMgQ29ycG9yYXRpb24xHzAdBgNV
BAsTFlN5bWFudGVjIFRydXN0IE5ldHdvcmsxKDAmBgNVBAMTH1N5bWFudGVjIENs
YXNzIDMgRVYgU1NMIENBIC0gRzMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQDYoWV0I+grZOIy1zM3PY71NBZI3U9/hxz4RCMTjvsR2ERaGHGOYBYmkpv9
FwvhcXBC/r/6HMCqo6e1cej/GIP23xAKE2LIPZyn3i4/DNkd5y77Ks7Imn+Hv9hM
BBUyydHMlXGgTihPhNk1++OGb5RT5nKKY2cuvmn2926OnGAE6yn6xEdC0niY4+wL
pZLct5q9gGQrOHw4CVtm9i2VeoayNC6FnpAOX7ddpFFyRnATv2fytqdNFB5suVPu
IxpOjUhVQ0GxiXVqQCjFfd3SbtICGS97JJRL6/EaqZvjI5rq+jOrCiy39GAI3Z8c
zd0tAWaAr7MvKR0juIrhoXAHDDQPAgMBAAGjggFdMIIBWTAvBggrBgEFBQcBAQQj
MCEwHwYIKwYBBQUHMAGGE2h0dHA6Ly9zMi5zeW1jYi5jb20wEgYDVR0TAQH/BAgw
BgEB/wIBADBlBgNVHSAEXjBcMFoGBFUdIAAwUjAmBggrBgEFBQcCARYaaHR0cDov
L3d3dy5zeW1hdXRoLmNvbS9jcHMwKAYIKwYBBQUHAgIwHBoaaHR0cDovL3d3dy5z
eW1hdXRoLmNvbS9ycGEwMAYDVR0fBCkwJzAloCOgIYYfaHR0cDovL3MxLnN5bWNi
LmNvbS9wY2EzLWc1LmNybDAOBgNVHQ8BAf8EBAMCAQYwKQYDVR0RBCIwIKQeMBwx
GjAYBgNVBAMTEVN5bWFudGVjUEtJLTEtNTMzMB0GA1UdDgQWBBQBWavn3ToLWaZk
Y9bPIAdX1ZHnajAfBgNVHSMEGDAWgBR/02Wnwt3su/AwCfNDOfoCrzMxMzANBgkq
hkiG9w0BAQsFAAOCAQEAQgFVe9AWGl1Y6LubqE3X89frE5SG1n8hC0e8V5uSXU8F
nzikEHzPg74GQ0aNCLxq1xCm+quvL2GoY/Jl339MiBKIT7Np2f8nwAqXkY9W+4nE
qLuSLRtzsMarNvSWbCAI7woeZiRFT2cAQMgHVHQzO6atuyOfZu2iRHA0+w7qAf3P
eHTfp61Vt19N9tY/4IbOJMdCqRMURDVLtt/JYKwMf9mTIUvunORJApjTYHtcvNUw
LwfORELEC5n+5p/8sHiGUW3RLJ3GlvuFgrsEL/digO9i2n/2DqyQuFa9eT/ygG6j
2bkPXToHHZGThkspTOHcteHgM52zyzaRS/6htO7w+Q==
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIE0zCCA7ugAwIBAgIQGNrRniZ96LtKIVjNzGs7SjANBgkqhkiG9w0BAQUFADCB
yjELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL
ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTowOAYDVQQLEzEoYykgMjAwNiBWZXJp
U2lnbiwgSW5jLiAtIEZvciBhdXRob3JpemVkIHVzZSBvbmx5MUUwQwYDVQQDEzxW
ZXJpU2lnbiBDbGFzcyAzIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0
aG9yaXR5IC0gRzUwHhcNMDYxMTA4MDAwMDAwWhcNMzYwNzE2MjM1OTU5WjCByjEL
MAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQLExZW
ZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTowOAYDVQQLEzEoYykgMjAwNiBWZXJpU2ln
biwgSW5jLiAtIEZvciBhdXRob3JpemVkIHVzZSBvbmx5MUUwQwYDVQQDEzxWZXJp
U2lnbiBDbGFzcyAzIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9y
aXR5IC0gRzUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCvJAgIKXo1
nmAMqudLO07cfLw8RRy7K+D+KQL5VwijZIUVJ/XxrcgxiV0i6CqqpkKzj/i5Vbex
t0uz/o9+B1fs70PbZmIVYc9gDaTY3vjgw2IIPVQT60nKWVSFJuUrjxuf6/WhkcIz
SdhDY2pSS9KP6HBRTdGJaXvHcPaz3BJ023tdS1bTlr8Vd6Gw9KIl8q8ckmcY5fQG
BO+QueQA5N06tRn/Arr0PO7gi+s3i+z016zy9vA9r911kTMZHRxAy3QkGSGT2RT+
rCpSx4/VBEnkjWNHiDxpg8v+R70rfk/Fla4OndTRQ8Bnc+MUCH7lP59zuDMKz10/
NIeWiu5T6CUVAgMBAAGjgbIwga8wDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8E
BAMCAQYwbQYIKwYBBQUHAQwEYTBfoV2gWzBZMFcwVRYJaW1hZ2UvZ2lmMCEwHzAH
BgUrDgMCGgQUj+XTGoasjY5rw8+AatRIGCx7GS4wJRYjaHR0cDovL2xvZ28udmVy
aXNpZ24uY29tL3ZzbG9nby5naWYwHQYDVR0OBBYEFH/TZafC3ey78DAJ80M5+gKv
MzEzMA0GCSqGSIb3DQEBBQUAA4IBAQCTJEowX2LP2BqYLz3q3JktvXf2pXkiOOzE
p6B4Eq1iDkVwZMXnl2YtmAl+X6/WzChl8gGqCBpH3vn5fJJaCGkgDdk+bW48DW7Y
5gaRQBi5+MHt39tBquCWIMnNZBU4gcmU7qKEKQsTb47bDN0lAtukixlE0kF6BWlK
WE9gyn6CagsCqiUXObXbf+eEZSqVir2G3l6BFoMtEMze/aiCKm0oHw0LxOXnGiYZ
4fQRbxC1lfznQgUy286dUV4otp6F01vvpX1FQHKOtw5rDgb7MzVIcbidJ4vEZV8N
hnacRHr2lVz2XTIIM6RUthg/aFzyQkqFOFSDX9HoLPKsEdao7WNq
-----END CERTIFICATE-----
  Automatically report details of possible security incidents to Google. Privacy policy
ReloadHIDE ADVANCED
www.abnamro.nl normally uses encryption to protect your information. When Chromium tried to connect to www.abnamro.nl this time, the website sent back unusual and incorrect credentials. This may happen when an attacker is trying to pretend to be www.abnamro.nl, or a Wi-Fi sign-in screen has interrupted the connection. Your information is still secure because Chromium stopped the connection before any data was exchanged.

You cannot visit www.abnamro.nl right now because the website uses HSTS. Network errors and attacks are usually temporary, so this page will probably work later.

About page of the browser:
Chromium	53.0.2785.143 (Developer Build) Built on Ubuntu , running on Ubuntu 16.04 (64-bit)
Revision	12ae4ebf489873fc4aad9efc231b9151b330a938
OS	Linux 
Blink	537.36 (@12ae4ebf489873fc4aad9efc231b9151b330a938)
JavaScript	V8 5.3.332.47
Flash	11.2.999.999
User Agent	Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/53.0.2785.143 Chrome/53.0.2785.143 Safari/537.36
Command Line	/usr/lib/chromium-browser/chromium-browser --ppapi-flash-path=/usr/lib/adobe-flashplugin/libpepflashplayer.so --ppapi-flash-version --enable-pinch --window-depth=24 --x11-visual-id=33 --wm-user-time-ms=689432738 --flag-switches-begin --flag-switches-end
Executable Path	/usr/lib/chromium-browser/chromium-browser
Profile Path	/home/schmidt/.config/chromium/Default
Variations	918346b9-3f4a17df
ba3f87da-92cc81ec
f049a919-3f4a17df
dd4da2fc-3f4a17df
43d0dd1e-3f4a17df
2e109477-e2e291f1
64cbdfc2-3f4a17df
b7786474-d93a0620
868bda90-3f4a17df
4ea303a6-3f4a17df
fa99bb73-3f4a17df
3d7e3f6a-2eb01455
f8c15c50-3f4a17df
9736de91-3f4a17df
30e679f-3f4a17df
ad6d27cc-3e870323
867c4c68-3f4a17df
d747916f-d747916f
fe05be5f-4ad60575

Comment 3 by and...@sambrook.net, Nov 15 2016

Same here with eBay's payment pages, amazon.co.uk and petition.parliament.uk.


Comment 4 by ttso...@gmail.com, Nov 16 2016

Same here. 
abnamro.nl (bank)
mail.yahoo.com
They both work fine in Firefox.

Chromium version: Version 53.0.2785.143 Built on Ubuntu , running on Ubuntu 14.04
Same here on https://youtrack.jetbrains.com/issue/WI-8962. Some pages are loading to varying degrees eg aws.amazon.com (no page resources loaded) and controls not functioning on other sites with JS libraries failing to load from popular CDN's.

Version 53.0.2785.143 Built on Ubuntu , running on Ubuntu 16.04 (64-bit)

Comment 6 Deleted

https://amazon.com also stopped working: https://bugs.chromium.org/p/chromium/issues/detail?id=665783

I've found some other sites too:
https://aws.amazon.com/ (fails to load some resources)
https://www.ebay.de/
https://soundcloud.com (fails to load some resources)
https://banking.raiffeisen.at

This issue should be fixed very soon as it makes chromium unusable for certain https sites.
Same with https://www.etsy.com/

It works well on Firefox.
a help.yahoo.com page
Screenshot_2016-11-17_06-59-14.png
31.8 KB View Download
I have the exact same screens as posted originally!!! Seriously how long can this go on 4 days for me now and using 4 different laptops ... who is responsible?
https is there for a reason so to say ignore it is foolish ... so restricting not being able to log into eBay, Hotmail, and at times Santander!!!
Same here. Several legitimate sites blocked. Many images blocked on multiple sites, notably Amazon. Sites blocked include UK Government petition site. Works fine in Chrome.
Mergedinto: 664177
Status: Duplicate (was: Unconfirmed)
Thanks. Fixed. :-)

Comment 14 by mlpok...@gmail.com, Nov 17 2016

Updating to Chromium to version 54 resolves the issue.
For linux mint:
sudo add-apt-repository ppa:canonical-chromium-builds/stage
sudo apt-get update
sudo apt-get install chromium-browser
Hello, thank you for your help, updated Chrome to version 54 , problem solved :)
Why isn't there a hotfix for this? We shouldn't have to install Chrome beta or a Chromium ppa for a bug this severe. With version numbers as granular as 53.0.2785.143 surely you can release a stable version with this fixed?
same here
error
Your connection is not private

Attackers might be trying to steal your information from sellercentral.amazon.in (for example, passwords, messages, or credit cards). NET::ERR_CERTIFICATE_TRANSPARENCY_REQUIRED


Screenshot (49).png
90.7 KB View Download

Sign in to add a comment