Issue metadata
Sign in to add a comment
|
Receiving NET::ERR_CERT_COMMON_NAME_INVALID with trusted self-signed cert in latest update
Reported by
brandonh...@gmail.com,
Mar 24 2017
|
||||||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.33 Safari/537.36 Steps to reproduce the problem: 1. Verify certificate *.foo.com is in mac keychain access 2. Navigate to bar.foo.com in Chrome beta What is the expected behavior? Website loads as "secure" (as indicated in address bar). Communication between site and other sites on *.foo.com allowed. What went wrong? Regardless of certificate being trusted in my keychain, I am unable to view the site without receiving a NET::ERR_CERT_COMMON_NAME_INVALID warning. Clicking through to enable access to the site works does eventually allow me in. The website and the backend API are located as subdomains on *.foo.com and usually, if I access both and trust (if for some reason my certificate is not currently loaded) chrome will happily allow communication between the two. However, after updating I had to bounce back and forth between both sites, reload, and retrust (UI -> trust, API -> trust, UI -> trust) and then it eventually worked. This was not a problem prior to this update. Did this work before? Yes Previous version of beta Chrome version: 58.0.3029.33 Channel: beta OS Version: OS X 10.12.3 Flash Version: Will be checking stable chrome to see if the issue is also there.
,
Mar 24 2017
I've tested functionality in 57 and it works as expected.
,
Mar 24 2017
+elawrence@, do you know any change in M58 might cause this change of behavior? And if it actually WAI? Thanks!
,
Mar 24 2017
Chrome 58 deprecates the use of the SubjectCN field in Self-signed certificates; the certificate hostname must appear in the SubjectAltNames instead. https://textslashplain.com/2017/03/10/chrome-deprecates-subject-cn-matching/
,
Mar 24 2017
(To be precise, Chrome 58 deprecated the use of the SubjectCN field in ALL certificates, but public CAs were required to migrate to SubjectAltNames years ago). |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by brandonh...@gmail.com
, Mar 24 2017