New issue
Advanced search Search tips

Issue 708864 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 308330
Owner: ----
Closed: Apr 2017
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug-Security



Sign in to add a comment

Not respecting wildcard SSL certificates with trusted CA Root

Reported by thehunmo...@gmail.com, Apr 6 2017

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3053.3 Safari/537.36

Steps to reproduce the problem:
1. Install a root certificate as trusted
2. Create a wildcard SSL certificate using that root certificate (*.example.com)
3. Configure a site to use that certificate (www.example.com)
4. Visit the site
5. Chrome reports a NET::ERR_CERT_COMMON_NAME_INVALID error

What is the expected behavior?
Chrome should report no error.

What went wrong?
The site is not respected as a properly validated secure site.

Did this work before? Yes 57

Chrome version: 59.0.3053.3  Channel: dev
OS Version: OS X 10.12.4
Flash Version: 

I've attached screenshots showing the issue. Chrome reports my certificate itself as valid under Developer Tools -> Security, but throws insecure warnings on the general Developer Tools -> Security page, and when visiting any web page in the affected domain.

I sure hope this is a regression, because it would suck if wildcard SSL certs didn't work in Chrome any more.
 
browser-security-warning.png
25.2 KB View Download
security-overview.png
64.3 KB View Download
valid-cert.png
55.9 KB View Download
Labels: Needs-Feedback
The error message seems to indicate that you don't have a SubjectAltName set in your certificate. Support for the common name fallback was removed as of Chrome 58. You should configure your self-added certificate includes a SubjectAltName and that should work. See  crbug.com/308330 .

NET::ERR_CERT_COMMON_NAME_INVALID is exactly the error that not having a SubjectAltName set in your certificate will throw. There is work going on to make this more clear.

Comment 2 by a...@chromium.org, Apr 6 2017

Mergedinto: 308330
Status: Duplicate (was: Unconfirmed)
Project Member

Comment 3 by sheriffbot@chromium.org, Jul 14 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment