New issue
Advanced search Search tips

Issue 708998 link

Starred by 7 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug
Team-Security-UX



Sign in to add a comment

Self-signed certificate not being accepted. Returns err_insecure_response

Reported by brandonh...@gmail.com, Apr 6 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0

Example URL:
URL's are internal

Steps to reproduce the problem:
1. Launch Chrome version 57.0.2987.133
2. Navigate to a site with a self signed cert
3. Accept certificate warning
4. Navigate to a page with an iframe
5. iframe fails to load with error  Failed to load resource: net::ERR_INSECURE_RESPONSE

What is the expected behavior?
The iframe's should load without issue since the certificate was accepted.  

What went wrong?
The frame fails to load the iframe with an error displayed to the end user that appears the page is down.  Dev console shows the Failed to load resource: net::ERR_INSECURE_RESPONSE error. 

Does it occur on multiple sites: Yes

Is it a problem with a plugin? No 

Did this work before? Yes Version 56

Does this work in other browsers? Yes

Chrome version: 57.0.2987.133  Channel: stable
OS Version: 10.0
Flash Version: 

This is the same bug that was previously fixed  Issue 565540 

This is really frustrating when working with equipment that typically will have a self signed certificate or an older sha-1 cert.  Understanding that there is a security risk but once you accept the risk the browser should remember that choice at least for that session.
 
As an update this appears to work correctly in Chromium Version 59.0.3065.0 (Developer Build) (32-bit) So maybe it will be fixed in a later build of Chrome?
Components: -Blink Internals>Network>Certificate UI>Browser>Interstitials
Status: WontFix (was: Unconfirmed)
Since it sounds fixed already, going to mark this as WontFix.

Comment 4 by karla...@gmail.com, Jul 26 2017

This is occurring for me in Version 60.0.3112.78 (Official Build) beta (64-bit) on Windows 10. Immediately after clicking through the cert warning (in my case, for an Ubiquiti Edgerouter config page), most of the CSS and JS files fail to load with ERR_INSECURE_RESPONSE in the console. I've resorted to leaving Fiddler open all the time with it's MITM decryption feature turned on, because for some reason Chrome will accept that locally-installed cert but won't take the Ubiquiti one.
edgerouter errors.PNG
46.1 KB View Download

Sign in to add a comment