New issue
Advanced search Search tips

Issue 713816 link

Starred by 0 users

Issue metadata

Status: Duplicate
Merged: issue 700595
Owner: ----
Closed: Apr 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

"Your connection is not private" for certificate which worked before upgrading Chrome

Reported by stu...@anchev.net, Apr 20 2017

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36

Steps to reproduce the problem:
1. Create own SSL certificate authority as explained here:

https://datacenteroverlords.com/2012/03/01/creating-your-own-ssl-certificate-authority/

(for the purpose of web development with a local Apache installation)

2. Open the local website using that certificate (in my case: https://test.local)

What is the expected behavior?
Should work without warning messages

What went wrong?
Getting a message:

Your connection is not private

Attackers might be trying to steal your information from test.local (for example, passwords, messages, or credit cards). NET::ERR_CERT_COMMON_NAME_INVALID

Automatically report details of possible security incidents to Google. Privacy policy
Back to safetyHIDE ADVANCED
This server could not prove that it is test.local; its security certificate is from [missing_subjectAltName]. This may be caused by a misconfiguration or an attacker intercepting your connection. Learn more.

Proceed to test.local (unsafe)

Did this work before? Yes 57.0.2987.133

Chrome version: 58.0.3029.81  Channel: stable
OS Version: openSUSE Leap 42.2
Flash Version: Shockwave Flash 25.0 r0

This has always worked in previous versions of Google Chrome. Currently I am also using Chromium 57.0.2987.133 and Firefox with the exact same settings as explained in step 1 - everything works without problems there. The issue started appearing after upgrading Google Chrome to 58.0.3029.81 about a day ago.
 

Comment 1 by stu...@anchev.net, Apr 20 2017

I have just tried also:

58.0.3029.81-1 (beta)
59.0.3071.9-1 (unstable)

The result is exactly the same - "Your connection is not private"

Cleaned cache, cookies, rebooted - no change. In the other browsers everything still works fine.
Mergedinto: 700595
Status: Duplicate (was: Unconfirmed)
missing_subjectAltName is your clue here. Please see https://textslashplain.com/2017/03/10/chrome-deprecates-subject-cn-matching/ for details on Chrome's deprecation of the SubjectCN field.
Components: Internals>Network>Certificate
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug

Comment 4 Deleted

Sign in to add a comment