New issue
Advanced search Search tips

Issue 714214 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 700595
Owner: ----
Closed: Apr 2017
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Using Decrypt and Scan on firewall

Reported by rtantor...@gmail.com, Apr 21 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; InfoPath.3; rv:11.0) like Gecko

Steps to reproduce the problem:
1. Use decrypt and scan for web traffic on your firewall
2. Upgrade to Chrome Version 58.0.3029.81
3. Open a https site

What is the expected behavior?
Your connection is not private

Attackers might be trying to steal your information from www.google.com (for example, passwords, messages, or credit cards). NET::ERR_CERT_COMMON_NAME_INVALID

What went wrong?
Version 58.0.3029.81 of Chrome prevented us from going to any HTTPS site. We are getting the error above. We use a feature in our Sophos UTM firewall called decrypt and scan that inspects for the validity of the SSL. We called Sophos and told us that this is an issue with the version of Chrome and our work around is to use a different browser or disable the "decrypt and scan" feature. Disabling "decrypt and scan" is a security risk. Please advise if there's a workaround within the new version of Chrome or when this issue will be fixed.

Did this work before? Yes 57.0.2987.133

Chrome version: 58.0.3029.81  Channel: n/a
OS Version: 10.0
Flash Version:
 
Here's ticket we opened with Sophos UTM.

This is regarding your service request number 7211905 with the reported issue.

Just to reiterate, the new version of Chrome V58 will no longer accept certificates that do not have a subject alternate name.

Chrome is following RFC 2818 for this change.
 
This could affect Sophos UTM, which use https scanning. 

The site generated certificate that we give back in these cases does not have a subject alternate name, meaning Chrome will reject the certificate and block the site.


Workaround:

1.	Use a different browser then chrome 

2.	Disabling https can get around the issue, but block pages will still show certificate error for https sites 

Comment 2 by mea...@chromium.org, Apr 21 2017

Labels: -Restrict-View-SecurityTeam allpublic
Mergedinto: 700595
Status: Duplicate (was: Unconfirmed)
This issue is explained in  bug 700595 , please see the details there. In particular, https://bugs.chromium.org/p/chromium/issues/detail?id=700595#c24 might be useful.

Sign in to add a comment