New issue
Advanced search Search tips

Issue 719493 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Revoked certificate is passed as secure with no warnings

Reported by gdw...@gmail.com, May 8 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.96 Safari/537.36

Steps to reproduce the problem:
Visit a website with a cert that has been revoked (at the time of writing, https://www.violin-memory.com/ has a revoked cert and Chrome presents the site as secure with a valid certificate.

What is the expected behavior?
Chrome should at least flag the site as not secure, or better yet, block access to the site because of the revocation.

What went wrong?
Access was allowed with no errors or warnings as to the revoked status of the cert.

Did this work before? N/A 

Chrome version: 58.0.3029.96  Channel: stable
OS Version: 6.3
Flash Version: Shockwave Flash 25.0 r0

Ignoring SSL revocations isn't good, Hosting a non-revoked cert is a key part of SSL security. If chrome is ignoring revoked certs it might as well ignore certs with the wrong date, mismatched names and so on.
 
Components: Internals>Network>SSL
Status: WontFix (was: Unconfirmed)
This is working as expected, unless the certificate is included in a CRLSet. Please see https://dev.chromium.org/Home/chromium-security/security-faq#TOC-What-s-the-story-with-certificate-revocation-
Project Member

Comment 2 by sheriffbot@chromium.org, Aug 15 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment