New issue
Advanced search Search tips

Issue 752386 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

NET::ERR_CERT_AUTHORITY_INVALID in multiple browsers after uninstalling AV

Reported by jaysonav...@gmail.com, Aug 4 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:54.0) Gecko/20100101 Firefox/54.0

Example URL:
any

Steps to reproduce the problem:
1. go to www.google.com
2. Your connection not private NET::ERR_CERT_AUTHORITY_INVALID
3. 

What is the expected behavior?
go to the website

What went wrong?
NET::ERR_CERT_AUTHORITY_INVALID

Does it occur on multiple sites: Yes

Is it a problem with a plugin? N/A 

Did this work before? Yes Not sure. 

Does this work in other browsers? Yes

Chrome version: Version 60.0.3112.90 (Official Build) (64-bit)  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: Shockwave Flash 26.0 r0

Please help, I believe it has something to do with the certificates
 
chrome-net-export-log.json
712 KB View Download
Status: Available (was: Unconfirmed)
It appears that you have an ESET Antivirus or Firewall installed, that is presenting its own certificates instead of the real Google ones.

Was this installed recently? If so, you'll need to check with ESET to see if there are specific steps you'll need to take to allow ESET to intercept your traffic.

Comment 3 by kochi@chromium.org, Aug 7 2017

Components: -Blink Internals>Network>Certificate
Assigning to appropriate component.
(though if ESET is the culprit, Chromium/Blink or SSL implementation cannot
do anything for this...)
I reinstalled Chrome, no more ESET certificates. Still same problem. Any other suggestions. Again, thank you for helping my out, this is so weird. 

Comment 5 by mattm@chromium.org, Aug 10 2017

Labels: Needs-Feedback
Please provide a new net-export log, thanks!

Comment 6 by mge...@chromium.org, Aug 17 2017

Can you provide a new netlog without the ESET certificates, or let us know if you've stopped seeing the error? Without a new log we'll have to close the issue.
I will today. THank you

Comment 8 Deleted

I am trying to add new new-export log
Here is the new log
chrome-net-export-log2.json
125 KB View Download

Comment 11 by rch@chromium.org, Aug 22 2017

This appears to still be the ESET certificate:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            5f:0c:9c:c3:62:59:fe:99:71:d7:e2:08:a5:dc:f8:b5
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN=ESET SSL Filter CA, O=ESET, spol. s r. o., C=SK
        Validity
            Not Before: Aug  8 13:04:30 2017 GMT
            Not After : Oct 31 12:40:00 2017 GMT
        Subject: C=US, ST=California, L=Mountain View, O=Google Inc, CN=www.google.com
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (2048 bit)
                Modulus (2048 bit):
                    00:cd:be:ed:3f:09:cd:c2:e1:0f:c1:ec:a4:b8:ca:
                    c1:e2:90:8a:2a:b8:4a:5b:59:da:39:40:2a:42:ab:
                    f6:8a:65:56:45:d0:99:32:b1:28:2f:25:f2:f3:d9:
                    e5:09:f6:87:a2:80:4c:92:07:7e:08:98:40:65:b7:
                    eb:5c:86:16:fa:37:a7:2d:66:7b:87:f6:36:1b:a7:
                    63:6f:be:67:d7:b7:7a:60:27:cd:27:17:c5:1e:41:
                    ca:10:71:16:ee:ac:68:8d:21:00:95:76:77:70:f9:
                    78:ff:0d:ba:89:82:65:69:ec:b0:1f:9d:3d:82:13:
                    91:bb:42:d2:2d:54:25:92:05:7e:76:ed:2e:94:3d:
                    1f:b6:d6:9a:48:82:b0:88:f8:51:47:18:43:ab:a7:
                    1f:84:c6:fa:3a:8c:80:86:6e:9a:6d:89:ed:d6:84:
                    78:9e:42:b1:bc:98:9d:8e:5a:5d:58:58:98:50:7a:
                    60:03:f0:97:82:5d:cd:27:d7:e9:3f:e6:11:02:14:
                    fc:a3:0b:d2:bb:6b:11:98:d7:04:79:40:2f:59:2a:
                    43:e7:93:c5:39:a9:44:f5:37:dd:ea:29:55:5e:b0:
                    be:80:1c:97:71:5c:eb:a6:ff:08:54:c0:09:fd:10:
                    e9:fb:17:10:35:c6:b9:c1:5a:c7:63:b5:a7:e3:4d:
                    12:03
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Subject Alternative Name: 
                DNS:www.google.com
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Key Usage: critical
                Digital Signature, Key Encipherment
            X509v3 Authority Key Identifier: 
                keyid:DF:F8:A3:76:65:78:2F:6C:CA:B2:0E:0D:91:56:6F:94:92:B9:87:59

    Signature Algorithm: sha256WithRSAEncryption
        86:3a:8c:df:94:71:05:28:b8:27:b7:90:42:cc:ab:4e:2a:4e:
        8e:b1:93:6b:ce:11:a8:34:cc:a3:83:40:dd:e4:8f:b6:8d:30:
        86:66:05:42:bc:62:11:f8:55:e1:d9:04:18:8e:15:5d:5d:03:
        1e:b9:51:e1:9c:43:22:f8:fc:12:8a:f0:dd:fe:0e:84:4e:62:
        25:93:51:13:4b:c3:ab:45:b5:54:b2:71:74:0b:bb:b4:b1:b0:
        f5:b6:a6:7d:1e:00:41:19:0f:08:1c:b5:0e:e5:6b:52:11:91:
        cc:2d:33:d7:e7:67:71:45:96:dc:98:89:d4:07:b7:b0:d7:83:
        92:1a:1b:c3:b7:c3:fe:8a:b0:41:5f:df:5c:af:b6:02:e2:08:
        0d:28:02:28:b2:59:6f:c6:7a:89:cf:4a:9a:62:be:55:d4:4c:
        95:ad:5f:0a:2a:0e:80:c4:52:48:90:6b:31:04:46:e6:a8:cf:
        f0:1c:14:13:6d:fc:ab:1b:49:5c:20:ba:f4:de:8f:36:82:40:
        ee:f8:52:78:3a:29:fd:12:42:03:66:69:a2:ff:67:21:0e:f1:
        86:a2:9d:e6:05:6e:aa:25:e9:b9:2e:da:01:c7:7b:21:be:c8:
        96:58:8c:ce:3d:bb:fe:57:e7:a1:48:4c:ca:32:eb:f4:89:33:
        d7:e3:17:fc
-----BEGIN CERTIFICATE-----
MIIDtTCCAp2gAwIBAgIQXwycw2JZ/plx1+IIpdz4tTANBgkqhkiG9w0BAQsFADBI
MRswGQYDVQQDExJFU0VUIFNTTCBGaWx0ZXIgQ0ExHDAaBgNVBAoTE0VTRVQsIHNw
b2wuIHMgci4gby4xCzAJBgNVBAYTAlNLMB4XDTE3MDgwODEzMDQzMFoXDTE3MTAz
MTEyNDAwMFowaDELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFjAU
BgNVBAcMDU1vdW50YWluIFZpZXcxEzARBgNVBAoMCkdvb2dsZSBJbmMxFzAVBgNV
BAMMDnd3dy5nb29nbGUuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
AQEAzb7tPwnNwuEPweykuMrB4pCKKrhKW1naOUAqQqv2imVWRdCZMrEoLyXy89nl
CfaHooBMkgd+CJhAZbfrXIYW+jenLWZ7h/Y2G6djb75n17d6YCfNJxfFHkHKEHEW
7qxojSEAlXZ3cPl4/w26iYJlaeywH509ghORu0LSLVQlkgV+du0ulD0fttaaSIKw
iPhRRxhDq6cfhMb6OoyAhm6abYnt1oR4nkKxvJidjlpdWFiYUHpgA/CXgl3NJ9fp
P+YRAhT8owvSu2sRmNcEeUAvWSpD55PFOalE9Tfd6ilVXrC+gByXcVzrpv8IVMAJ
/RDp+xcQNca5wVrHY7Wn400SAwIDAQABo3sweTAdBgNVHSUEFjAUBggrBgEFBQcD
AQYIKwYBBQUHAwIwGQYDVR0RBBIwEIIOd3d3Lmdvb2dsZS5jb20wDAYDVR0TAQH/
BAIwADAOBgNVHQ8BAf8EBAMCBaAwHwYDVR0jBBgwFoAU3/ijdmV4L2zKsg4NkVZv
lJK5h1kwDQYJKoZIhvcNAQELBQADggEBAIY6jN+UcQUouCe3kELMq04qTo6xk2vO
Eag0zKODQN3kj7aNMIZmBUK8YhH4VeHZBBiOFV1dAx65UeGcQyL4/BKK8N3+DoRO
YiWTURNLw6tFtVSycXQLu7SxsPW2pn0eAEEZDwgctQ7la1IRkcwtM9fnZ3FFltyY
idQHt7DXg5IaG8O3w/6KsEFf31yvtgLiCA0oAiiyWW/GeonPSppivlXUTJWtXwoq
DoDEUkiQazEERuaoz/AcFBNt/KsbSVwguvTejzaCQO74Ung6Kf0SQgNmaaL/ZyEO
8YaineYFbqol6bku2gHHeyG+yJZYjM49u/5X56FITMoy6/SJM9fjF/w=
-----END CERTIFICATE-----

So how do I fix this issue? I really like Chrome but this is not worth the
hassle. Please advise.
Labels: -Needs-Feedback
(Feedback was provided, seems like the bot failed to remove the label)
Does anyone have an idea as to fixing this issue? Thank you in advance.

Comment 15 by mattm@chromium.org, Sep 12 2017

Your connections are still getting intercepted by something. If you have any ESET software installed, check if it has any option for TLS scanning or TLS monitoring or anything like that, and disable it.

I have disabled the TLS from ESET. I still get same message from chrome.
NET::ERR_CERT_AUTHORITY_INVALID

Comment 17 by mattm@chromium.org, Sep 13 2017

Was it disabled when the netlog in comment 10 was generated? If not, we'll need a new netlog to see if it is a different issue or not.
Here you go, with the ESET SSL disabled.
Sorry, here it is.
chrome-net-export-log_NoESETon.json
568 KB View Download

Comment 20 by mattm@chromium.org, Sep 15 2017

Looks like it's getting the correct cert chain now, but still failing with AUTHORITY_INVALID. Not sure why that would happen unless your system root trust settings have been modified. Does it work in IE or Edge?
Using IE, I typed "google.com" and it states that there is a certificate
error. Not so with FireFox or Opera.

Comment 22 by mattm@chromium.org, Sep 21 2017

Ok, that would be as expected then. IE uses the system trust store, like Chrome. Firefox does not use the system trust store. (I'm not familiar with what opera does.)

Unfortunately I don't know of a good simple way to fix the system trust store settings, aside from reinstalling windows :(
One possible workaround:

Open a Windows Command Prompt (https://www.lifewire.com/how-to-open-command-prompt-2618089)

Run the following command, without quotes (type the words then press enter)
"certutil -f -verifyCTL AuthRootWU"
rch@, C#11 - how did you gen this nice diag listing?

I'm debugging certificate problems in the Chrome Help forum and am looking for something less tedious than hand copying the BEGIN/END cert blocks to .cer files.
Status: WontFix (was: Available)
Summary: NET::ERR_CERT_AUTHORITY_INVALID in multiple browsers after uninstalling AV (was: NET::ERR_CERT_AUTHORITY_INVALID)
I don't think there's anything actionable here for the Chrome team. It sounds like the user's trust store settings were corrupt, which led to general distrust of a required root certificate.

Sign in to add a comment