New issue
Advanced search Search tips

Issue 763430 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Sep 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug



Sign in to add a comment

StartCom cert issued prior to October 21st 2016 is not trusted

Reported by d...@davejeffery.com, Sep 8 2017

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36

Steps to reproduce the problem:
1. Go to https://live.pin.gy/
2. Chrome will present user with NET::ERR_CERT_AUTHORITY_INVALID error

What is the expected behavior?
As shown in the attached screenshot, the certificate was issued on 4 October 2016.

According to Google's security blog all certificates issued by StartCom prior to Oct 21 2016 should be trusted: https://security.googleblog.com/2016/10/distrusting-wosign-and-startcom.html

The certificate validates correctly on latest versions of Firefox and Safari.

What went wrong?
Certificate should have been trusted according to Google's security blog but it was not.

Did this work before? N/A 

Chrome version: 60.0.3112.113  Channel: n/a
OS Version: OS X 10.12.3
Flash Version:
 
Screen Shot 2017-09-08 at 18.19.51.png
139 KB View Download
Components: Internals>Network>Certificate
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
I believe this is working as expected. 

All such certs will be distrusted in Chrome 61: https://security.googleblog.com/2017/07/final-removal-of-trust-in-wosign-and.html


 Issue 713355  reduced the list of trusted certificates from the root, as described in the blog post:

"We started the phase out in Chrome 56 by only trusting certificates issued prior to October 21st 2016, and subsequently restricted trust to a set of whitelisted hostnames based on the Alexa Top 1M. We have been reducing the size of the whitelist over the course of several Chrome releases."
Status: WontFix (was: Unconfirmed)
This domain wasn't in the Alexa Top Million, and thus stopped working even before https://codereview.chromium.org/2718243003
Ok, thank you for the quick reply.

Sign in to add a comment