New issue
Advanced search Search tips

Issue 809292 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 1
Type: Bug-Security



Sign in to add a comment

Security: Unclear error message with certificate on 66 (Stable 64 opens https page, canary 66 / dev 66 show cert. error)

Project Member Reported by mar...@mwiacek.com, Feb 6 2018

Issue description


URL: mediamarkt.ch

Steps: open URL

Result: Stable 64.0.3282.137 opens https page, canary 66.0.3338.0 / dev 66.0.3335.4 show certificate error

Note: checked on Android only, Android 7/S7
 
stable.png
289 KB View Download
canary_dev.png
189 KB View Download
Components: -UI -Internals>CertAnalysis Internals>Network>Certificate
Labels: -Restrict-View-SecurityTeam allpublic
Status: WontFix (was: Unconfirmed)
This site needs to update its certificate. 

https://security.googleblog.com/2017/09/chromes-plan-to-distrust-symantec.html?m=1

Comment 2 by mar...@mwiacek.com, Feb 6 2018

Status: Unconfirmed (was: WontFix)
I have unfortunately to reopen this issue because current error in 66 doesn't show clear, what's the real root cause and how to fix it.

In other words: problem with certificate is not result of Chrome bug or problem with certificate itself and I suggest to add more descriptive info instead "server's certificate is not trusted".

Proposals:

"Server's certificate is not trusted from Chrome 66"

"Server's certificate authority is not trusted"

"Server's certificate authority is not trusted from Chrome 66"

"Server's certificate authority RapidSSL SHA 256 SSL is not trusted from Chrome 66"

"Certificate authority RapidSSL SHA 256 SSL is not trusted from Chrome 66" (probably the best)

Additionally I strongly suggest to add "(more info)" with link to the full article showing reason of revoking and plan related to it.

Please close this bug again if you think, that Chrome is behaving perfectly now.

Comment 3 by mar...@mwiacek.com, Feb 6 2018

Summary: Security: Unclear error message with certificate on 66 (Stable 64 opens https page, canary 66 / dev 66 show cert. error) (was: Security: Stable 64.0.3282.137 opens https page, canary 66.0.3338.0 / dev 66.0.3335.4 show cert. error)
Status: WontFix (was: Unconfirmed)
Thank you for your feedback. Various UI options were considered as part of this removal of trust, and the current text was intentionally chosen.

Sign in to add a comment