New issue
Advanced search Search tips

Issue 825238 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Apr 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug
Team-Security-UX



Sign in to add a comment

certificate mismatch

Reported by rafat.a...@gmail.com, Mar 23 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3379.0 Safari/537.36

Steps to reproduce the problem:
1. go to app1
2. get certificate for app2 -- then get cert invalid error
3. both certificate for app1&2 on web proxy

What is the expected behavior?
the correct certificate is deployed for the correct app

What went wrong?
my apps work on all browser except canary.  canary pulls the wrong the app certificate

Did this work before? N/A 

Chrome version: 67.0.3379.0  Channel: canary
OS Version: 6.3
Flash Version:
 

Comment 1 by ajha@chromium.org, Mar 26 2018

Labels: Needs-Triage-M67
Cc: vamshi.kommuri@chromium.org
Labels: Triaged-ET Needs-Feedback
Thanks for filing the issue!

@Reporter: Could you please share a sample test URL/file which helps us to triage the issue in a better way as we are not clear about app1, app2. Any further inputs from your end may help us.
check URL https://cform.mwg.nj.gov/ on regular chrome vs canary.

regular chrome gets correct cert.  canary gets cert. for another application.  all certs stored in front-end proxy.
Project Member

Comment 4 by sheriffbot@chromium.org, Mar 26 2018

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Can anyone from Chromium please respond to this?  Is this a bug?  Is this a new protocol that Canary will follow?

What is going on?  Why is the browser getting the wrong certificate?

Comment 6 by l...@chromium.org, Apr 2 2018

Components: -Platform>DevTools Platform>DevTools>Security
Owner: est...@chromium.org
Status: WontFix (was: Unconfirmed)
When opening the DevTools Console for the link mentioned in #3, I see the warning:

"The SSL certificate used to load resources from https://cform.mwg.nj.gov will be distrusted in M70. Once distrusted, users will be prevented from loading these resources. See https://g.co/chrome/symantecpkicerts for more information."

Please see the link (https://g.co/chrome/symantecpkicerts) for more details on the timeline and deprecation of affected certificates.  Currently stable Chrome is on version M65, with deprecation changes coming in M66 - M70.

Sign in to add a comment