New issue
Advanced search Search tips

Issue 832067 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 3
Type: ----



Sign in to add a comment

ERR_CERT_SYMANTEC_LEGACY on software.charitylog.co.uk

Reported by joolz.hi...@ageukessex.org.uk, Apr 12 2018

Issue description

Device name:Chromebook

From "Settings > About Chrome"
Application version:66.0.3359.79 (Official Build) beta (64-bit)
Operating system:Chrom

URLs (if applicable):
https://www.charitylog.co.uk/?login=1

Steps to reproduce:
(1)www.charitylog.co.uk/?logon=1
(2)
(3)

Expected result:no warning sign and able to log in


Actual result:


 
Screenshot 2018-04-12 at 14.24.00.png
155 KB View Download
Labels: Needs-triage-Mobile
Labels: -OS-Android Triaged-Mobile OS-Chrome
Issue seems to be related to ChromeOS. Updating the issue accordingly.

Thanks!
Components: Internals>Network>Certificate
Summary: ERR_CERT_SYMANTEC_LEGACY on software.charitylog.co.uk (was: Warning: Your browser cannot connect to the server securely via TLS1.2. Please check that you are using an up-to-date browser.)
Chrome's supported TLS 1.2 for quite a while now. Rather, that site is just loading from https://software.charitylog.co.uk/images/one-pixel-transparent.gif?1523993806438 and, if it fails, assuming that it failed due to TLS 1.2.

This is not what's going on. Rather, it's got a legacy Symantec certificate.
Cc: asymmetric@chromium.org
Status: WontFix (was: Unconfirmed)
Yup, this certificate has been distrusted in Chrome, Firefox, and likely soon, other browsers, related to https://security.googleblog.com/2018/03/distrust-of-symantec-pki-immediate.html and https://blog.mozilla.org/security/2018/03/12/distrust-symantec-tls-certificates/

This site needs to replace its certificate.

https://www.ssllabs.com/ssltest/analyze.html?d=software.charitylog.co.uk&latest contains details as well


To replace this certificate, the site needs to contact DigiCert - https://www.digicert.com/replace-your-symantec-ssl-tls-certificates/

Sign in to add a comment