New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Symantec PKI Distrust Impact Tracking

Project Member Reported by asymmetric@chromium.org, Jul 26

Issue description

All remaining certificates issued from the Legacy Symantec PKI are being distrusted starting in M70 ( crbug.com/796230 ). As of the point this code landed, there are many top sites using certificates that are impacted by this change.

This bug is to track impact and site breakage and coordinate outreach to ensure affected site operators replace the distrusted certificates in time.

Original announcement:
https://security.googleblog.com/2017/09/chromes-plan-to-distrust-symantec.html

Instructions for affected site operators:
https://security.googleblog.com/2018/03/distrust-of-symantec-pki-immediate.html

 
Description: Show this description
Cc: awhalley@chromium.org
 Issue 868378  has been merged into this issue.
Cc: abdulsyed@chromium.org ligim...@chromium.org ajha@chromium.org gov...@chromium.org rsleevi@chromium.org nyerramilli@chromium.org
 Issue 868334  has been merged into this issue.
Issue 869201 has been merged into this issue.
Issue 869174 has been merged into this issue.
 Issue 870334  has been merged into this issue.
Cc: allendam@chromium.org geohsu@chromium.org vsu...@chromium.org avkodipelli@chromium.org posciak@chromium.org
 Issue 870911  has been merged into this issue.
 Issue 870778  has been merged into this issue.
Cc: wanderview@chromium.org
Cc: cthomp@chromium.org
 Issue 871282  has been merged into this issue.
https://accounts.intuit.com/ is affected by this issue; can't access it in M70 canary.
it seems a lot of sites is affected, is there a temporary way or some special flag to bypass the check?
This issue affects the bill-pay feature on bankofamerica.com.  Login required from main site, but the internal failing origin is:

https://billpay-ui.bankofamerica.com/

The main BoA sites seem unaffected.
 Issue 873446  has been merged into this issue.
 Issue 874052  has been merged into this issue.
 Issue 874049  has been merged into this issue.
Issue 874137 has been merged into this issue.
Labels: Hotlist-ConOps
Issue 867830 has been merged into this issue.
 Issue 870897  has been merged into this issue.
Same error in paypal.com as well  Issue 839935 , C#7.
www.paydirekt.de - online payment provider endorsed/promoted by major German banks
Cc: viswa.karala@chromium.org
 Issue 874480  has been merged into this issue.
 Issue 874505  has been merged into this issue.
 Issue 874507  has been merged into this issue.
Japan Airlines:  https://www121.jal.co.jp/
Labels: Hotlist-ConOps-CrOS
German Railway https://www.bahn.de 
Air Canada and United are affected. Can't book flights.
Are we adding the list of all sites that are effected to this change? If yes, here is one more. https://appleinsider.com/
Its better to share a Google Form and collect all the URLs into a spreadsheet.
Cc: asymmetric@chromium.org
 Issue 891522  has been merged into this issue.
Cc: susan.boorgula@chromium.org
 Issue 893513  has been merged into this issue.
 Issue 895848  has been merged into this issue.
Possible interaction with OpenDNS and/or Netgear C7000 parental controls features and settings. This was reported by a user on Chromebook Central.

User was blocked from accessing Google services (Gmail, YouTube. Google Docs and Google Sheets) and Facebook, with the error NET::ERR_CERT_AUTHORITY_INVALID

https://productforums.google.com/forum/#!topic/chromebook-central/3kn9cDwb0FA

Removal of OpenDNS and turning off router's parental controls solved the issue. Further investigation is ongoing.

Sign in to add a comment