New issue
Advanced search Search tips

Issue 883647 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Sep 14
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Chrome , Mac
Pri: 2
Type: Bug
Team-Security-UX



Sign in to add a comment

Unknown behavior on Firmaprofesional SSL certificates validation

Reported by clo...@firmaprofesional.com, Sep 13

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.92 Safari/537.36

Steps to reproduce the problem:
1. Enter https://www.firmaprofesional.com, which uses an EV certificate issued by AC Firmaprofesional
2. The URL does not show a green bar neither the Organizations name

What is the expected behavior?
To show the green bar and the Organization's name

What went wrong?
There are the following SubCA for Autoridad de Certificacion * Firmaprofesional CIF A62634068 (crt.sh ID 24651) in the CRLSet:
* AC Firmaprofesional - INFRAESTRUCTURA (crt.sh ID 2209962)
SEU Autoridad de Certificacion (crt.sh ID 34351)

The thing is that, in the URL http://crl.firmaprofesional.com/infraestructura.crt we published the SHA1 INFRAESTRUCTURA SubCA Certificate (crt.sh ID 2209962) and now it is published the SHA2 INFRAESTRUCTURA SubCA Certificate (crt.sh ID 10601239). These two certificates share Subject and keypair, but not serial number, of course. Even more, the SHA1 has been revoked.

Our guess is that the fact of having the SHA1 INFRAESTRUCTURA SubCA Certificate in the CRLSet is, somehow (we do not HOW), provoking that Chrome does not reveal the green bar for EV certificates from Firmaprofesional, and also a "tags don't match error in crt.sh (https://crt.sh/ocsp-responders?trustedExclude=&trustedBy=&trustedFor=&dir=v&sort=2&url=%25firmaprofesional%25&get=&post=&randomserial=)

Did this work before? Yes Don't know

Chrome version: 69.0.3497.92  Channel: stable
OS Version: ubuntu 18.04.1
Flash Version:
 
Components: UI>Browser>Omnibox>SecurityIndicators>VerboseChip
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam OS-Chrome OS-Mac OS-Windows Type-Bug
Routing this out of the security issue queue, since it does not appear to be a vulnerability.
Cc: mea...@chromium.org
Components: Internals>Network>Certificate Internals>Network>CertTrans
The certificate chain is fine, and would verify correctly as EV.

The problem is the Certificate Transparency check.
There is only one SCT provided for the certificate, however Chrome requires at least 2:

https://chromium.googlesource.com/chromium/src/+/726e68d05c3db9d60cbfe889fa2541456a81a6a9/components/certificate_transparency/chrome_ct_policy_enforcer.cc#217
Status: WontFix (was: Unconfirmed)
Thanks for triaging, Eric. Marking WontFix/WorkingAsIntended

Sign in to add a comment