New issue
Advanced search Search tips

Issue 895760 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 5
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome
Pri: 3
Type: Bug
Team-Security-UX



Sign in to add a comment

https://pmmvy-cas.nic.in/ cert accepted by Chrome but rejected by Edge, Firefox and Safari as revoked

Project Member Reported by foolip@chromium.org, Oct 16

Issue description

Chrome Version: (71.0.3573.0 (Official Build) dev (64-bit)
OS: Debian 4.17.17-1rodete2 (2018-08-28) x86_64 GNU/Linux

What steps will reproduce the problem?
(1) Visit https://pmmvy-cas.nic.in/

What is the expected result?

In Edge, Firefox and Safari, an interstitial about rejected cert is shown. This also happens for Chrome on Mac, but not other OSes.

What happens instead?

Chrome on Android, ChromeOS, Linux and Windows loads the site.

This was reported in https://github.com/webcompat/web-bugs/issues/19872  as a bug in Firefox, but given the consistent behavior of other browsers this seems more likely to be a Chrome bug. Adding Hotlist-Interop to track this.
 
Attaching some screenshots. For Chrome I have two, a Mac one with an interstitial and a Win one that loads the site. Edge, Firefox and Safari have interstitials.
bs_machs_Chrome_69.0.jpg
71.2 KB View Download
bs_machs_Safari_11.1.jpg
69.7 KB View Download
bs_win10_Edge_17.0.jpg
64.0 KB View Download
bs_win10_Firefox_62.0.jpg
103 KB View Download
bs_win10_Chrome_71.0 dev.jpg
133 KB View Download
Labels: Triaged-ET Target-72 M-72 FoundIn-71 FoundIn-70 FoundIn-72 Needs-Triage-M71
Able to reproduce the issue on Win-10 and Ubuntu 14.04 using chrome stable #69.0.3497.100 and latest canary #72.0.3581.0. Issue is not seen in OS-mac.
This is a non-regression issue as it is observed from M60 old builds. 

Hence, marking it as untriaged to get more inputs from dev team.

Thanks...!!
Components: Internals>Network>Certificate
Cc: rsleevi@chromium.org
It appears that the site is no longer serving the revoked certificate (a fresh SSLLabs scan shows no issues and a different certificate fingerprint than the screenshots in the linked webcompat bug).

Chromium does not necessarily have the same behavior for revoked certificates as other browsers, and iirc the behavior can vary from platform to platform. I would not consider different revocation checking behavior as a webcompat issue.

+rsleevi@, who can comment more on the vagaries of certificate revocation. 
Status: WontFix (was: Untriaged)
Marking WontFix. Yes, differences in trust stores or revocation behaviour is not necessarily a WebCompat issue.

Even the behaviour of Firefox and Safari will vary based on Firefox version & about://flags or, in the case of Safari, the macOS version and configuration, even for otherwise consistent versions of Safari.

Sign in to add a comment