New issue
Advanced search Search tips

Issue 910153 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Dec 4
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

Intermittent NET::ERR_CERT_AUTHORITY_INVALID on valid certificate

Reported by bjhy...@cps.edu, Nov 29

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36

Example URL:
https://www.wpcp.org

Steps to reproduce the problem:
1. Having a hard time reproducing this consistently, so I imagine you won't be able to reproduce, but with a new instance of Chrome, simply visit https://www.wpcp.org.

I'm hopeful the attached network log will have something revealing.

What is the expected behavior?
Site loads just fine.

What went wrong?
Chrome (on Windows) flags this page as having an invalid certifying authority and displays the usual "Privacy Error" interstitial page.

Did this work before? N/A 

Chrome version: 70.0.3538.110  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: 

Other browsers, as well as other Windows computers running the same version of Chrome, work fine.

If I view the certificate through Chrome, I see what's in the attached screenshot. Note "Windows does not have enough information to verify this certificate." The "Certification Path" tab isn't pictured, but shows only "www.wpcp.org" and nothing above it, i.e. no cert chain. I've exported the certificate using the built-in Windows Certificate Export Wizard, and it's identical to a certificate as downloaded onto a working machine.

This has happened on multiple machines.
 
chrome_invalid.PNG
39.2 KB View Download
chrome-net-export-log-bytes.zip
1.1 MB Download
Components: -Internals>Network Internals>Network>Certificate
Labels: Needs-Triage-M70
Cc: phanindra.mandapaka@chromium.org
Labels: Needs-Feedback Triaged-ET
Thanks for the issue...

Tried to reproduce the issue on reported chrome version 70.0.3538.110 using Windows 7. Attaching screen-cast for reference.
Steps: 
------
1. Launched reported chrome 
2. Navigated the URL " https://www.wpcp.org "
3. Opened certificate 
As we have observed that the chrome displaying as valid certificate

@Reporter: Could you please check the attached screen cast and let us know if anything missed from our end and verify this on chrome beta 71.0.3578.75, you can download latest chrome builds here:" https://www.chromium.org/getting-involved/dev-channel ". Let us know whether issue still persists.

Thanks.!
910153.mp4
2.4 MB View Download
You're not missing anything in your screencast. All looks good on your end. Per my note that "other Windows computers running the same version of Chrome work fine" -- we'll be very lucky indeed if you manage to reproduce this.

As to your request to verify this on a newer build, I accidentally downloaded the latest dev build -- 72.0.3622.0 -- instead of the latest beta build.

That said, the problem persists, even in the latest dev build -- at least, it does on the same computer that was originally experiencing the issue. I've attached a new network log, as pulled from that build.

This is not the only machine I've ever experienced this issue on. However, it's the only one I'm aware of that's currently going awry.

If you'd like me to confirm this on beta as well as dev, I'm happy to do so.

If you'd like some additional visual evidence, I don't have screen-cast software on the problematic machine, but I could probably arrange something.
chrome-net-export-log-bytes.zip
2.0 MB Download
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 30

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: Needs-Feedback
As per comment #4, retried the issue on reported chrome 70.0.3538.110 and latest chrome 73.0.3629.0 using Windows 7. 
Steps:
-----
1. Launched reported chrome 
2. Opened https://www.wpcp.org >> opened certificate and observed same as comment #3.

As we are unable to reproduce the issue. Hence, requesting Internals>Network>Certificate team to look into it for further triaging it.

Thanks..!
Status: WontFix (was: Unconfirmed)
The server is misconfigured, so as not to send the necessary intermediate.

As a consequence, during verification, it's necessary to fetch intermediate certificates to attempt to correct the server misconfiguration. The fetching of those intermediates is done by the OS, and can be affected by a variety of settings (e.g. local proxy configuration, local system corruption, etc). That it intermittently shows results suggests a long-timeout is likely involved, which likely points at misconfiguring the Windows proxy configuration (distinct from the Chrome proxy configuration, the Windows configuration is used by things like certificate fetches and system update fetches)

You can see these findings reflected at SSLLabs - https://www.ssllabs.com/ssltest/analyze.html?d=www.wpcp.org - in particular, the incomplete chain.

Please see https://docs.microsoft.com/en-us/windows/desktop/winhttp/proxycfg-exe--a-proxy-configuration-tool and https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731131(v=ws.10) for information about configuring clients (appropriate for the version of Windows you're using)
Don't think I would have found that on my own. Thanks so much for pointing me in the right direction! Really appreciate it. Sorry to have misreported the issue.

Sign in to add a comment