firefox is warning about untrusted connection but certificate is valid

Bug #923531 reported by Alexandre BELLONI
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
firefox (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

On some sites, firefox is reporting an untrusted connection when the certificate is valid.

One exemple is images-na.ssl-images-amazon.com. It verifies OK with openssl when using:

openssl s_client -connect images-na.ssl-images-amazon.com:443 -showcerts -status -CApath /etc/ssl/certs

It also verifies ok with chrome. The same happens with www.zeroforfait.fr

ProblemType: Bug
DistroRelease: Ubuntu 11.10
Package: firefox 9.0.1+build1-0ubuntu0.11.10.2
ProcVersionSignature: Ubuntu 3.0.0-16.27-generic 3.0.17
Uname: Linux 3.0.0-16-generic i686
AddonCompatCheckDisabled: False
AlsaVersion: Advanced Linux Sound Architecture Driver Version 1.0.24.
AplayDevices:
 **** List of PLAYBACK Hardware Devices ****
 card 0: Intel [HDA Intel], device 0: ALC272 Analog [ALC272 Analog]
   Subdevices: 1/1
   Subdevice #0: subdevice #0
ApportVersion: 1.23-0ubuntu4
Architecture: i386
ArecordDevices:
 **** List of CAPTURE Hardware Devices ****
 card 0: Intel [HDA Intel], device 0: ALC272 Analog [ALC272 Analog]
   Subdevices: 1/1
   Subdevice #0: subdevice #0
AudioDevicesInUse:
 USER PID ACCESS COMMAND
 /dev/snd/controlC0: alex 1464 F.... pulseaudio
BuildID: 20111228084953
Card0.Amixer.info:
 Card hw:0 'Intel'/'HDA Intel at 0xf0340000 irq 43'
   Mixer name : 'Realtek ALC272'
   Components : 'HDA:10ec0272,144dca00,00100001'
   Controls : 19
   Simple ctrls : 11
Channel: release
Date: Mon Jan 30 00:22:57 2012
ForcedLayersAccel: False
IfupdownConfig:
 auto lo
 iface lo inet loopback
InstallationMedia: Ubuntu 9.10 "Karmic Koala" - Release i386 (20091028.5)
IpRoute:
 default via 192.168.1.254 dev wlan0 proto static
 169.254.0.0/16 dev wlan0 scope link metric 1000
 192.168.1.0/24 dev wlan0 proto kernel scope link src 192.168.1.103 metric 2
ProcEnviron:
 PATH=(custom, user)
 LANG=en_US.UTF-8
 SHELL=/bin/bash
Profiles: Profile0 (Default) - LastVersion=9.0.1/20111228084953 (Running)
RunningIncompatibleAddons: False
SourcePackage: firefox
UpgradeStatus: Upgraded to oneiric on 2011-12-03 (57 days ago)
WifiSyslog:

dmi.bios.date: 09/08/2009
dmi.bios.vendor: Phoenix Technologies Ltd.
dmi.bios.version: 11CA.M015.20090908.RHU
dmi.board.name: NC10
dmi.board.vendor: SAMSUNG ELECTRONICS CO., LTD.
dmi.board.version: Not Applicable
dmi.chassis.asset.tag: No Asset Tag
dmi.chassis.type: 10
dmi.chassis.vendor: SAMSUNG ELECTRONICS CO., LTD.
dmi.chassis.version: N/A
dmi.modalias: dmi:bvnPhoenixTechnologiesLtd.:bvr11CA.M015.20090908.RHU:bd09/08/2009:svnSAMSUNGELECTRONICSCO.,LTD.:pnNC10:pvrNotApplicable:rvnSAMSUNGELECTRONICSCO.,LTD.:rnNC10:rvrNotApplicable:cvnSAMSUNGELECTRONICSCO.,LTD.:ct10:cvrN/A:
dmi.product.name: NC10
dmi.product.version: Not Applicable
dmi.sys.vendor: SAMSUNG ELECTRONICS CO., LTD.

Revision history for this message
Alexandre BELLONI (abelloni) wrote :
Revision history for this message
Alexandre BELLONI (abelloni) wrote :

Note that it doesn't happen with a fresh profile but has happened on multiple profiles I am using on various computers.

Revision history for this message
Sam_ (and-sam) wrote :

No certificate warning here with www.zeroforfait.fr

images-na.ssl-images-amazon.com says:
Service Unavailable
The server is temporarily unable to service your request. Please try again later.
Reference #6.e9b302cc.1327929330.45adf6d

firefox:
  Installed: 9.0.1+build1-0ubuntu0.11.10.2
  Candidate: 9.0.1+build1-0ubuntu0.11.10.2
  Version table:
 *** 9.0.1+build1-0ubuntu0.11.10.2 0
        500 http://archive.ubuntu.com/ubuntu/ oneiric-updates/main amd64 Packages
        500 http://archive.ubuntu.com/ubuntu/ oneiric-security/main amd64 Packages
        100 /var/lib/dpkg/status
     7.0.1+build1+nobinonly-0ubuntu2 0
        500 http://archive.ubuntu.com/ubuntu/ oneiric/main amd64 Packages

Revision history for this message
Alexandre BELLONI (abelloni) wrote :

In fact, restarting firefox seems to solve temporarily the issue. Note that this also happens using iceweasel 9.0.1 (other computer, other profile).

When it happens, I can close firefox, restart it, it will lod my tabs without warning. After a while, it will complain about Untrusted Connection.

Maybe you can try to load http://www.zeroforfait.fr/ in a tab, click on the black button labeled Espace client on the upper right.

After a while, reload the tab and it should happen.

Revision history for this message
Sam_ (and-sam) wrote :

Alexandre, followed the steps and can't confirm, neither with noscript en- or disabled and reloading this page.
https://www.zeroforfait.fr/cgi-bin/cie.cgi?cid=zf&p=/espace_client.shtml

Revision history for this message
Alexandre BELLONI (abelloni) wrote :

I doesn't seem to happen again since I upgraded to firefox 10.0.2+build1-0ubuntu0.11.10.1. Still, I have a wireshark capture showing the issue.

Changed in firefox (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.