unable to view invalid certificate with HSTS

Bug #1405042 reported by avdd
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
firefox (Ubuntu)
Expired
Undecided
Unassigned

Bug Description

The only way to view invalid certificates in firefox is to click "Add exception" on the "Untrusted connection" screen. But sometimes this option is disabled: e.g. if there the site uses HSTS. Then there is no way to view the certificate in the current session.

ProblemType: Bug
DistroRelease: Ubuntu 14.04
Package: firefox 34.0+build2-0ubuntu0.14.04.1
ProcVersionSignature: Ubuntu 3.13.0-43.72-generic 3.13.11.11
Uname: Linux 3.13.0-43-generic x86_64
AddonCompatCheckDisabled: False
ApportVersion: 2.14.1-0ubuntu3.6
Architecture: amd64
AudioDevicesInUse:
 USER PID ACCESS COMMAND
 /dev/snd/controlC0: avdd 2511 F.... pulseaudio
BuildID: 20141127111021
Channel: Unavailable
CurrentDesktop: Unity
Date: Tue Dec 23 13:10:49 2014
DefaultProfileIncompatibleExtensions:
 English (South Africa) Language Pack - <email address hidden>
 English (GB) Language Pack - <email address hidden>
 Japanese Language Pack - <email address hidden>
 Default - {972ce4c6-7e08-4474-a285-3208198ce6fd}
DefaultProfilePrefSources: prefs.js
ForcedLayersAccel: False
IfupdownConfig:
 # interfaces(5) file used by ifup(8) and ifdown(8)
 auto lo
 iface lo inet loopback
InstallationDate: Installed on 2014-05-03 (233 days ago)
InstallationMedia: Ubuntu 14.04 LTS "Trusty Tahr" - Release amd64 (20140417)
IpRoute:
 default via 192.168.178.1 dev eth0 proto static
 172.17.0.0/16 dev docker0 proto kernel scope link src 172.17.42.1
 192.168.178.0/24 dev eth0 proto kernel scope link src 192.168.178.20 metric 1
MostRecentCrashID: bp-39cb68f1-0f39-471b-863a-879bb2140901
Profile1IncompatibleExtensions:
 Japanese Language Pack - <email address hidden>
 English (South Africa) Language Pack - <email address hidden>
 English (GB) Language Pack - <email address hidden>
 Default - {972ce4c6-7e08-4474-a285-3208198ce6fd}
Profile1PrefSources: prefs.js
Profile2IncompatibleExtensions:
 Global Menu Bar integration - <email address hidden>
 Default - {972ce4c6-7e08-4474-a285-3208198ce6fd}
Profile2PrefSources:
 prefs.js
 user.js
Profiles:
 Profile0 (Default) - LastVersion=34.0/20141127111021 (In use)
 Profile1 - LastVersion=34.0/20141127111021
 Profile2 - LastVersion=34.0/20141127111021
RelatedPackageVersions:
 rhythmbox-mozilla 3.0.2-0ubuntu2
 totem-mozilla 3.10.1-1ubuntu4
RunningIncompatibleAddons: True
SourcePackage: firefox
SubmittedCrashIDs:
 bp-39cb68f1-0f39-471b-863a-879bb2140901
 bp-70dc89dd-e04c-4c06-a92b-04dd92140513
UpgradeStatus: No upgrade log present (probably fresh install)
WifiSyslog:

dmi.bios.date: 07/09/2013
dmi.bios.vendor: LENOVO
dmi.bios.version: G2ET95WW (2.55 )
dmi.board.asset.tag: Not Available
dmi.board.name: 2306CTO
dmi.board.vendor: LENOVO
dmi.board.version: 0B98405 Std
dmi.chassis.asset.tag: No Asset Information
dmi.chassis.type: 10
dmi.chassis.vendor: LENOVO
dmi.chassis.version: Not Available
dmi.modalias: dmi:bvnLENOVO:bvrG2ET95WW(2.55):bd07/09/2013:svnLENOVO:pn2306CTO:pvrThinkPadX230:rvnLENOVO:rn2306CTO:rvr0B98405Std:cvnLENOVO:ct10:cvrNotAvailable:
dmi.product.name: 2306CTO
dmi.product.version: ThinkPad X230
dmi.sys.vendor: LENOVO

Revision history for this message
avdd (avdd) wrote :
Revision history for this message
madbiologist (me-again) wrote :

Is this still occurring on Firefox 37.0.1?

Changed in firefox (Ubuntu):
status: New → Incomplete
Revision history for this message
avdd (avdd) wrote :

No idea. I don't currently have a combination of HSTS and invalid cert to test.

However, the poor usability of selecting "Add exception" simply to VIEW a certificate I would expect warrants attention.

Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for firefox (Ubuntu) because there has been no activity for 60 days.]

Changed in firefox (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.