firefox ignore Your connection is not secure

User Help for Mozilla Firefox
User avatar
therube
Posts: 21714
Joined: March 10th, 2004, 9:59 pm
Location: Maryland USA

Re: firefox ignore Your connection is not secure

Post by therube »

Falnor wrote:Getting the same problem on ... microsoft sites
I had one yesterday on a MS site.
Thought it to be odd, wondered why it happened, but didn't pursue it.
(If I'm recalling it was on a MS "consumer support" site [link].)

Here:
https://social.technet.microsoft.com/Forums/en-us/home

But its a different error:

Code: Select all

Secure Connection Failed

An error occurred during a connection to social.technet.microsoft.com.

Invalid OCSP signing certificate in OCSP response.

Error code: <a id="errorCode" title="SEC_ERROR_OCSP_INVALID_SIGNING_CERT">SEC_ERROR_OCSP_INVALID_SIGNING_CERT</a>
Someone noted the Pref, security.ssl.enable_ocsp_stapling.
Toggling that does allow the MS site to load, but no clue as to what "ocsp stapling" is...
The OCSP response validity range is 2017-03-14T21:40:24Z to 2017-05-28T21:40:24Z (expired yesterday at 9:40pm). This is correctly identified by both Firefox and Chrome as an expired certificate. Firefox treats the error as fatal and refuses to load the page, while Chrome still loads the page but does not consider the connection to be secure.
Other MS sites (that now fail):

https://www.bing.com/
https://onedrive.live.com/



Issues while accessing Visual Studio Team Services through Firefox browser – 05/29 – Investigating


Bug 1368433 Can no longer connect to various microsoft domains with SEC_ERROR_OCSP_INVALID_SIGNING_CERT


mozillazine: Firefox blocking microsoft websites. Why?
Fire 750, bring back 250.
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball CopyURL+ FetchTextURL FlashGot NoScript
Brummelchen
Posts: 4480
Joined: March 19th, 2005, 10:51 am

Re: firefox ignore Your connection is not secure

Post by Brummelchen »

the cert is revoked, whether you like it not or file a ridiculous bug
https://www.digicert.com/help/

Code: Select all

DNS resolves freshproducegroup.us to 23.229.248.66

HTTP Server Header: Apache/2.4.25

SSL certificate

Common Name = rntoptions.com
Subject Alternative Names = rntoptions.com, www.rntoptions.com, vftfoodgroup.us, mexicanfoodproducts.us, craftbeersandtequilatrade.us, freshproducegroup.us
Issuer = Go Daddy Secure Certificate Authority - G2
Serial Number = 5E1B2938E7D57EDB
SHA1 Thumbprint = 0E22651C7872286C78A0A65D4F93131752212024
Key Length = 2048
Signature algorithm = SHA256 + RSA (excellent)
Secure Renegotiation: Supported
SSL Certificate is revoked

The certificate has been revoked. You should replace it with a new certificate as soon as possible.

OCSP Staple:	Not Enabled
OCSP Origin:	Revoked
CRL Status:	Revoked

SSL Certificate expiration

The certificate expires July 23, 2017 (55 days from today)
Falnor
Posts: 202
Joined: May 4th, 2004, 9:51 am
Location: Wrexham, Wales

Re: firefox ignore Your connection is not secure

Post by Falnor »

Brummelchen wrote:the cert is revoked, whether you like it not or file a ridiculous bug
https://www.digicert.com/help/

Code: Select all

DNS resolves freshproducegroup.us to 23.229.248.66

HTTP Server Header: Apache/2.4.25

SSL certificate

Common Name = rntoptions.com
Subject Alternative Names = rntoptions.com, www.rntoptions.com, vftfoodgroup.us, mexicanfoodproducts.us, craftbeersandtequilatrade.us, freshproducegroup.us
Issuer = Go Daddy Secure Certificate Authority - G2
Serial Number = 5E1B2938E7D57EDB
SHA1 Thumbprint = 0E22651C7872286C78A0A65D4F93131752212024
Key Length = 2048
Signature algorithm = SHA256 + RSA (excellent)
Secure Renegotiation: Supported
SSL Certificate is revoked

The certificate has been revoked. You should replace it with a new certificate as soon as possible.

OCSP Staple:	Not Enabled
OCSP Origin:	Revoked
CRL Status:	Revoked

SSL Certificate expiration

The certificate expires July 23, 2017 (55 days from today)
I have used that digicert to check all the microsoft sites and none of the certificates have been revoked. Yet firefox thinks they have been revoked and displays that error
Brummelchen
Posts: 4480
Joined: March 19th, 2005, 10:51 am

Re: firefox ignore Your connection is not secure

Post by Brummelchen »

digicert has nothing in common with mozilla - the cert is not valid, that is the official answer. it is not important, what chrome or microsoft show up.
but not all point that out, eg https://www.sslshopper.com/ssl-checker. ... cegroup.us

Symantec instead shows invalid
https://cryptoreport.websecurity.symantec.com/checker/

Code: Select all

Common name:
 rntoptions.com
SAN:
 rntoptions.com, www.rntoptions.com, vftfoodgroup.us, mexicanfoodproducts.us, craftbeersandtequilatrade.us, freshproducegroup.us
Valid from:
 2016-Jul-31 21:52:38 GMT
Valid to:
 2017-Jul-23 22:21:38 GMT
Certificate status:
 Revoked
Revocation check method:
 OCSP
Revocation reason:
 Cessation of operation
or here
https://www.ssllabs.com/ssltest/analyze ... .us&latest

Code: Select all

Revocation status	Revoked   INSECURE
DNS CAA	No (more info)
Trusted	No   NOT TRUSTED

Common names	*.prod.phx3.secureserver.net   MISMATCH

Revocation information	CRL, OCSP 
CRL: http://crl.starfieldtech.com/sfig2s1-37.crl 
OCSP: http://ocsp.starfieldtech.com/ 
revoked ;)
Mouse5
Posts: 1279
Joined: April 11th, 2014, 7:34 pm
Location: Sydney Australia

Re: firefox ignore Your connection is not secure

Post by Mouse5 »

User avatar
therube
Posts: 21714
Joined: March 10th, 2004, 9:59 pm
Location: Maryland USA

Re: firefox ignore Your connection is not secure

Post by therube »

All I can say to that is, yuca.
(Its nice when someone actually puts a usable explanation in a bug.)
Fire 750, bring back 250.
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball CopyURL+ FetchTextURL FlashGot NoScript
User avatar
lovemyfoxy
Posts: 2337
Joined: December 11th, 2009, 11:23 am
Location: USA

Re: firefox ignore Your connection is not secure

Post by lovemyfoxy »

52ESR. I'm getting messages that THIS site is insecure, just the past few days, but I can connect anyway. I have HTTPS Everywhere. Is it because we're not https?

Should I just add that about:config line?
2 Desktops--Win 7 Ult.SP1 x64/6GB RAM /Firefox 52.9ESR/Waterfox64 2022.11/Thunderbird 52.9ESR/BitWarden PW Manager/Verizon FIOS wired network
User avatar
therube
Posts: 21714
Joined: March 10th, 2004, 9:59 pm
Location: Maryland USA

Re: firefox ignore Your connection is not secure

Post by therube »

Correct. No https: here.
(Yet ;-).)
Fire 750, bring back 250.
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball CopyURL+ FetchTextURL FlashGot NoScript
Mouse5
Posts: 1279
Joined: April 11th, 2014, 7:34 pm
Location: Sydney Australia

Re: firefox ignore Your connection is not secure

Post by Mouse5 »

LoveMyFoxy wrote:52ESR. I'm getting messages that THIS site is insecure, just the past few days, but I can connect anyway. I have HTTPS Everywhere. Is it because we're not https?

Should I just add that about:config line?
yeah i think so, but a lot of sites havent switched to using HTTPS yet either
User avatar
lovemyfoxy
Posts: 2337
Joined: December 11th, 2009, 11:23 am
Location: USA

Re: firefox ignore Your connection is not secure

Post by lovemyfoxy »

But it can help on sites where I hang out a lot.
2 Desktops--Win 7 Ult.SP1 x64/6GB RAM /Firefox 52.9ESR/Waterfox64 2022.11/Thunderbird 52.9ESR/BitWarden PW Manager/Verizon FIOS wired network
Post Reply