Packages

  • Status Closed
  • Percent Complete
    100%
  • Task Type Security Issue
  • Category Stable
  • Assigned To
    g4jc
  • Operating System Hyperbola GNU/Linux-libre
  • Severity Critical
  • Priority Very High
  • Reported Version Any
  • Due in Version Starfix
  • Due Date Undecided
  • Votes
  • Private
Attached to Project: Packages
Opened by fablamar78 - 27/07/2018
Last edited by g4jc - 28/07/2018

FS#1112 - [iceweasel-uxp] Issue with HTTPS websites

With latest iceweasel-uxp, I can’t connect to some HTTPS websites :

For example :

https://pkgs.fedoraproject.org/ is an example

SEC_ERROR_UNKNOWN_ISSUER

Closed by  g4jc
28.07.2018 17:07
Reason for closing:  Invalid
Additional comments about closing:  

Defective website as per SSLTest

Admin
g4jc commented on 28.07.2018 17:07
This site uses HTTP Strict Transport Security (HSTS) to specify that Iceweasel-UXP may only connect to it securely. As a result, it is not possible to add an exception for this certificate.

You need to e-mail the site owner about that, we do not want to disable HSTS support as it would greatly affect users security during online banking. This of course affects every browser, not just Iceweasel-UXP.

You can see how poor the cert is here: https://www.ssllabs.com/ssltest/analyze.html?d=pkgs.fedoraproject.org#whyNotTrusted

Date User Effort (H:M)
watch my effort tracking timers

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing