Live data from Hacker News

Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

sslmate.com

11–20 of 95 posts

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#11
post #5

I'm using Chromium on Ubuntu 16, and I've been trying to visit https://www.nist.gov/ but I don't even get an option to 'browse insecurely' under the 'Advanced' link. In my experience that past couple days, I get the warning on about 10-25% of major web sites.

try typing 'badidea' on that page and report back if it works. :)

[deleted]

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#12
post #5

I'm using Chromium on Ubuntu 16, and I've been trying to visit https://www.nist.gov/ but I don't even get an option to 'browse insecurely' under the 'Advanced' link. In my experience that past couple days, I get the warning on about 10-25% of major web sites.

try typing 'badidea' on that page and report back if it works. :)

actually works

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#13

"Too many websites have chosen redaction incorrectly" I purchased a Symantec cert from ssls.com for one of my sites. I wasn't given the option of redacting anything.. yet I'm seeing this error with Chrome 53 in Linux. (I also have Chrome 54 on another computer, and it's working fine). There are clearly other ways of ending up with a certificate that triggers this.

Did you find your cert in the public log? What does the host name look like? Is it redacted? Maybe they did it without confirming with you, first :/

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#14
tl;dr: Symantec have tried to implement a broken version of Certificate Transparency on their Certs when IETF have not finished the spec.

As such new Symantec certificates don't work in newer versions of Chrome.

Crazy but true.

Kudos to the site owner - clear and simple and authoritative explanation

(Although I see the hand of politics behind this. "Hey we really fucked up the Google.com certificates. The board insists we do what Google wants and implement full certificate transparency by June 30. And it took two hours to explain it to the board so I am not going back to explain that it's all changed - Just implement the most recent IETF draft. Then I can tell the board it's done. What's the worst that can happen!"

Oh ....)

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#15

"Too many websites have chosen redaction incorrectly" I purchased a Symantec cert from ssls.com for one of my sites. I wasn't given the option of redacting anything.. yet I'm seeing this error with Chrome 53 in Linux. (I also have Chrome 54 on another computer, and it's working fine). There are clearly other ways of ending up with a certificate that triggers this.

> There are clearly other ways of ending up with a certificate that triggers this.

The update at the top of the blog post should explain why this error message is triggered even with an unredacted certificate.

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#16

I'm using Chromium on Ubuntu 16, and I've been trying to visit https://www.nist.gov/ but I don't even get an option to 'browse insecurely' under the 'Advanced' link. In my experience that past couple days, I get the warning on about 10-25% of major web sites.

Ugh that's the worst. I work on servers where the GUI can only be accessed using HTTPS, but its all internal so many clients don't bother. And I don't know why browsers sometimes don't let me say "continue anyway" but it's super frustrating.

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#17

"Too many websites have chosen redaction incorrectly" I purchased a Symantec cert from ssls.com for one of my sites. I wasn't given the option of redacting anything.. yet I'm seeing this error with Chrome 53 in Linux. (I also have Chrome 54 on another computer, and it's working fine). There are clearly other ways of ending up with a certificate that triggers this.

Did you find your cert in the public log? What does the host name look like? Is it redacted? Maybe they did it without confirming with you, first :/

Checked, and it's not redacted.

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#18
post #15

"Too many websites have chosen redaction incorrectly" I purchased a Symantec cert from ssls.com for one of my sites. I wasn't given the option of redacting anything.. yet I'm seeing this error with Chrome 53 in Linux. (I also have Chrome 54 on another computer, and it's working fine). There are clearly other ways of ending up with a certificate that triggers this.

> There are clearly other ways of ending up with a certificate that triggers this. The update at the top of the blog post should explain why this error message is triggered even with an unredacted certificate.

Yes, thanks. The cert isn't redacted. I read the update, then read the article, and forgot all about it. That probably explains it.

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#19

I'm using Chromium on Ubuntu 16, and I've been trying to visit https://www.nist.gov/ but I don't even get an option to 'browse insecurely' under the 'Advanced' link. In my experience that past couple days, I get the warning on about 10-25% of major web sites.

I do get the "proceed to www.xxx (unsafe)" under Advanced. Version 53.0.2785.143 Built on Ubuntu , running on Ubuntu 16.04 (64-bit)

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#20

"Too many websites have chosen redaction incorrectly" I purchased a Symantec cert from ssls.com for one of my sites. I wasn't given the option of redacting anything.. yet I'm seeing this error with Chrome 53 in Linux. (I also have Chrome 54 on another computer, and it's working fine). There are clearly other ways of ending up with a certificate that triggers this.

Would you mind sharing the domain?
Post reply on HN