cancel
Showing results for 
Search instead for 
Did you mean: 
Hayton
Level 17

This site in FF : "Secure Connection Failed". Again.

It's doing it again. This ought to have been fixed by now - do a search for previous posts about this issue. If Firefox get enough reports about this problem they'll classify this site as malicious.

FF OCSP error.PNG

0 Kudos
5 Replies
exbrit
Level 21

Re: This site in FF : "Secure Connection Failed". Again.

This appears to be a problem restricted to Firefox from past threads on the subject, but I don't see the error and I use Firefox.   Are you up to date and have everything set to default values?

0 Kudos
Hayton
Level 17

Re: This site in FF : "Secure Connection Failed". Again.


Ex_Brit wrote:



This appears to be a problem restricted to Firefox from past threads on the subject, but I don't see the error and I use Firefox.   Are you up to date and have everything set to default values?


It's most visible in Firefox because Firefox allows you to take a robust approach to verifying the identity of a website. There's a setting somewhere which tells the browser to reject a connection if the OCSP third-party certificate validation fails. In IE a failed validation is quietly ignored by default. Chrome may have a setting to check for this but I don't see it (yet).

What I do see in Chrome are warnings about insecure connections to this site.

Community security warnings.PNG

0 Kudos
Hayton
Level 17

Re: This site in FF : "Secure Connection Failed". Again.

I've raised this issue before and in those threads I went into considerable detail about security considerations, OCSP stapling, Firefox settings, and SSL failings. They bear reading through if you want to see how little has been done in this area in the past three years.

https://community.mcafee.com/message/233639#233639          March 2012

https://community.mcafee.com/message/319413#319413          February 2014

https://community.mcafee.com/message/333176#333176          May 2014

0 Kudos
exbrit
Level 21

Re: This site in FF : "Secure Connection Failed". Again.

I wonder why I don't see this?

0 Kudos
Hayton
Level 17

Re: Re: This site in FF : "Secure Connection Failed". Again.


There's a setting somewhere which tells the browser to reject a connection if the OCSP third-party certificate validation fails.


So there is, and this is where it is in Firefox.

FF OCSP option.PNG

0 Kudos