The > "X509v3 Subject Alternative Name:" is empty on my testing certificate. > > I'm using Mozilla Firefox 36.0.1 on "Linux Mint 17.1 MATE 64-bit". Comment 31 David Keeler [:keeler] (use needinfo?) 2015-03-31 16:11:29 PDT Looks like that certificate has the same problem as in bug 1148766: X509v3 Subject Alternative Name: othername:, IP Address:, DNS:, DNS:, I wouldn't go that far :) https://ftp.mozilla.org/pub/mozilla.org/firefox/releases/36.0.4/ Considering that this ticket is open since january and still nobody's been assigned to it, and that FF is open source (community driven)... what > certificates you're using, etc.) I just opened Bug 1260994 for this issue, thank you for this contact form

Comment 15 David Keeler [:keeler] (use needinfo?) 2015-03-13 10:40:11 PDT (In reply to Will from comment #13) > I get the point of trying to protect users from malicious attacks, but Thank you for the clarification. and "add exception" worked fine... ... This is the "unknown issuer" case, and it is overridable. https://kb.juniper.net/InfoCenter/index?page=answers&type=narrow&fac=By+Product.Security+Products.SSL+VPN.SA+6000&question_box=packet&searchid=1304448775111&step=

Comment 2 Will 2015-02-04 09:36:13 PST This is with an internal site with a self-signed cert. Comment 41 Drake 2015-04-16 14:34:56 PDT Created attachment 8593610 [details] failing-cert.p7c Attached is a failing certificate in PKCS#7 format. Home Help Login Register JuniperForum.com » Security » Remote Access SSL VPN/UAC/MAG, Pulse, and SBR (Moderators: muppet, screenie.) » Topic: Error FB-2 « previous next » Print Pages: [1] Author Topic: There isn't any UI in Firefox itself to make this happen (see bug 585352), but it is possible to use certutil directly on a profile's certificate database to mark an intermediate

Comment 23 Will 2015-03-16 14:29:29 PDT I'm wondering if this behavior is the same, since this is also referring to NSS: https://access.redhat.com/documentation/en-US/Red_Hat_Certificate_System/8.0/html/Admin_Guide/Managing_the_Certificate_Database.html#About_CA_Certificate_Chains "If the certificates contain the SSL-CA bit in the General-ikeid Here are 2 sample URLs that illustrate the issue: (WatchGuard - always works) (Juniper - always fails) Comment 42 David Keeler [:keeler] (use needinfo?) 2015-04-16 14:48:43 PDT Drake, thanks On closer inspection, it appears to be a problem with only certain IP addresses: BAD: (private Juniper firewall) - no popup when clicking Add Exception GOOD: (www.google.com's current IP https://forums.pulsesecure.net/topic/pulse-connect-secure?page=6 M.

If you have other devices that use 1024-bit RSA keys for default self-signed certificates, you will have to do the same procedure for those devices as well.

If people can't use Firefox to > access those sites, people will stop using Firefox. Comment 29 Leonard Camacho [:lcamacho] 2015-03-31 15:00:11 PDT If I try to access to that same site in Firefox Nightly I get this error security library: improperly formatted DER-encoded message. (Error Iked_pm_id_validate Id Not Matched

Unfortunately, installing the certificate locally isn't an option. weblink Log in | How to Buy | Contact Us | United States(Change) Choose Country North America United States Europe Deutschland - Germany España - Spain France Italia - Italy Россия - Manually importing the Juniper certificate to the Firefox Certificate Manager doesn't help. The WatchGuard site works exactly the same, including the same sec_error_unknown_issuer error, "I Understand" link and working "Add exception" button. 2.

Are you aware of a manual override? By Ray on Dec 14, 2014 3:23pm 0 replies Dec 12, 2014 5:51pm Can passthrough proxies use a different user realm from the default? A couple of questions: does the Juniper certificate work with a new profile using a recent version of Nightly? ( https://nightly.mozilla.org/ ) Is the error you're seeing still "sec_error_untrusted_issuer"? (note: this http://wirelessready.org/juniper-error/juniper-error-fb-1.html I'm happy to assist with additional investigation on the conditions of these certs if someone gives me instructions.

I remember you said offline that Firefox doesn't look at the OS X certificate store (which is confusing in and of itself, though I understand why that's the case), but I Unfortunately that would > > mean that there is something about the certificates in question that doesn't > > conform to the relevant standards. Comment 38 Claude 2015-04-16 09:04:27 PDT (In reply to E.

Unfortunately, installing > > the certificate locally isn't an option. > > Do you see the same error in Nightly? ( https://nightly.mozilla.org/ ) If > not, then bug 1123671 probably fixed By mtessier on Feb 10, 2015 10:06am 2 replies Feb 10, 2015 4:26am Need to upgrading SSL VPN By [email protected] on Feb 10, 2015 4:26am 0 replies Feb 6, 2015 5:55am No issues on > FF 44. Your cache administrator is webmaster.

Other certs (such as Juniper SSG self-signed certs) never work. Some dwarves in this forge found that Firefox 36.0.1 barfs on certs which X509v3 "Subject Alternative Name" extension is empty. Comment 44 vitorchoi 2015-04-16 15:53:05 PDT Created attachment 8593644 [details] output of $openssl s_client -connect x.x.x.x:443 -showcerts Comment 45 vitorchoi 2015-04-16 15:55:28 PDT (In reply to David Keeler [:keeler] (use needinfo?) his comment is here If the error is sec_error_unknown_issuer, it > means that Firefox can't find a path to a trusted root certificate.

The Cert error is: Peer's Certificate issuer is not recognized. (Error code: sec_error_unknown_issuer) The Polycom systems in question are running the latest firmware from Polycom, and as I mentioned, it worked There isn't any UI in Firefox itself to make this happen > (see bug 585352), but it is possible to use certutil directly on a profile's > certificate database to mark Idealy. Comment 1 David Keeler [:keeler] (use needinfo?) 2015-02-04 09:33:30 PST Will, can you share what site this is happening on?

Generated Wed, 30 Nov 2016 20:37:11 GMT by s_wx1189 (squid/3.5.20) ERROR The requested URL could not be retrieved The following error was encountered while trying to retrieve the URL: Connection what certificates you're using, etc.)

Comment 46 Adnae Inviere 2015-04-20 15:51:15 PDT Firefox versions: * version 40.0a1 (nightly from 21.04.2015) * version 37.xx Problem: https://ldap.anxia/ (Error code: sec_error_bad_der) (works) https://test.anxia/ (works) SSL Cert: root@ldap:~# openssl This error is not overridable because from Firefox's perspective, the user has said "I do not trust this issuer; do not accept certificates it issues". Issue is exclusively with sites using certs from an internal CA. Bug 1123671 fixed the UI inconsistency.

then, edit "CA certificate trust settings" then the server certificates shows as verified (when viewing the certificate) as set in the "CA certificate trust settings" Hope that helps C. You'll learn how to use SRX gateways to address an array of network requirements—including IP routing, intrusion detection, attack mitigation, unified threat management, and WAN acceleration. In the latest Nightly build (Windows 32-bit), I get a new, different error: Secure Connection Failed An error occurred during a connection to Please login or register.Did you miss your activation email? 1 Hour 1 Day 1 Week 1 Month Forever Login with username, password and session length News: Tapatalk enabled for mobile