3 ms·
Looks like that bug was reported for Chrome 37, which is the last version of Chrome to rely on the underlying OS for validating SHA-2 Certificates. Chrome 38+
by Gregordinary 10y ago
Looks like that bug was reported for Chrome 37, which is the last version of Chrome to rely on the underlying OS for validating SHA-2 Certificates.
Chrome 38+ should be able to validate the cert.
"Chrome is capable of supporting SHA-2 certificates as of version 1.0, however through version 37 it is dependent on the operating system. For instance, on Windows Server 2003 without MS13-095 or Windows XP SP2 Chrome will not connect to pages using SHA-2 certs. Applying MS13-095 to Server 2003, or SP3 to Windows XP will allow Chrome to support SHA-2 on these legacy systems.
Chrome 38+ can validate SHA-2 certificates independently, even on systems like Server 2003 without MS13-095 applied."
Source: https://support.globalsign.com/customer/en/portal/articles/1499561-sha-256-compatibility#1a https://support.globalsign.com/customer/en/portal/articles/1...
- prdonahue 10y agoYou're missing the point. Yes, Google hacked in SHA-2 support into M38[1] but not ECDSA support, which is why them advertising the SHA-2/ECDSA pair is bad. [1] -https://chromium.googlesource.com/chromium/src/+/25e2bc0a95354727342757ba71582bf4de638fe8 https://chromium.googlesource.com/chromium/src/+/25e2bc0a953...
- Gregordinary 10y agoAh, I see what you're saying. Thank you for the clarification.