7 ms·
Not sure if it’s just me but I get an invalid SSL cert warning and can’t load the page (DDG mobile browser)
by binarymax 4y ago
Not sure if it’s just me but I get an invalid SSL cert warning and can’t load the page (DDG mobile browser)
- Aachen 4y agoWorks for me on a random old android browser (that wraps around standard webview afaik), using Android 10 or 11 not sure
- zem 4y agotheir manager paid for a valid SSL cert that they never used!
- jborean93 4y agoI get the same on Firefox on Linux (Fedora 37). It looks like the server is responding with an ECDHE key exchange using a SHA1 signature algorithm which is disabled on modern versions of OpenSSL. I'm not sure why it works on Chrome, maybe their TLS client is a bit more lax. You can see openssl fail to verify the signature locally with `openssl s_client -connect blog.dijit.sh:443` due to the wrong signature type. At least for me on Fedora, I believe Firefox uses the system policies and Fedora has set policies to block SHA1 signature algorithms https://fedoraproject.org/wiki/Changes/StrongCryptoSettings2#Detailed_Description https://fedoraproject.org/wiki/Changes/StrongCryptoSettings2....
- 28mm 4y agoI am not sure about that. On my system that openssl invocation fails because the site doesn't staple the intermediate Letsencrypt R3 certificate, and openssl doesn't retrieve it while browsers do. If their system is old enough perhaps they have a version of the ISRG X1 certificate that is cross-signed by the expired DST X3 certificate. Some ssl imlementations did poorly with this. https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/ https://letsencrypt.org/docs/dst-root-ca-x3-expiration-septe...
- jborean93 4y agoThat could be it for yourself but I have a newer OpenSSL version (3.0.8) and the error does state the following > 006E552F8D7F0000:error:0A000172:SSL routines:tls12_check_peer_sigalg:wrong signature type:ssl/t1_lib.c:1592: The error from Firefox is SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM which seems to align to what I'm seeing on the signature algorithm returned. Lastly by setting my system wide policy to allow the LEGACY (Fedora's term) algorithms the website starts to work on Firefox. It could very well be that the server is at fault here (based on what I've read this seems to be the case) and that's due to the Let's Encrypt cross signed certificate. But the reason it's failing to load on the client side is because some clients block SHA1 based signing algorithms and that's what the server is offering here.
- sbierwagen 4y agoWhat version of Android? Qualys shows a bunch of errors and an incorrect cert chain but it does manage to get a working connection on almost all test browsers: https://www.ssllabs.com/ssltest/analyze.html?d=blog.dijit.sh&s=2a02%3a2770%3a0%3a0%3a21a%3a4aff%3afebf%3a3acc https://www.ssllabs.com/ssltest/analyze.html?d=blog.dijit.sh...
- crote 4y agoSame issue here. My Firefox on Fedora gives "SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM". I found a bug report[0] which suggest it is (mostly) a server issue. Fedora refuses to use SHA1, and the server ignores the client's attempt to negotiate a more secure algorithm. [0]: https://bugzilla.mozilla.org/show_bug.cgi?id=1749670 https://bugzilla.mozilla.org/show_bug.cgi?id=1749670