7 ms·
> Chrome will try to match intermediate certificates with what it is seen since the browser has been started. This has the effect of meaning that a cold start o
by gregmac 3y ago
> Chrome will try to match intermediate certificates with what it is seen since the browser has been started. This has the effect of meaning that a cold start of Chrome does not behave the same way as a Chrome that has been running for 4 hours.
Holy crap. I have definitely run into this in the past, but had no idea!
I was configuring a load balancer that served SSL certificates for customer domains which included a mix of wildcard, client-supplied and LetsEncrypt-obtained certificates, and was all dynamically configured based on a backend admin app.
I was getting wildly inconsistent behavior where I'd randomly get certificate validation errors, but then the problem would disappear while diagnosing it. The problem would often (but not always) re-occur on other systems or even on the same system days later, and disappear while diagnosing. I never isolated it to Chrome or the time-since-Chrome-was-restarted, but I do remember figuring out it only affected certificates using an intermediate root. There was a pool of load balancers and I remember us spending a lot of time comparing them but never finding any differences. The fix ended up being to always include the complete certificate chain for everything, so I am pretty confident this explains it.
This was several years ago, but maddening enough that reading this triggered my memory of it.