Closed Bug 1683781 Opened 4 years ago Closed 4 years ago

SEC_ERROR_REVOKED_CERTIFICATE on hetzner.com due to security.pki.crlite_mode=2 (Nightly default)

Categories

(Core :: Security: PSM, defect)

x86_64
Linux
defect

Tracking

()

RESOLVED DUPLICATE of bug 1683525
Tracking Status
firefox-esr78 --- unaffected
firefox84 --- disabled
firefox85 --- disabled
firefox86 --- disabled

People

(Reporter: jan, Unassigned)

References

(Blocks 1 open bug, Regression)

Details

(Keywords: nightly-community, regression)

Gnome Xwayland, Debian Testing

Certificate after opening the website:

about:certificate?cert=MIIGgjCCBWqgAwIBAgIQCMGtgMH1A6YKOkIizXlMuDANBgkqhkiG9w0BAQsFADBfMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMR4wHAYDVQQDExVUaGF3dGUgRVYgUlNBIENBIDIwMTgwHhcNMjAwNzA5MDAwMDAwWhcNMjEwODIyMTIwMDAwWjCB5zEdMBsGA1UEDwwUUHJpdmF0ZSBPcmdhbml6YXRpb24xEzARBgsrBgEEAYI3PAIBAxMCREUxFzAVBgsrBgEEAYI3PAIBAhMGQmF5ZXJuMRgwFgYLKwYBBAGCNzwCAQETB0Fuc2JhY2gxETAPBgNVBAUTCEhSQiA2MDg5MQswCQYDVQQGEwJERTEPMA0GA1UECBMGQmF5ZXJuMRUwEwYDVQQHEwxHdW56ZW5oYXVzZW4xHDAaBgNVBAoTE0hldHpuZXIgT25saW5lIEdtYkgxGDAWBgNVBAMTD3d3dy5oZXR6bmVyLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKvlXt%2B0TcG%2FYvZ63Ts3FwQOICn%2BMnGtb301nN12vMIFm6dqsHEXDobcrWX%2BFA0JSlTyWo59lAeCK8Ec9t1RBRdyQwvJErLGSTPWijRN5vUfay8cCBTBshIVp340y5wDYbKvEaCmdSH5YjSjazqm4BjGIdHoicOyF9wzLBort2jG8%2Fg6ohl1QFc5cEHfMvFF44qBJOWKqmGACJ2hOD%2FMiE2Fl17bCaGFeL1jtCQuod7TRXMwVzvlEHSBwerz37vU7af1esLUJ0be7lexxIeUIPx5EMfaT2lMrxBEg4mcDFH4%2FcoOaDNoANWVUISm0wz7JwEOeWgGKHK0nBp1wEFkcQ8CAwEAAaOCAq8wggKrMB8GA1UdIwQYMBaAFOcB%2FAwWGMp9sozshyejb2GBO4Q5MB0GA1UdDgQWBBQel%2FsZBkS0KKP1CAYRpJDJlbgWOjAnBgNVHREEIDAeggtoZXR6bmVyLmNvbYIPd3d3LmhldHpuZXIuY29tMA4GA1UdDwEB%2FwQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwPAYDVR0fBDUwMzAxoC%2BgLYYraHR0cDovL2NkcC50aGF3dGUuY29tL1RoYXd0ZUVWUlNBQ0EyMDE4LmNybDBLBgNVHSAERDBCMDcGCWCGSAGG%2FWwCATAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMAcGBWeBDAEBMHEGCCsGAQUFBwEBBGUwYzAkBggrBgEFBQcwAYYYaHR0cDovL3N0YXR1cy50aGF3dGUuY29tMDsGCCsGAQUFBzAChi9odHRwOi8vY2FjZXJ0cy50aGF3dGUuY29tL1RoYXd0ZUVWUlNBQ0EyMDE4LmNydDAMBgNVHRMBAf8EAjAAMIIBAwYKKwYBBAHWeQIEAgSB9ASB8QDvAHUA9lyUL9F3MCIUVBgIMJRWjuNNExkzv98MLyALzE7xZOMAAAFzMrvZ9gAABAMARjBEAiBMA5SuokRfrVzVBFHm6FtqAjKjSmWOdIOxbo7E8pjzhAIgO1UIowSkPDsshVW4OixwGbd46PS8r6%2BX2h8nMR8ZnVEAdgBc3EOS%2FuarRUSxXprUVuYQN%2FvV%2BkfcoXOUsl7m9scOygAAAXMyu9oeAAAEAwBHMEUCIEY9IVsgVbrqDCLaHdNk9dOMWW0qeOIpcSmv%2F60cZ7%2BQAiEAqsSZWhMisx%2BAUXPS8ZJHVSnqTHb%2BKHs5XthBwYuAyy0wDQYJKoZIhvcNAQELBQADggEBACWt0x8oO91%2BYpTryW4Ha%2BcT5N%2F3YyuITQKMCIj652qk3JnaJgF2HKlgFYLj4fiDfhFActVy1sBaEc3uB9BssLUnaCYwl6CrBpJr%2Fu3oo3sF%2B5zKECnEBLDs%2BeV4cZi2FLNHnPxE1rNZ609nze0lLcdAnfAyDtl0cXflntl0m1xzlXOoRMjocMBam80DjgPrdCt8qhPD0fyFcqY5aB7npWF67hWD1wltHAmIYyjW5DnMzsLz9DZcK4gH%2BkM6XDCuu4apK2vwrFCup8Y7ksZU21nUYxxO%2FLGESGHQqtMevLRiXipYCzadqoIr%2B7X9i6FY6z6svqGmNNHnghRO8dPknHk%3D&cert=MIIEoDCCA4igAwIBAgIQBpaPlkroI1bHThfCtTZbADANBgkqhkiG9w0BAQsFADBsMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSswKQYDVQQDEyJEaWdpQ2VydCBIaWdoIEFzc3VyYW5jZSBFViBSb290IENBMB4XDTE3MTEwNjEyMjI1N1oXDTI3MTEwNjEyMjI1N1owXzELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEeMBwGA1UEAxMVVGhhd3RlIEVWIFJTQSBDQSAyMDE4MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp0Cu52zmdJFnSezXMKvL0rsoWgA%2F1X7OxjMQHsAllID1eDG836ptJXSTPg%2BDoEenHfkKyw%2B%2BwXobgahr0cU%2F2v8RWR3fID53ZDhEGHzS%2BOl7V%2BHRtZG5teMWCY7gldtBQH0r7xUEp%2F3ISVsZUVBqtUmLVJlf9nxJD6Cxp4LBlcJJ8%2BN6kSkV%2BfA%2BWdQc0HYhXSg3PxJP7XSU28Wc7gf6y9kZzQhK4WrZLRrHHbHC2QXdqQYUxR927QV%2BUCNXnlbTcZy2QpxWTPLzK%2B%2FcKXX4cwP6MGF7%2B8RnUgHlij%2F5V2k%2FtIF9ep4B72ucqaS%2FUhEPpIN%2FT7A3OAw995yrB38glQIDAQABo4IBSTCCAUUwHQYDVR0OBBYEFOcB%2FAwWGMp9sozshyejb2GBO4Q5MB8GA1UdIwQYMBaAFLE%2Bw2kD%2BL9HAdSYJhoIAu9jZCvDMA4GA1UdDwEB%2FwQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH%2FBAgwBgEB%2FwIBADA0BggrBgEFBQcBAQQoMCYwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRpZ2ljZXJ0LmNvbTBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8vY3JsMy5kaWdpY2VydC5jb20vRGlnaUNlcnRIaWdoQXNzdXJhbmNlRVZSb290Q0EuY3JsMD0GA1UdIAQ2MDQwMgYEVR0gADAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMA0GCSqGSIb3DQEBCwUAA4IBAQAWGka%2B5ffLpfFuzT%2BWlwDRwhyTZSunnvecZWZTPPKXipynjpXx5dK8YG%2B2XoH74285GR1UABuvHMFV94XeDET9Pzz5s%2FNHS1%2FeAr5eGdwfBl80XwPkwXaYqzRtw6J4RAxeLqcbibhUQv9Iev9QcP0kNPyJu413Xov76mSuJlGThKzcurJPive2eLmwmoIgTPH11N%2FIIO9nHLVe8KTkt%2BFGgZCOWHA3kbFBZR39Mn2hFS974rhUkM%2BVS9KbCiQQ5OwkfbZ%2F6BINkE1CMtiESZ2WkbxJKPsF3dN7p9DFYWiQSbYjFP%2BrCT0%2FMkaHHYUkEvLNPgyJ6z29eMf0DjLu%2FSXJ&cert=MIIDxTCCAq2gAwIBAgIQAqxcJmoLQJuPC3nyrkYldzANBgkqhkiG9w0BAQUFADBsMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSswKQYDVQQDEyJEaWdpQ2VydCBIaWdoIEFzc3VyYW5jZSBFViBSb290IENBMB4XDTA2MTExMDAwMDAwMFoXDTMxMTExMDAwMDAwMFowbDELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTErMCkGA1UEAxMiRGlnaUNlcnQgSGlnaCBBc3N1cmFuY2UgRVYgUm9vdCBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMbM5XPm%2B9S75S0tMqbf5YE%2Fyc0lSbZxKsPVlDRnogocsF9ppkCxxLeyj9CYpKlBWTrT3JTWPNt0OKRKzE0lgvdKpVMSOO7zSW1xkX5jtqumX8OkhPhPYlG%2B%2BMXs2ziS4wblCJEMxChBVfvLWokVfnHoNb9Ncgk9vjo4UFt3MRuNs8ckRZqnrG0AFFoEt7oT61EKmEFBIk5lYYeBQVCmeVyJ3hlKV9Uu5l0cUyx%2BmM0aBhakaHPQNAQTXKFx01p8VdteZOE3hzBWBOURtCmAEvF5OYiiAhF8J2a3iLd48soKqDirCmTCv2ZdlYTBoSUeh10aUAsgEsxBu24LUTi4S8sCAwEAAaNjMGEwDgYDVR0PAQH%2FBAQDAgGGMA8GA1UdEwEB%2FwQFMAMBAf8wHQYDVR0OBBYEFLE%2Bw2kD%2BL9HAdSYJhoIAu9jZCvDMB8GA1UdIwQYMBaAFLE%2Bw2kD%2BL9HAdSYJhoIAu9jZCvDMA0GCSqGSIb3DQEBBQUAA4IBAQAcGgaX3NecnzyIZgYIVyHbIUf4KmeqvxgydkAQV8GK83rZEWWONfqe%2FEW1ntlMMUu4kehDLI6zeM7b41N5cdblIZQB2lWHmiRk9opmzN6cN82oNLFpmyPInngiK3BD41VHMWEZ71jFhS9OMPagMRYjyOfiZRYzy78aG6A9%2BMpeizGLYAiJLQwGXFK3xPkKmNEVX58Svnw2Yzi9RKR%2F5CYrCsSXaQ3pjOLAEFe4yHYSkVXySGnYvCoCWw9E1CAx2%2FS6cCZdkGCevEsXCS%2B0yx5DaMkHJ8HSXPfqIbloEpw8nL%2Be%2FIBcm2PN7EeqJSdnoDfzAIJ9VNep%2BOkuE6N36B9K

F5 after ~half a minute:

Secure Connection Failed

An error occurred during a connection to www.hetzner.com. Peer’s Certificate has been revoked.

Error code: SEC_ERROR_REVOKED_CERTIFICATE

The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.
Please contact the website owners to inform them of this problem.

mozregression --good 2020-11-01 --bad 2020-11-10 -a https://www.hetzner.com

20:13.46 INFO: Last good revision: 3f08ccb1f141069bfd90474d6023413303307ec4
20:13.46 INFO: First bad revision: b635c277c9f47d93515f8d957571b2e1f4aa51a4
20:13.46 INFO: Pushlog:
https://hg.mozilla.org/integration/autoland/pushloghtml?fromchange=3f08ccb1f141069bfd90474d6023413303307ec4&tochange=b635c277c9f47d93515f8d957571b2e1f4aa51a4

b635c277c9f47d93515f8d957571b2e1f4aa51a4 J.C. Jones — Bug 1675138 - Set CRLite to enforcement mode in Nightly-only r=keeler

Setting security.pki.crlite_mode back to 1 indeed fixes the problem.

Test sites don't show any problem:

Status: NEW → RESOLVED
Closed: 4 years ago
Resolution: --- → DUPLICATE
Has Regression Range: --- → yes
You need to log in before you can comment on or make changes to this bug.