Closed
Bug 556294
Opened 15 years ago
Closed 15 years ago
SSL Error Message for https://mozilla.com and https://mozilla.org
Categories
(mozilla.org Graveyard :: Server Operations, task)
mozilla.org Graveyard
Server Operations
Tracking
(Not tracked)
RESOLVED
DUPLICATE
of bug 398923
People
(Reporter: mcoates, Unassigned)
References
()
Details
Issue
A domain mismatch SSL error is presented to any user browsing to https://mozilla.com or https://mozilla.org. Our wildcard certificate is valid for *.mozilla.com or *.mozilla.org. This works great for all situations including https://www.mozilla.com. However, it does not accommodate the scenario where a user specifically types https://mozilla.com (or a link is created to that location).
This scenario can create a risk if users regularly see the SSL error message and become trained to click through the error. This may make them more prone to a MITM attack against a site where they actually enter sensitive information.
In addition, SSL error messages can result bad press amongst the technical community.
To reproduce:
Browse to https://mozilla.com/en-US/firefox/personal.html
or https://mozilla.org
Recommended Remediation
There are two methods to remediate this issue:
1. Purchase an additional certificate for https://mozilla.com and https://mozilla.org
2. Use redirects or server rewrites to automatically send a user to the "www" version of the https page. In order to avoid the SSL error message this must be designed so the user is redirected before the SSL handshake occurs. (See https://mozilla.org/access which redirects to http://www.mozilla.org/access)
Comment 1•15 years ago
|
||
This is not a security issue.
(In reply to comment #0)
> There are two methods to remediate this issue:
> 1. Purchase an additional certificate for https://mozilla.com and
> https://mozilla.org
See bug 398923 and related bugs.
> 2. Use redirects or server rewrites to automatically send a user to the "www"
> version of the https page. In order to avoid the SSL error message this must be
> designed so the user is redirected before the SSL handshake occurs. (See
> https://mozilla.org/access which redirects to http://www.mozilla.org/access)
That is not possible.
Assignee: nobody → server-ops
Group: websites-security
Status: NEW → RESOLVED
Closed: 15 years ago
Component: www.mozilla.com → Server Operations
Product: Websites → mozilla.org
QA Contact: www-mozilla-com → mrz
Resolution: --- → DUPLICATE
Version: unspecified → other
Reporter | ||
Comment 2•15 years ago
|
||
Not sure I agree with claim this isn't a security issue. The situation can be leveraged by attackers to the detriment of our users.
Re suggestion 2, a valid cert is required via subject alternate name or separate cert. So, agreed - wouldn't be possible in current situation
None-the-less, it is a duplicate.
Updated•10 years ago
|
Product: mozilla.org → mozilla.org Graveyard
You need to log in
before you can comment on or make changes to this bug.
Description
•