SSL Decryption Firefox issue

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

SSL Decryption Firefox issue

L3 Networker

I am testing SSL Decryption and have setup the certs.

IE and Chrome work like expected. But firefox is having an issue with untrusted site error  (Error code: sec_error_untrusted_issuer)

Has anyone worked around this problem before?

1 accepted solution

Accepted Solutions

For example:

Mozilla-cert.JPG

Thanks

View solution in original post

11 REPLIES 11

L3 Networker

I also want to say I have deleted my cookies like it said to in the Knowledge base, but this did not fix it, i also have deleted the files out of the profiles folder as well for firefox.

Hi Mark,

IE and Chrome uses same Certificate repository, while Mozilla uses different one.

You are supposed to import certificate to Mozilla Certificate repository. It should work fine from there.

Regards,

Hardik Shah

Thanks for the reply, I have imported it.  I followed this URL to generate the cert and sub cert.

How to Implement Certificates Issued from Microsoft Certificate Services

Our domain machines already have the at cert trusted.  I have tried importing it into the Firefox certs, but still it does not work.

L6 Presenter

How to import Cert in Mozilla repository?

Mozilla_Import.png

Import cert as mentioned in above post, it should work fine.

For example:

Mozilla-cert.JPG

Thanks

Thank you, this solved my problem.

My next question what about items like dropbox app, does the cert then have to sit on the machine?

Hi Mark,

Please provide more detail for better understanding.

Regards,

Hardik Shah

If our machines have something like the dropbox application on it, I assume then the traffic is using the local pc certificate store where our root cert is.  Does that make sense?

My next question what about items like dropbox app, does the cert then have to sit on the machine? 

AFAIK Dropbox uses a hard-coded client certificate embedded in the dropbox application and won't accept what is in the Windows and/or Firefox certificate store.  Your choices are (in no specific order):

1.) permit it knowing you can't decrypt it

2.) block it because you can't decrypt it

3.) limit its use to specific people because you can't decrypt it

4.) find a different solution that is more flexible with certificates and SSL MITM

Hi Mark,

For all applications using SSL decryption, process is same. Lets say google drive uses SSL decryption, then it will work the same way gmail works. No difference.

Howe very, there are some application which do not support SSL decryption.

List of Applications Excluded from SSL Decryption

Regards,

Hardik Shah

  • 1 accepted solution
  • 7827 Views
  • 11 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!