Friday, April 3, 2009

sec_error_unknown_issuer

Firefox 3.0 and above have the offensive wardship with serious security issue complains. Especially this is true for self-made certificates. Since policy 1.2 official vision is here.

Previous versions of Firefox were ok after playing with

about:config -> browser.ssl_override_behavior = 6

Attention! This trick doesn't seems to work so well when you use proxy connection.

A short story of "safe" alternative and fundamental solution:

  • make sure you don't use any proxy, at least to accept a desired certificate

  • install "perspectives" extension

  • (Optional) SSL Blacklist 30MB

  • (Optional) Finally, about:config -> browser.identity.ssl_domain_display = 1 to do the highlighting with SSL domain


For more details see the article.

No comments: