-
TheSHAD0W
Hey, how do I add a self-signed certificate to the browser now? And how do I bypass an expired cert?
-
frg_Away
TheSHADOW certificate management has not changed much. Still in Preferences Privacy & Security Certificates. Rarely use it so maybe check mozillaZine for documentation.
-
frg_Away
For websites you can usually bypass if you load it on a per session base. Permanently not sure if possible.
-
TheSHAD0W
frg_Away: There's no click-through to bypass any more.
-
TheSHAD0W
Either per-session or to add to the cert database.
-
TheSHAD0W
Makes it a much bigger problem if governments start trying to censor websites by monkeying with certs.
-
tomman
also, there is strict HSTS with no bypass by design
-
frg_Away
tomman yes Suspect strict transport security is on.
-
tomman
and if your government is tampering with SSL, you've had BIGGER problems than a exceptions dialog
-
tomman
---you've got
-
TheSHAD0W
Of course it is. So is there a way to turn off strict transport security?
-
TheSHAD0W
In about:config I assume?
-
TheSHAD0W
I see network.stricttransportsecurity.preloadlist but no separate one.
-
TheSHAD0W
Tried several ways to get the old behavior back and haven't been successful.
-
TheSHAD0W
It's not the first time some site operator let a cert expire, and it won't be the last, and turning off a way to bypass it is just stupid.
-
TheSHAD0W
This doesn't even have the "thisisunsafe" bypass that's in chrome. I think I'm finally going to have to switch browsers.
-
frg_Away
bye then
-
njsg
TheSHAD0W: there is, I think, a store inside the profile. wasn't this in readable text? it might be possible to edit that file to reset the site's hsts status
-
njsg
I don't know the current interface to bypass such situations, except for knowing it won't show the bypass button when hsts had been detected in the past
-
frg_Away
SiteSecurityServiceState.txt
-
njsg
there's something in the certificate manager, let me see if it works
-
njsg
it's possible to add an exception but it seems it's ignored with HSTS?
-
therube
i only saw 1 post on "virustotal", so i might have missed something... anyhow,
virustotal.com/old-browsers
-
tomman
therube: awesome
-
tomman
now SeaMonkey is considered IBM-vintage
-
therube
heh.
-
tomman
well, at least they have AN option for us, unlike many sites that drank the Google Kool-Aid
-
tomman
I was looking to check some file last week with VirusTotal, just to discover that Chromeisms have infected them
-
therube
VirusTotal IS Google. (google bought them a long time back. And given that Chrome is Google ;-) ...)
-
tomman
oh, so that explains a lot
-
tomman
VirusTotal IS a virus then
-
tomman
another sad day for the Internet then