
Firefox update
For past few weeks, Whenever I try to update FFX on windows 11, it fails. It takes me to another screen and tells me to download Firefox. When I try to download it , it aborts with this message.
"download.mozilla.org has a security policy called HTTP Strict Transport Security (HSTS), which means that Firefox can only connect to it securely. You can’t add an exception to visit this site."
To download Firefox with new version I have to use another browser but no choice. Then with new version of Firefox, I have faced the same issue of update and used same approach to update firefox to a newer version.
This error appears for some google sites as well but the same occurring for firefox download site itself is not understood.
Ajay
An gyara
All Replies (9)
Hello
Maybe this issue happen when your system's date and time are incorrect, which makes the browser think the security certificate is invalid. If the date is wrong, the browser can't verify the certificate's validity and blocks the connection.
I suggest you check your date and time first.
Thanks. I have searched possible solutions before posting this and one of the post did refer time and date mismatch. But there is no mismatch. I do not use location services so may be server assumed location and actual location mismatch leading to time and date mismatch. This did not happen as few Firefox versions earlier so something changed in between.
Ajay
Hey Ajay, clarification question, did this happen when you try to migrate from Windows 10 to Windows 11 and sync your Firefox, or you already have Firefox installed on Windows 11 and wanted to update it?
Thanks Konstantina
I have been using WIn11 for almost last five years and never had an issue like this. It is only recently (may be last few versions, v141 onward probably) this issue has crept in. The Firefox I use is not installed from MS store but directly downloaded from Mozilla site.
To add further, I also have Linux installed on dual boot mode. I have the similar profile but separate folders for FFX profile for Win and Linux. Till V141 I did not have any such issue in Win11 version.
When I experienced the reported issue opening one of the google site (https://www.google.com/finance/quote/NIFTY_50:INDEXNSE) on win11, I copied over the linux FFX profile and used it for Win 11 FFX and the quoted google site worked. As linux have a different approach for FFX update, the FFX win11 is still causing the reported update issue since v141. I remember to have downloaded FFX for three to four time in last few weeks using another browser since it won't update directly or let me download FFX using FireFox itself.
Ajay
Thanks Ajay, and just to confirm, the problem appears on Firefox Release correct? Not Nightly or Beta versions?
Thanks. Yes I use Firefox Release.
Hi Ajay, on the page where you get the secure connection error, can you find a View Certificate link? This might require first clicking an Advanced button.
For comparison, the issuer signing cert I see for the site is "DigiCert TLS RSA SHA256 2020 CA1"
Thanks. See the attachment.
Hi Ajay, the certificate screen indicates that the certificate was issued by Bitdefender. If Bitdefender is intercepting this connection, presumably it is filtering all of your browsing connections. Therefore, it's surprising that Firefox rejected the fake certificate in this case but not in other cases. My guess would be that Mozilla has barred exceptions for its most sensitive sites to protect against impostors there.
A lot of people use Bitdefender, so you probably are not alone in this situation. But when I searched on Bugzilla, I couldn't find an open bug. If Bitdefender doesn't have any workaround (i.e., ability to exclude download.mozilla.org from interception), you could file a new bug. https://bugzilla.mozilla.org/