Firefox does not connect to "google.de" or "amazon.de" do to "HTTP Strict Transport Security (HSTS)"

  • Poslednja wotmołwa wot gimmeshelter

Firefox does not connect to "google.de" or "amazon.de" do to "HTTP Strict Transport Security (HSTS)". First I cleaned the "Firefox" (about:config). Then I deinstalled and reinstalled it. No change in behavior. I started with an empty "SiteSecurityServiceState.txt" Anyway still no connection possible to "google.de" or "amazon.de". I would be glad if anyone could help me.

BS is WIN10 Version 20H2 (Version 21H1 could not be loaded yet --> mistake while installing. I am still waiting for a solution to this problem via MS)

Sorry for my humble English.

Wubrane rozrisanje

Hi Jscher, that did it. You were perfectly right. "No proxy", and the connection works again. Thanks a lot!!!


Wšě wotmołwy (6)

It looks like your security software has replaced a certificate for these websites to spy on your secure browsing.

Using "Chrome" or "Edge" doesn't show this behavior. Amazon and Google are reachable under these browsers, guarded by the same security software. I use Symantecs "SEP" by the way.

Hi gimmeshelter, on the error page saying that Firefox did not connect, could you click the "Advanced" button. That section has at least two useful bits of information:

(1) Error code

Many of these are covered in the following article: How to troubleshoot security error codes on secure websites

(2) "View Certificate" link

This opens a page with details on the certificate that Firefox cannot verify as valid. Typically the best clues are in the Issuer/Issued by section where you may spot a link to particular software.

For https://www.google.de/ I have "Common Name: GTS CA 1O1"

For https://www.amazon.de/ I have "Common Name: DigiCert Global CA G2"

Hi jscher, Fehlercode: SEC_ERROR_UNKNOWN_ISSUER The error code is: https://www.google.de/

Der Zertifikat-Aussteller der Gegenstelle wurde nicht erkannt. (The certificate issuer of the remote terminal was not recognized.)

HTTP Strict Transport Security: false HTTP Public Key Pinning: true



What can I do? Is there a way to import the google and amazon certificate?

Thank you for the certificate, it shows:

Issuer Name = DigiCert Global Root G1A

This seems to be associated with a proxy, but in all the threads where I've seen it, no one has identified who that is. Either way, the usual workaround is:

  • Windows: "3-bar" menu button (or Tools menu) > Settings (previously "Options")
  • Mac: "3-bar" menu button (or Firefox menu) > Preferences
  • Linux: "3-bar" menu button (or Edit menu) > Preferences
  • Any system: type or paste about:preferences into the address bar and press Enter/Return to load it

In the search box at the top of the page, type proxy and Firefox should filter to the "Settings" button, which you can click.

Change to "No proxy"

Any difference?

