Cerca nel supporto

Attenzione alle mail truffa. Mozilla non chiederà mai di chiamare o mandare messaggi a un numero di telefono o di inviare dati personali. Segnalare qualsiasi attività sospetta utilizzando l'opzione “Segnala abuso”.

Learn More

Questa discussione è archiviata. Inserire una nuova richiesta se occorre aiuto.

TLS Chain issues but trusted?

more options

I have checked one website to check if there is an Problem, and there was it. Why is this site TRUSTED? may I know it?

here is a tested site link of it : https://www.ssllabs.com/ssltest/analyze.html?d=neis.go.kr

I have checked one website to check if there is an Problem, and there was it. Why is this site TRUSTED? may I know it? here is a tested site link of it : https://www.ssllabs.com/ssltest/analyze.html?d=neis.go.kr

Soluzione scelta

Hi SJang, that server obviously has a lot of problems with its configuration.

The chain issue mentioned on SSLLabs is that the site sends an extra certificate that is not required to verify its site certificate. That happens on a lot site (I've made that mistake myself with a Comodo bundle file) and as far as I can tell, that does not invalidate the certificate for any browser.

Firefox is able to find agreement on TLS 1.2 and a cipher that both the server and Firefox support, and therefore is able to make a secure connection even though the server allows weaker connections.

Leggere questa risposta nel contesto 👍 1

Tutte le risposte (1)

more options

Soluzione scelta

Hi SJang, that server obviously has a lot of problems with its configuration.

The chain issue mentioned on SSLLabs is that the site sends an extra certificate that is not required to verify its site certificate. That happens on a lot site (I've made that mistake myself with a Comodo bundle file) and as far as I can tell, that does not invalidate the certificate for any browser.

Firefox is able to find agreement on TLS 1.2 and a cipher that both the server and Firefox support, and therefore is able to make a secure connection even though the server allows weaker connections.