Showing questions for topic:

Firefox Desktop Version 157 TLS key logging warning — Norton 360 Standard is suspected, but HTTPS scanning tests did not resolve it and so I need help with identifying the root casues and sepcifc steps to eliminate this warning

My system • Windows 11 on a Dell laptop. • Firefox Version 157, my default browser. • Norton 360 Standard. • Two Firefox profiles; the warning appears in both. • Firefox … (les mer)

My system • Windows 11 on a Dell laptop. • Firefox Version 157, my default browser. • Norton 360 Standard. • Two Firefox profiles; the warning appears in both. • Firefox Troubleshooting Mode does not eliminate the warning https://support.mozilla.org/en-US/kb/sslkeylogfile-warning?utm_source=chatgpt.com


What I have observed The warning appears on Firefox network-error pages, including when the internet is disconnected or I enter an incorrect URL. A particularly reproducible example occurs after I successfully log in to Kotak Net Banking and select Help → Raise a Query. Firefox then displays a connection/privacy warning associated with the embedded page. I do not see the same behaviour in Chrome or Firefox Private Browsing when performing the equivalent Kotak steps. Troubleshooting already completed 1. Norton Safe Web HTTPS scanning was disabled and re-enabled without resolving the issue. 2. QUIC/HTTP3 scanning, WebSocket Protocol Scanning and DNS/DoH scanning were individually tested without resolving it. 3. Firefox Enterprise Policies are inactive. 4. I found no SSLKEYLOGFILE entry in either Windows User Variables or System Variables. 5. Norton and Dell malware scans found no malware. 6. The warning also occurs when I connect through a mobile phone hotspot rather than my usual BSNL connection. Questions for Mozilla's technical contributors 1. Does this warning establish that Firefox detects SSLKEYLOGFILE, or could another mechanism produce the same message? 2. Can the variable be inherited by Firefox from a parent process or injected into its running process even when it is absent from the Windows User and System Variables? 3. What is the safest way to identify which process or security product is setting it on Windows 11? 4. Is there a known interaction between Firefox 157 and Norton 360 Standard that could explain this behaviour? 5. What evidence should I collect to distinguish a Norton issue from a Firefox issue without disabling security protections or modifying Windows settings? I am not looking to disable security features indiscriminately. I want to identify the actual cause and, if Norton is responsible, determine the precise setting that needs attention. I would particularly appreciate a response from a contributor with Windows networking, Firefox TLS or security-software diagnostic experience. Thank you.

Open 2

Thank you. I would like to know the specific steps for addressing both the error state shown, and the TLS logging

Thank you. I’m not a technical person and so could you please share the specific and safe steps which will resolve both the error state shown, and the TLS logging issue … (les mer)

Thank you. I’m not a technical person and so could you please share the specific and safe steps which will resolve both the error state shown, and the TLS logging issue without creating any other unintended consequences. I don’t want create any additional problems while trying to address these two issues. Thank you

Open 6 1

The certificate for inbound.att.net does not come from a trusted source.

Thunderbird will not download mail. It sends this: "The certificate for inbound.att.net does not come from a trusted source." "Location: inbound.att.net:995" Then it sen… (les mer)

Thunderbird will not download mail. It sends this: "The certificate for inbound.att.net does not come from a trusted source." "Location: inbound.att.net:995" Then it sends the data with the certificate information. I am not a programmer, I do not understand what I am supposed to do to get it going again.

Solved 19 7

certificate has been revoked. unable to receive email.

AVG sends message: "We've identified a site certificate problem" "Trust for this certificate has been revoked." Looking at certificate page that AVG provides is Greek … (les mer)

AVG sends message: "We've identified a site certificate problem" "Trust for this certificate has been revoked."

Looking at certificate page that AVG provides is Greek to me. General tab displays:

"This certificate has been revoked by its certification authority"

issued to : inbound.att.net

issued by: Digicert Global G2 TLS RSA SHA256 20250 CA1

Valid from: 4/12/26 to 10/28/26

Details tab:

lists a bunch of things that I don't comprehend and offers an option to "copy to file" and lists a number of formats to copy the file to.  Have no idea which would be the one to use. 

Trying to access email directly from browser has not been successful because it wants verify my identity by sending message to my phone, but it does not send anything.

Solved 15 11

Windows 11 preview update results in invalid certificate error - timezone change

Hi there. I'm in Alberta, where we have recently changed timezones. Note that the CLOCK has not changed yet, as we are still before the date in November when we would "fa… (les mer)

Hi there.

I'm in Alberta, where we have recently changed timezones. Note that the CLOCK has not changed yet, as we are still before the date in November when we would "fall back". We were UTC-6 summer and UTC-7 winter. Windows called this "Mountain Time (USA and Canada), but now the "Mountain Time (Alberta)" timezone is in Windows after the 2026-09 Preview Update (KB5124010) (26300.9550).

When connecting to Shaw.ca's IMAP servers, the certificates that were valid prior to the Windows update are now reported as invalid. This has been confirmed across two separate PCs with different email accounts. The data for the certificate LOOKS valid (see screenshot) and is the same before and after the timezone change.

The failure occurred on the latest ESR release of Thunderbird, as well as 156.0 and 157.0 non-ESR.

Thanks :)

Open 5 1 20

Norton blocks Thunderbird email due to "expired certificate"

I have Thunderbird installed on Windows 11 along with Norton 360. Today, my connection to the AT&T e-mail server suddenly disconnected and I immediately got a pop-up… (les mer)

I have Thunderbird installed on Windows 11 along with Norton 360. Today, my connection to the AT&T e-mail server suddenly disconnected and I immediately got a pop-up notification that Norton detected a problem with a security certificate. When I inspected the details, it indicated that the certificate for inbound.att.net had expired (the range of valid dates on the certificate actually listed the current date as the last valid date). After several infuriating calls with AT&T support and Norton support, I figured out that simply disabling Norton e-mail protection allowed me to access my e-mail account.

Multiple web searches on similar issues suggested that since Thunderbird has its own certificate storage, fixing the problem involves locating the Norton certificate file and importing it using Thunderbird's certificate manager. Unfortunately, that solution appears to be applicable for first-time Thunderbird installation, and I when I tried it I was informed that the certificate was already installed. Another web search suggested that I should go to the Authorities tab and remove the entry for "Norton Email Protection". Unfortunately, the entry that I found was for "Norton Web/Mail Shield", which according to at least one source is not the same thing, so I am afraid to remove it.

So my question is has anyone else encountered this same problem, and is the correct approach to remove the Norton Web/Mail Shield authority before importing Norton's certificate file?

Open

indication is that certificate has expired, email will not download (new problem as of today)

Norton flags that the Thunderbird certificate has expired. Looked at instructions on the help, but most are to start from scratch. This is a new problem as of today, so… (les mer)

Norton flags that the Thunderbird certificate has expired. Looked at instructions on the help, but most are to start from scratch. This is a new problem as of today, so fairly sure it isn't on my end, but cannot verify.

Open

Thunderbird 140.15.0esr does not find a manually imported S/MIME recipient certificate although it is correctly displayed under “People” in the Certificate Manager.

I am trying to send an S/MIME encrypted email from Thunderbird to: jobcenter-chemnitz.netzwerkpartner@jobcenter-ge.de The recipient certificate is provided by the officia… (les mer)

I am trying to send an S/MIME encrypted email from Thunderbird to:

jobcenter-chemnitz.netzwerkpartner@jobcenter-ge.de

The recipient certificate is provided by the official certificate directory of the German Federal Employment Agency (Bundesagentur für Arbeit).

I downloaded the recipient certificate and successfully imported it into Thunderbird under:

Settings → Privacy & Security → Certificates → Manage Certificates → People

The certificate is displayed correctly there. The email address contained in the certificate is:

jobcenter-chemnitz.netzwerkpartner@jobcenter-ge.de

The certificate is valid from July 29, 2026 to July 29, 2028 and includes E-mail Protection and Key Encipherment.

The required CA certificates are also installed:

BA-Class-1-Root-CA-4:PN BA-VPS-CA-11:PN

However, when I compose an encrypted email to this exact address, Thunderbird reports:

“You have selected to encrypt this message, but the application failed to find an encryption certificate for jobcenter-chemnitz.netzwerkpartner@jobcenter-ge.de.”

Under S/MIME → Recipient Certificates, Thunderbird also shows the certificate as “Not found”.

I have already tried:

deleting and re-importing the recipient certificate completely restarting Thunderbird after importing it manually typing the recipient address in lowercase without using autocomplete checking the complete CA certificate chain temporarily disabling OCSP

None of these changed the result.

My own personal S/MIME certificate works correctly. As a test, I can compose an encrypted email to my own email address without any certificate error. Therefore, the basic S/MIME configuration and my own certificate appear to be working.

When I reproduce the problem with the Thunderbird Error Console open, I get:

NS_ERROR_ILLEGAL_VALUE (0x80070057)

related to:

nsIMsgComposeSecure.beginCryptoEncapsulation

This seems similar to Mozilla Bug 2021265, where a manually imported recipient certificate is visible in Certificate Manager but is not found when composing an encrypted message.

Is this a known issue in Thunderbird 140 ESR, and is there a workaround for using this manually imported recipient certificate?

Open 1

Request for assistance with Firefox 157 TLS/SSLKEYLOGFILE warning

Hi Amazing Friends I am proud Mozillian from India. I served as Chair, Mozilla Reps Council twice in the past, good to connect you once again. I need your expert help on … (les mer)

Hi Amazing Friends

I am proud Mozillian from India. I served as Chair, Mozilla Reps Council twice in the past, good to connect you once again.

I need your expert help on following.

One of my friend is facing an issue with the latest Firefox 157 browser. Firefox is displaying the following warning while accessing the Kotak Bank website

“Your connection may not be private. An app or service may see your encrypted traffic from this site.”

The Firefox explanation indicates that the issue is related to TLS Logging / SSLKEYLOGFILE being enabled.

She has Norton 360 anti-virus and suspecting that if the antivirus/security may be involved in inspecting encrypted HTTPS traffic.

We would particularly like to understand:

Why Firefox 157 is detecting TLS key logging on system, which application or service is setting/using SSLKEYLOGFILE, whether Norton 360 is enabling it, and whether there is a safe Firefox or Windows configuration change that can eliminate the warning without weakening HTTPS security.

We would appreciate the opportunity if some of you can help at your earliest convenience.

Thank you very much for your help.

Regards,

Shahid

Open 1

Certificate not from trusted source.

Thunderbird email says the certificate for my Shaw email server does not come from trusted source. The certificate looks fine. I cannot get Thunderbird to "Add exception"… (les mer)

Thunderbird email says the certificate for my Shaw email server does not come from trusted source. The certificate looks fine. I cannot get Thunderbird to "Add exception". The certificate issue seems to be an intermittent problem since yesterday lunchtime. It started working again yesterday afternoon, but stopped working at lunchtime today. How do I stop this error?

Solved 2 14

SHA3 support

Hi, I remember i tried 7y. ago a email certificate signed with SHA3, it was not OK. I tried again now, and it is still blocked. 1) the certs can be added in the account s… (les mer)

Hi,

I remember i tried 7y. ago a email certificate signed with SHA3, it was not OK.

I tried again now, and it is still blocked.

1) the certs can be added in the account settings > S/MIME for signature and ciphering, with a warning. 2) then creating a new email, the recipients certificates are not detected (while configured in another account on the same thunderbird client), and forcing ciphering is not allowed with the error message

"Sending of the message failed. This message cannot be digitally signed because the signing certificate selected in your End-to-End Encryption settings is not valid for this operation. (The certificate was signed using a signature algorithm that is disabled because it is not secure.)"

"Unable to save your message as a draft. This message cannot be digitally signed because the signing certificate selected in your End-to-End Encryption settings is not valid for this operation. (The certificate was signed using a signature algorithm that is disabled because it is not secure.)"

Even, when using only ciphering, and no signature in S/MIME.

The parameter mail.smime.accept_insecure_sha1_message_signatures do not change the bahavior.


-> Can Thunderbird allow SHA3 usage, please ?

Even if thunderbird does not want to generalize it, mozilla may create a parameter by default false

mail.smime.accept_sha3_message_signatures


Best Regards, Gwenolé

Open

Confirm Security Exception is not persistant when permanently stored

I am using an email server that currently is using certificates that have expired. That problem is being worked on. In the meantime, whenever I access the server to open … (les mer)

I am using an email server that currently is using certificates that have expired. That problem is being worked on. In the meantime, whenever I access the server to open a folder, I get a pop-up notification telling me that the certificate has expired. I go ahead and confirm the security exception and check the box to permanently store the exception. Trouble is this ISN'T being persisted, when I open a different folder I have to go through this process again in order to access my emails in that folder.

Me thinks you got a bug in your software Kemosabe!

Arkivert 4 252

I can't get me e-mails today it says someone might be trying to impersonate the server so not to continue.

I can't get my e-mails today. I got a message saying The certificate for pop.centurylink.net is not valid for that server. Someone could be trying to impersonate the serv… (les mer)

I can't get my e-mails today. I got a message saying The certificate for pop.centurylink.net is not valid for that server. Someone could be trying to impersonate the server and you should not continue.

Why did I get this message? I never saw this before. I like to get my e-mails. I tried reseting my router and turned off my computer and it still says the same thing. What do I do and how will I see your reply if I can't get the e-mails? Please fix this. My e-mail is toosmiley@centurylink.net

Thank you

Open

removing malicious certificate that is blocking mail

I can't find the certificate in order to delete/distrust it. Its name is my mail server. Organization: Lumen Technologies, Monroe, Louisiana Subject Name Country US State… (les mer)

I can't find the certificate in order to delete/distrust it. Its name is my mail server. Organization: Lumen Technologies, Monroe, Louisiana

Subject Name Country US State/ProvinceLouisiana LocalityMonroe Organization Common Name Lumen Technologies, Inc. mail.centurylink.net Issuer Name Country Organization Common Name US DigiCert Inc DigiCert Global G2 TLS RSA SHA256 2020 CA1 Validity Not BeforeWed, 27 Aug 2025 00:00:00 GMT Not AfterSun, 27 Sep 2026 23:59:59 GMT

Open 1 10