搜尋 Mozilla 技術支援網站

防止技術支援詐騙。我們絕對不會要求您撥打電話或發送簡訊,或是提供個人資訊。請用「回報濫用」功能回報可疑的行為。

Learn More

access to a site with revoked certificate is allowed

  • 無回覆
  • 1 有這個問題
  • 4 次檢視
more options

When I try to access the website https://revoked.grc.com/, at first I get a dialog about expired certificate. When I click Accept the risk and continue, the site loads. This is somewhat unexpected since the site's certificate is revoked (https://crt.sh/?id=123799530&opt=ocsp), and this shouldn't be possible to override by user. Is this a bug or a feature?

I do believe that this behavior is easy to replicate everywhere, so I'd like to ask anybody who's about to respond with "send us diagnostics data" or "reset your profile", please try the steps yourself first.

When I try to access the website https://revoked.grc.com/, at first I get a dialog about expired certificate. When I click Accept the risk and continue, the site loads. This is somewhat unexpected since the site's certificate is revoked (https://crt.sh/?id=123799530&opt=ocsp), and this shouldn't be possible to override by user. Is this a bug or a feature? I do believe that this behavior is easy to replicate everywhere, so I'd like to ask anybody who's about to respond with "send us diagnostics data" or "reset your profile", please try the steps yourself first.