We're calling on all EU-based Mozillians with iOS or iPadOS devices to help us monitor Apple’s new browser choice screens. Join the effort to hold Big Tech to account!

搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

详细了解

Was "VeriSign Class 3 International Server CA - G3" certificate authority removed from FF 3.6.12?

  • 3 个回答
  • 268 人有此问题
  • 2 次查看
  • 最后回复者为 cor-el

more options

We have a site that has a SSL certificate with this authority and now we are seeing "Untrusted connection". This was working fine with older versions of FireFox.

We have a site that has a SSL certificate with this authority and now we are seeing "Untrusted connection". This was working fine with older versions of FireFox.

所有回复 (3)

more options

That is an intermediate certificate that a server needs to send. Firefox will store such a certificate in the Certificate Manager as Software Security Device and store it in cert8.db for future use. So if cert8.db was deleted or you use a new profile then you won't have that certificate unless the server sends it.

See https://knowledge.verisign.com/support/ssl-certificates-support/index?page=content&id=AR1130

more options

Hi cor-el, for some reason firefox does not seem to retrieve this intermediate certificate from the webserver, EVEN when the issuer of the intermediate certificate is in the trusted root store of firefox. I had to add an exception manually. I checked this with IE and Opera and both retrieve the correct intermediate g3 certificate when it is not installed on the client. Why does firefox not use the operating system certificate store anyway? This is causing heaps of problems since our website is using the new verisign G5 root and G3 intermediate certificates. We are getting complaints from customers using firefox claiming our website is not safe.

more options

It is the responsibility of websites to send all required intermediate certificates. If websites do not send them and Firefox hasn't stored them from a past visit to other websites that send them then you get then not trusted error message. Firefox is a multi platform application and every platform would require a different approach for each supported feature. That would require a lot of extra code that the devs want to avoid, even if APIs for such an enhancement (don't know about this one).

You can also check certificates via other test sites.