Accept invalid CA certificate or not?

Do you like random polls?

  • Yes, lemme see the responses!

    Votes: 1 100.0%
  • No, not wasting my time (except for this one).

    Votes: 0 0.0%

  • Total voters
    1

Cain

Level 4
Thread author
Verified
Dec 19, 2013
171
I'm lost on this one guys and need some input. I've done a clean build with Win8.1 and when trying to access any google domain pages I get the message "This Connection is Untrusted" from firefox. This is the certificate (note the window title o_O )..
rndDWC3.png

I'm not sure why this is the case and what to do about it.

When trying to get to google in Firefox:
"www.google.com.au uses an invalid security certificate." - block page comes up.
The certificate is not trusted because it was issued by an invalid CA certificate.
(Error code: sec_error_inadequate_key_usage)

When trying to get to google in IE:
€d€· €
€ €Œ €
(Each URL I try produces a different string similar to above, placed in the top left on a blank page)

...now, I've checked that it's not malware related, see here
but now I don't know what to do about it. Do I accept and install it, forget about it and move on (not ideal), or is there any better advice?

Help me please MT!
 
I

illumination

I'm lost on this one guys and need some input. I've done a clean build with Win8.1 and when trying to access any google domain pages I get the message "This Connection is Untrusted" from firefox. This is the certificate (note the window title o_O )..
rndDWC3.png

I'm not sure why this is the case and what to do about it.

When trying to get to google in Firefox:
"www.google.com.au uses an invalid security certificate." - block page comes up.
The certificate is not trusted because it was issued by an invalid CA certificate.
(Error code: sec_error_inadequate_key_usage)


When trying to get to google in IE:
€d€· €
€ €Œ €
(Each URL I try produces a different string similar to above, placed in the top left on a blank page)

...now, I've checked that it's not malware related, see here
but now I don't know what to do about it. Do I accept and install it, forget about it and move on (not ideal), or is there any better advice?

Help me please MT!


That is an old cert for sure, here is the latest..

google_zpsaace5dfb.jpg
 
I

illumination

...so what's the solution?

From what i just read, deleting the cert file and its key3 encryption file will give you a set of clean Authority Certs on restart of Firefox.

Source: http://forums-test.mozillazine.org/...sid=95d2d43f85d8b6cec277359112098fd4&start=30

Posted April 13th, 2014, 4:25 pm

See this before you start messing with it > https://support.mozilla.org/en-US/kb/ad ... icates-tab

In general deleting the related cert file and its key3 encryption file will give you a clean, current set of Authority certs on restart of Firefox. The mozilla entry will be gone along with any other user added entries


https://support.mozilla.org/en-US/kb/advanced-settings-browsing-network-updates-encryption?redirectlocale=en-US&as=u&redirectslug=Options window - Advanced panel&utm_source=inproduct#w_certificates-tab
 

Cain

Level 4
Thread author
Verified
Dec 19, 2013
171

Thanks, I'll start reading. But does this certificate look the way it should? Like the 'Issued by', when google is their own CA in the first place.
 
I

illumination

Thanks, I'll start reading. But does this certificate look the way it should? Like the 'Issued by', when google is their own CA in the first place.
No, something is wrong, whether a corruption upon install, or something else..
 

Cain

Level 4
Thread author
Verified
Dec 19, 2013
171
No, something is wrong, whether a corruption upon install, or something else..

ahhh, ok :rolleyes: ..thats a logical explanation. I'll reset IE settings to test this and see if it fixes that side, then try Firefox.
 
I

illumination

ahhh, ok :rolleyes: ..thats a logical explanation.
LOL, i would be more descriptive, but im working with, it is a clean install, and a screen shot of a obviously not right cert.. ;)

I'll reset IE settings to test this and see if it fixes that side, then try Firefox.

Sounds like a good place to start, if it is not effecting the other browsers, chances are it was a corrupted install with Firefox.
 

Cain

Level 4
Thread author
Verified
Dec 19, 2013
171
OKAY! crisis over, lol :)

I found the problem (partially) Kaspersky is somehow responsible for this one. I disabled Kaspersky services, reset IE to default and rebooted, now it's all working fine o_O
This really does not give me much confidence in Kaspersky, especially after just switching from Comodo IS to KIS Pure 3.0 as a test drive on my new build. I thought I'd use the 30 day trial before using the license I purchased, what a dull move. I should have tested before buying the license :D
So now, I will try to work out where KIS went wrong and moooove on!

@ illumination and Littlebits, Thanks for the feedback guys :)
 

Littlebits

Retired Staff
May 3, 2011
3,893
OKAY! crisis over, lol :)

I found the problem (partially) Kaspersky is somehow responsible for this one. I disabled Kaspersky services, reset IE to default and rebooted, now it's all working fine o_O
This really does not give me much confidence in Kaspersky, especially after just switching from Comodo IS to KIS Pure 3.0 as a test drive on my new build. I thought I'd use the 30 day trial before using the license I purchased, what a dull move. I should have tested before buying the license :D
So now, I will try to work out where KIS went wrong and moooove on!

@ illumination and Littlebits, Thanks for the feedback guys :)

I'm glad you solved the problem, third-party security products on Windows 8 cause all kinds of problems but this is the first time that heard about one blocking certificates. It had to be a network filter driver on KIS. That why I don't recommend using third-party firewalls on Windows 8.

Enjoy!! :D
 
  • Like
Reactions: illumination

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top