Project

General

Profile

Actions

Task #10816

closed

TLS Error on services.d4science.org when accessed by Firefox

Added by Fabio Sinibaldi over 7 years ago. Updated over 7 years ago.

Status:
Closed
Priority:
Immediate
Assignee:
_InfraScience Systems Engineer
Category:
System Application
Target version:
Start date:
Jan 02, 2018
Due date:
% Done:

100%

Estimated time:
Infrastructure:
Production

Description

Portals hosted in services.d4science.org cannot be accessed with Firefox Browser. Reported error message is :

"An error occurred during a connection to services.d4science.org. A required TLS feature is missing. Error code: MOZILLA_PKIX_ERROR_REQUIRED_TLS_FEATURE_MISSING"


Related issues

Related to D4Science Infrastructure - Incident #10823: social.isti.cnr.it TLS error with latest Firefox versionClosed_InfraScience Systems EngineerJan 04, 2018Jan 08, 2018

Actions
Has duplicate D4Science Infrastructure - Support #10817: Infrastructure gateways TLS error with FirefoxClosed_InfraScience Systems EngineerJan 02, 2018

Actions
Actions #1

Updated by Andrea Dell'Amico over 7 years ago

  • Status changed from New to In Progress
  • % Done changed from 0 to 20

I'm investigating the issue. I do not have a clue yet, the same exact configuration is working on the dev and preproduction instances.

As a temporary workaround, the 'ocsp must staple' check can be disabled on Firefox:

  • Write about:config in the URL bar

  • search for security.ssl.enable_ocsp_must_staple and set its value to false

Actions #2

Updated by Luca Frosini over 7 years ago

  • Is duplicate of Support #10817: Infrastructure gateways TLS error with Firefox added
Actions #3

Updated by Andrea Dell'Amico over 7 years ago

  • Is duplicate of deleted (Support #10817: Infrastructure gateways TLS error with Firefox)
Actions #4

Updated by Luca Frosini over 7 years ago

  • Status changed from In Progress to Closed
Actions #5

Updated by Andrea Dell'Amico over 7 years ago

  • Has duplicate Support #10817: Infrastructure gateways TLS error with Firefox added
Actions #6

Updated by Luca Frosini over 7 years ago

  • Status changed from Closed to In Progress
Actions #7

Updated by Andrea Dell'Amico over 7 years ago

  • Status changed from In Progress to Feedback
  • % Done changed from 20 to 100

It seems a openssl bug. Why it started showing now I've yet to understand. I worked around it for the time being and at the next renewal the certificates on the haproxy nodes will have the must staple flag disabled.

Actions #8

Updated by Andrea Dell'Amico over 7 years ago

  • Related to Incident #10823: social.isti.cnr.it TLS error with latest Firefox version added
Actions #9

Updated by Andrea Dell'Amico over 7 years ago

  • Status changed from Feedback to Closed
Actions

Also available in: Atom PDF

Add picture from clipboard (Maximum size: 8.91 MB)