搜尋 Mozilla 技術支援網站

防止技術支援詐騙。我們絕對不會要求您撥打電話或發送簡訊,或是提供個人資訊。請用「回報濫用」功能回報可疑的行為。

Learn More

thawte Extended Validation SSL CA / Certficate viewer using 2 different fonts

more options

I received an error going to https://www.secunia.com stating that the site could not be trusted as the issuer of the certificate (in this case thawte Extended Validation SSL CA) was unknown. I went to GRC.com and ran the https fingerprint tool to evaluate if the site certificate was ok and when I compared fingerprints I noticed that two different fonts were being used in the SHA-1 and SHA-256 fingerprints.

I want to say that this laptop has malware infections that I am trying to clean. I have removed some but am confident that more remain. I was going to that website to download a tool that assists in keeping all application current with all publisher updates.

I received an error going to https://www.secunia.com stating that the site could not be trusted as the issuer of the certificate (in this case thawte Extended Validation SSL CA) was unknown. I went to GRC.com and ran the https fingerprint tool to evaluate if the site certificate was ok and when I compared fingerprints I noticed that two different fonts were being used in the SHA-1 and SHA-256 fingerprints. I want to say that this laptop has malware infections that I am trying to clean. I have removed some but am confident that more remain. I was going to that website to download a tool that assists in keeping all application current with all publisher updates.
附加的畫面擷圖

由 JustinAlt 於 修改

所有回覆 (4)

more options

What do you see in the Details pane?

Try to rename the cert8.db file (cert8.db.old) and delete the cert_override.txt file in the Firefox profile folder to remove intermediate certificates and exceptions that Firefox has stored.

If that has helped to solve the problem then you can remove the renamed cert8.db.old file. Otherwise you can rename (or copy) the cert8.db.old file to cert8.db to restore the previously stored intermediate certificates. Firefox will automatically store intermediate certificates when you visit websites that send such a certificate.

You can use this button to go to the current Firefox profile folder:

more options

Hmm, I don't get an error for that URL, just a download dialog. There is a gray ! warning triangle when I visit the site, perhaps because of the SHA-1 or mixed content, but that isn't a block like the one you're seeing. Odd...

more options

The details pane as requested. I will do the other steps when i get back home. What do you make of the different fonts used for the SHA-1 and the SHA-256 fingerprint?

more options

Firefox expects servers to sent "intermediate" certificate between the server's own certificate and the "root" certificates distributed with browsers and operating systems. Secunia's webmaster goofed on that. This was confirmed by https://www.ssllabs.com/ssltest/analyze.html?d=secunia.com (intermediate certificate requires an extra download, which Firefox does not do).

But I'm not sure what the best workaround is. Finding a server that sends that particular intermediate certificate may be difficult, as the issuer's home site now uses a more updated one and otherwise it's pure guesswork. You could try importing it from the Windows certificate store, but if you aren't planning on using this site frequently, you might just want to download the EXE file using another browser.