Skip to content

[Security][SSL] Self signed certificate seems to be always accepted. #3283

Closed
@jklmnn

Description

Expected behaviour

When a self signed certificate is used and the warning is shown, clicking Cancel should not build up a connection.

Actual behaviour

When the warning is shown, a connection is build up, even if you have clicked Cancel.

Steps to reproduce

  1. Run ownCloud desktop client.
  2. Intercept traffic and set up mitm attack.
  3. Wait for certificate warning and click Cancel.
  4. See traffic in mitm.

Server configuration

Operating system: Debian 8.0

Web server: Apache 2.4

Database: Sqlite 3.8

PHP version: 5.6

ownCloud version: 8.0.3

Storage backend: SQLite

Client configuration

Client version: 1.8.1+dfsg-1

Operating system: Debian Stretch

OS language: German

Installation path of client: /usr/bin/owncloud

Metadata

Assignees

No one assigned

    Labels

    Securityp2-highEscalation, on top of current planning, release blocker

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions