Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

www.psegliny.com - see bug description #19195

Closed
webcompat-bot opened this issue Sep 27, 2018 · 5 comments
Closed

www.psegliny.com - see bug description #19195

webcompat-bot opened this issue Sep 27, 2018 · 5 comments
Labels
browser-firefox type-symantec-distrust Issues caused by Symantec certificate distrust
Milestone

Comments

@webcompat-bot
Copy link

URL: https://www.psegliny.com/

Browser / Version: Firefox 64.0
Operating System: Mac OS X 10.13
Tested Another Browser: Unknown

Problem type: Something else
Description: I cannot login to the website
Steps to Reproduce:
Visit website, try to login.

Browser Configuration
  • mixed active content blocked: false
  • buildID: 20180927100044
  • tracking content blocked: false
  • hasTouchScreen: false
  • gfx.webrender.blob-images: true
  • gfx.webrender.all: false
  • mixed passive content blocked: false
  • gfx.webrender.enabled: false
  • image.mem.shared: true
  • channel: nightly

From webcompat.com with ❤️

@jasonthomas
Copy link

Please reach out to me if you need more details.

@jasonthomas
Copy link

Tested Another Browser: Yes, works on other browsers

@adamopenweb
Copy link
Collaborator

HI @jasonthomas thanks for the report. Since I can't log into the website, can you provide more details about what happens when you try to login? Are you using add-ons or tracking protection?

It helps to eliminate your Firefox profile as being part of the issue. You may want to try running Firefox in Safe Mode.

If that doesn't work, you can also try to refresh Firefox, but you will lose your current add-ons doing this.

@jasonthomas
Copy link

I've created a new profile and disabled tracking protection on this website:

In debug console when I try to login:

TypeError: n.terminate is not a function[Learn More] raptor.min.js:1:1102
FetchModule/</<
https://www.psegliny.com/scripts/GlobalScripts/vendor/raptor.min.js:1:1102
dispatch
https://www.psegliny.com/scripts/GlobalScripts/vendor/jquery-3.2.1.min.js:14:50993
add/a.handle
https://www.psegliny.com/scripts/GlobalScripts/vendor/jquery-3.2.1.min.js:14:49047
Content Security Policy: Ignoring ‘x-frame-options’ because of ‘frame-ancestors’ directive.
Content Security Policy: Ignoring ‘x-frame-options’ because of ‘frame-ancestors’ directive.
Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at https://idcs-9b3bc95c7c274882bcf64ca723f0acbb.identity.oraclecloud.com/sso/v1/sdk/authenticate?appName=MyAccDashboard. (Reason: CORS request did not succeed).[Learn More]
SyntaxError: JSON.parse: unexpected end of data at line 1 column 1 of the JSON data[Learn More] module-LI-login.js:79:50
startAuthn/<
https://www.psegliny.com/scripts/GlobalScripts/component/module-LI-login.js:79:50

On further investigation it looks like https://idcs-9b3bc95c7c274882bcf64ca723f0acbb.identity.oraclecloud.com requests are not succeeding due to certificate blocking - Error code: MOZILLA_PKIX_ERROR_ADDITIONAL_POLICY_CONSTRAINT_FAILED

After 'Accepting & continuing risk' it works now.

@adamopenweb
Copy link
Collaborator

This is really helpful @jasonthomas, thanks!

Navigating to https://idcs-9b3bc95c7c274882bcf64ca723f0acbb.identity.oraclecloud.com/ we see:

...
Websites prove their identity via certificates, which are issued by certificate authorities. Most 
browsers will no longer trust Symantec, the certificate authority for
 idcs-9b3bc95c7c274882bcf64ca723f0acbb.identity.oraclecloud.com.
...

So yeah this is the Symantec distrust issue.

If you navigate to about:config security.pki.distrust_ca_policy is set to 2, changing this to 1 no longer displays this error. But you will no longer be warned about sites that are using Symantec certificates and are distrusted by Mozilla and Google.

Since we will not be reversing this policy I'm going to close this report as duplicate. The site will need to update their certificates.

Referencing this issue in:
https://bugzilla.mozilla.org/show_bug.cgi?id=1484006

@denschub denschub added type-symantec-distrust Issues caused by Symantec certificate distrust browser-firefox and removed nsfw os-android Issues only happening on Android. os-ios Issues only happening on iOS. os-linux Issues only happening on Linux. os-mac Issues only happening on macOS. os-win Issues only happening on Windows. priority-important q4-2019-outreach Tracking outreach in Q42019. sci-exclude Bugs to exclude from out Top Site Compat Index metrics severity-critical The site or core functionality is unusable, or you would probably open another browser to use it. severity-important A non-core broken piece of functionality, not behaving the way you would expect. severity-minor The site has a cosmetic issue. sitepatch-applied There is an UA override/intervention in place for this site status-contact-success status-diagnosis-finished status-diagnosis-started status-login-needed Issues where we cannot progress without a login status-multiple-contacts status-needsinfo status-needsinfo-adamopenweb ping @adamopenweb status-needsinfo-cipriansv status-needsinfo-denschub ping @denschub status-needsinfo-foolip ping @foolip status-needsinfo-karlcow ping @karlcow status-needsinfo-miketaylr ping @miketaylr status-needsinfo-rwlbuis status-needsinfo-wisniewskit ping @wisniewskit labels Dec 20, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
browser-firefox type-symantec-distrust Issues caused by Symantec certificate distrust
Projects
None yet
Development

No branches or pull requests

4 participants