NET :: ERR_CERT_REVOKED in Chrome when the certificate is not actually revoked

I'm looking for some help trying to satisfy my curiosity by figuring out why Chrome46.0.2490.80 won't let me access https://www.evernote.com while Firefox is working fine. Chrome worked fine, up to 2 days ago, but now it throws a NET :: ERR_CERT_REVOKED error.

So, I was curious - is the certificate really revoked? Ok check ...

I opened the certificate dialog box and exported the certificate (evernote.pem) as well as the issuer chain (evernote-chain.pem): enter image description here

enter image description here

Take the OCSP Responder URI from the certificate:

$ openssl x509 -noout -ocsp_uri -in evernote.pem
http://ss.symcd.com 

Now check the status of the certificate:

$ openssl ocsp -no_nonce -issuer evernote-chain.pem -CAfile evernote-chain.pem -cert evernote.pem -url http://ss.symcd.com
Response verify OK
evernote.pem: good
        This Update: Dec 16 09:14:05 2015 GMT
        Next Update: Dec 23 09:14:05 2015 GMT

, , Firefox . , Chrome? , ?

, - . Chrome , Firefox, openssl. Chrome :

|- Class 3 Public Primary Certification Authority (Builtin Object Token, self-signed)
|---- VeriSign Class 3 Public Primary Certification Authority - G5 (35:97:31:87:F3:87:3A:07:32:7E:CE:58:0C:9B:7E:DA)
|------- Symantec Class 3 Secure Server CA - G4
|---------- www.evernote.com

Firefox openssl :

|- VeriSign Class 3 Public Primary Certification Authority - G5 (18:DA:D1:9E:26:7D:E8:BB:4A:21:58:CD:CC:6B:3B:4A, self-signed)
|---- Symantec Class 3 Secure Server CA - G4
|------- www.evernote.com

, . , VeriSign Class 3 Public Primary CA Chrome, , , -, , , " " Chrome... ? - , ?

UPDATE:

. , , - b/c. Google "Class 3 Public Primary CA", : https://googleonlinesecurity.blogspot.ca/2015/12/proactive-measures-in-digital.html

: https://code.google.com/p/chromium/issues/detail?id=570892

, , CRLSet chrome://components/

:

Chrome ?

Firefox, openssl https://www.digicert.com/help/, :

VeriSign Class 3 Public Primary Certification Authority - G5
18:DA:D1:9E:26:7D:E8:BB:4A:21:58:CD:CC:6B:3B:4A

Symantec Class 3 Secure Server CA - G4
51:3F:B9:74:38:70:B7:34:40:41:8D:30:93:06:99:FF

www.evernote.com
18:A9:E9:D2:F7:F4:D9:A1:40:23:36:D0:F0:6F:DC:91

Chrome :

Class 3 Public Primary Certification Authority
70:BA:E4:1D:10:D9:29:34:B6:38:CA:7B:03:CC:BA:BF
- This is the no longer trusted Root CA

VeriSign Class 3 Public Primary Certification Authority - G5
35:97:31:87:F3:87:3A:07:32:7E:CE:58:0C:9B:7E:DA   <- WTF?!

Symantec Class 3 Secure Server CA - G4
51:3F:B9:74:38:70:B7:34:40:41:8D:30:93:06:99:FF

www.evernote.com
18:A9:E9:D2:F7:F4:D9:A1:40:23:36:D0:F0:6F:DC:91

, , , "" "VeriSign Class 3 Public Primary Certification Authority - G5" . CN " " "" , CA, Chrome. Chrome Firefox. ( Symantec), (), - ().

, /-, Chrome? , Ubuntu? , , www.evernote.com TLS, (, : https://security.stackexchange.com/questions/37409/certificate-chain-checking).

Chrome?

+4
2

, , :

https://code.google.com/p/chromium/issues/detail?id=570892

https://googleonlinesecurity.blogspot.ca/2015/12/proactive-measures-in-digital.html

Google Symantec Google, , ( ). Chromium:

-, , , . , chrome://components CRLSet, "". 2698 , .

+4

, , Chrome , .

:

www.evernote.com
18:A9:E9:D2:F7:F4:D9:A1:40:23:36:D0:F0:6F:DC:91

Symantec Class 3 Secure Server CA - G4
51:3F:B9:74:38:70:B7:34:40:41:8D:30:93:06:99:FF

VeriSign Class 3 Public Primary Certification Authority - G5
25:0c:e8:e0:30:61:2e:9f:2b:89:f7:05:4d:7c:f8:fd

, , , , , ,

, , SSL, , . , openssl 1.0.1 Ubuntu 14.04 , Chrome, , CA "Class 3 Public Primary Certification Authority". OpenSSL 1.0.2 , , "VeriSign Class 3 Public Primary Certification Authority - G5", , ( , ).

Chrome Symantec, , , . , , Chrome , .

+2

Source: https://habr.com/ru/post/1620821/


All Articles