Unable to bypass security exception for 2 days expired cert Topic is solved

Users and developers helping users with generic and technical Pale Moon issues on all operating systems.

Moderator: trava90

Forum rules
This board is for technical/general usage questions and troubleshooting for the Pale Moon browser only.
Technical issues and questions not related to the Pale Moon browser should be posted in other boards!
Please keep off-topic and general discussion out of this board, thank you!
Karina800

Unable to bypass security exception for 2 days expired cert

Unread post by Karina800 » 2017-06-16, 20:42

Hi,
Never seen this before.
Palemoon 27.3.0. 64 Bit won't let me add a security exception for site
https://www.edv-lehrgang.de/fussnoten-endnoten/
with two days expired certificate (see screenshot attached)
Any ideas why and what to do? Can anyone reproduce this?
Thanks and Cheers
k.

Palemoon 27.3.0. 64 Bit, JavaScript active
Windows 7
Site: https://www.edv-lehrgang.de/fussnoten-endnoten/
Add-Ons reproduced it with UBlock and Encrypted web disabled, but installed.
Else no privacy relevant or functionality reducing Add-Ons, but a few addons active, that I use for years (norwell, quickjava, refcontrol)
image800.PNG
You do not have the required permissions to view the files attached to this post.

coffeebreak
Moon Magic practitioner
Moon Magic practitioner
Posts: 2986
Joined: 2015-09-26, 04:51
Location: U.S.

Re: Unable to bypass security exception for 2 days expired cert

Unread post by coffeebreak » 2017-06-17, 01:12

The site uses HTTP Strict Transport Security (HSTS). (See Qualys)

If you change the setting network.stricttransportsecurity.enabled to false, it will offer the opportunity to set an exception.

User avatar
Pallid Planetoid
Knows the dark side
Knows the dark side
Posts: 4279
Joined: 2015-10-06, 16:59
Location: Los Angeles CA USA

Re: Unable to bypass security exception for 2 days expired cert

Unread post by Pallid Planetoid » 2017-06-17, 04:26

coffeebreak wrote:The site uses HTTP Strict Transport Security (HSTS). (See Qualys)

If you change the setting network.stricttransportsecurity.enabled to false, it will offer the opportunity to set an exception.
I tried setting this pref to "false" and I still get the same thing the OP is getting, no opportunity to do anything except "get me out of here".

Maybe this pref needs me to close/open the browser.... I'll try that....
Current Pale Moon(x86) Release | WIN10 | I5 CPU, 1.7 GHz, 6GB RAM, 500GB HD[20GB SSD]
Formerly user Pale Moon Rising - to provide context involving embedded reply threads.
Good judgment comes from experience and a lot of that comes from bad judgment. - Will Rogers
Knowing Pale Moon is indisputably #1 is defined by knowing the totality of browsers. - Pale Moon Rising

User avatar
Pallid Planetoid
Knows the dark side
Knows the dark side
Posts: 4279
Joined: 2015-10-06, 16:59
Location: Los Angeles CA USA

Re: Unable to bypass security exception for 2 days expired cert

Unread post by Pallid Planetoid » 2017-06-17, 04:39

Okay, browser needs to be closed/opened (after changing pref setting) for pref to take effect (as illustrated below in the screen-shot0.
Change in warning after exit - start browser.png
Just in case the OP (who is new to the forum) is not familiar with pref settings, type "about:config" in the browser address bar (without quotes) click "I promise to be careful" button.
Do the following (click on images below to see better):
If you type the pref setting in the search box, you'll get this which has a value of "true" (which is the default setting):
network.stricttransportsecurity.enabled - default true.png
By doing a left-double-click on this setting the value will change (toggle) to "false" as illustrated in the screen-shot below (you can close about:config tab once change has been made):
network.stricttransportsecurity.enabled - set to false.png
As mentioned above, be sure to close/open Pale Moon to see the prompt you see in the first screen-shot.

Thanks coffeebreak :thumbup: (I don't recall that we used to have this option :think:)
You do not have the required permissions to view the files attached to this post.
Current Pale Moon(x86) Release | WIN10 | I5 CPU, 1.7 GHz, 6GB RAM, 500GB HD[20GB SSD]
Formerly user Pale Moon Rising - to provide context involving embedded reply threads.
Good judgment comes from experience and a lot of that comes from bad judgment. - Will Rogers
Knowing Pale Moon is indisputably #1 is defined by knowing the totality of browsers. - Pale Moon Rising

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35647
Joined: 2011-08-28, 17:27
Location: Motala, SE

Re: Unable to bypass security exception for 2 days expired cert

Unread post by Moonchild » 2017-06-17, 13:02

What really needs to happen is the people need to renew their certificate.
Enforcing strict https with HSTS implies that you MUST, at all times, have your server security in order.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite