Join the Mozilla’s Test Days event from 9–15 Jan to test the new Firefox address bar on Firefox Beta 135 and get a chance to win Mozilla swag vouchers! 🎁

This site will have limited functionality while we undergo maintenance to improve your experience. If an article doesn't solve your issue and you want to ask a question, we have our support community waiting to help you at @FirefoxSupport on Twitter and/r/firefox on Reddit.

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

sec_error_unknown_issuer on sites without intermediate certs

  • 3 odgovori
  • 1 ima ovaj problem
  • 2 views
  • Posljednji odgovor poslao philipp

more options

Why in this day and age is this still an issue with Firefox alone. Sites that do not have the intermediate cert installed, cause an error in Firefox (sec_error_unknown_issuer). I understand the technical reason why this happens, but my question is why doesn't the Firefox foundation do something about it? The sites are not inherently insecure and to the user you are making it look like it is.

All of the sites correctly work in every other modern day browser: IE11, Safari 8, Chrome (43) except Firefox. Why would all of those other browser make the decision to allow it, but not Firefox?

Why in this day and age is this still an issue with Firefox alone. Sites that do not have the intermediate cert installed, cause an error in Firefox (sec_error_unknown_issuer). I understand the technical reason why this happens, but my question is why doesn't the Firefox foundation do something about it? The sites are not inherently insecure and to the user you are making it look like it is. All of the sites correctly work in every other modern day browser: IE11, Safari 8, Chrome (43) except Firefox. Why would all of those other browser make the decision to allow it, but not Firefox?

All Replies (3)

more options

hello, it is necessary to have a full link from a server certificate to the certificate authorities in the browser's root trust store - otherwise the whole cert system won't work. what solutions would you propose?

more options

Why cannot it be solved in the same manner as: IE11, Safari 8, Chrome (43) ?

more options

the reason why mozilla isn't going this approach is explained in https://bugzilla.mozilla.org/show_bug.cgi?id=399324