Den här webbplatsen har begränsad funktionalitet medan vi utför underhåll för att förbättra din upplevelse. Om en artikel inte löser ditt problem och du vill ställa en fråga har vi vår gemenskap som väntar på att hjälpa dig på @FirefoxSupport på Twitter, /r/firefox på Reddit.

Sök i support

Akta dig för supportbedrägerier: Vi kommer aldrig att be dig att ringa eller skicka ett sms till ett telefonnummer eller dela personlig information. Rapportera misstänkt aktivitet med alternativet "Rapportera missbruk".

Läs mer

Valid certifcate, but "ssl_error_bad_cert_domain"

more options

I have a SSL web-server xxx.yyy with a valid certificate that is signed by a CA known to Firefox.

When I access "https://xxx.yyy" everything is fine. When I access "https://xxx.yyy/some_page", I get the "This Connection is Untrusted" dialog, which tells me:

Technical Details xxx.yyy uses an invalid security certificate. The certificate is only valid for @subject_cn@ (Error code: ssl_error_bad_cert_domain)

When I then try to add an exception, after some seconds it tells me: "Valid certificate: This site provides valid, certified identification. There is no need to add an exception".  And the "Confirm Security Exception" button stays greyed out.
Now I am stuck .... :-(

Thanks in advance

I have a SSL web-server xxx.yyy with a valid certificate that is signed by a CA known to Firefox. When I access "https://xxx.yyy" everything is fine. When I access "https://xxx.yyy/some_page", I get the "This Connection is Untrusted" dialog, which tells me: ##### Technical Details xxx.yyy uses an invalid security certificate. The certificate is only valid for @subject_cn@ (Error code: ssl_error_bad_cert_domain) ##### When I then try to add an exception, after some seconds it tells me: "Valid certificate: This site provides valid, certified identification. There is no need to add an exception". And the "Confirm Security Exception" button stays greyed out. Now I am stuck .... :-( Thanks in advance

Alla svar (4)

more options

I am suspecting the "@subject_cn@" wants to tell me something. Why doesn't it show the CN of the certificate (xxx.yyy)?

Just some more info: the SSL server is on a different network, behind a Socks5 proxy (firefox) configured to do DNS lookups. Maybe this is related...

more options

Some more info. The proxy configuration is not the problem. It might be that the certificate has a problem after all.

When inspecting the certificate with openssl, it shows;

> X509v3 Subject Alternative Name: > DNS:@subject_cn@, email:user@zzz.yyy

Is that a syntax recognized by firefox? Is that valid at all?
more options

cookies should be enabled in your browser for CAPTCHA validation. how do I enable this to allow these cookies from this site for registration.