Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Paul1977

5171 posts

Uber Geek
+1 received by user: 2192


#214116 28-Apr-2017 12:17
Send private message

I have various devices that I connect to over the LAN using https which have self-signed certificates (routers, printers, etc). Since they are only being accessed over the LAN I am perfectly happy with self-signed.

 

To avoid security warnings, and to allow Chrome to save the login details, I import the self-signed certificates as Trusted Root Authorities on my PC.

 

However, Chromes latest update to version 58 has broken this.

 

Everything I am reading says it is because of the certificates not having a SAN, however Chrome is reporting two problems with the certificate. One says "Subject Alternative Name Missing" but the other says "ERR_CERT_AUTHORITY_INVALID".

 

What little I can find about this change says that replacing the certs with new self-signed ones that have a SAN will sort both problems, however when I do this it only resolves the first error. I still get the second error "ERR_CERT_AUTHORITY_INVALID" and the cert is still not trusted by Chrome. I have imported the new cert as a Trusted Root Authority.

 

Does anyone now how I can get Chrome to trust a self-signed certificate on version 58?





 Home:                                                           Work:
Home Work


Create new topic
Paul1977

5171 posts

Uber Geek
+1 received by user: 2192


  #1771956 28-Apr-2017 15:22
Send private message

Figured it out.

 

Chrome now not only insists on a certificate having a SAN, but the CN now has to be a FQDN. So hostname or IP address is no good.


Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.