mozilla / vinz-clortho

INACTIVE - http://mzl.la/ghe-archive - BrowserID Keymaster for LDAP enabled Identity Providers
16 stars 21 forks source link

[android stock 2.2] login.{mozilla,allizom}.org lacks equifax cross-root certificate #110

Closed jrgm closed 2 years ago

jrgm commented 11 years ago

@mostlygeek: Ask @gene1wood - we need this to not have ssl certificate issues on, ugh, the lamer-than-ie8 stock browser on android 2.2

gene1wood commented 11 years ago

Here's the cross root cert to add to the chain : https://knowledge.geotrust.com/support/knowledge-base/index?page=content&id=AR1426&actp=search&viewlocale=en_US&searchid=1283360269668

vladikoff commented 11 years ago

Related issue https://github.com/mozilla/browserid/issues/3633

gene1wood commented 11 years ago

@vladikoff I don't think that issue relates to this one. I believe this issue is a straight forward cross root certificate issue which we know how to solve. The issue you referenced is not related to cross root issues and is something else that we haven't yet identified.

vladikoff commented 11 years ago

@gene1wood ohhh, so many 2.2 issues :\

mostlygeek commented 11 years ago

thanks @gene1wood. I added the cert to the chain. Redeploying the staging server so @jrgm can test it again.

mostlygeek commented 11 years ago

@jrgm the staging server (https://login.allizom.org) has been updated with the cross root cert added to the chain. Could you please check with Android 2.2 again to see if that resolves the issue?

jrgm commented 11 years ago

@mostlygeek On login.allizom.org, I see the equifax cross-root in the chain, and this android stock 2.2 browser no longer shows a warning.

I don't see the same things for login.mozilla.org, and you're probably going to change it there (after I confirm here). So, yeah, do that.

mostlygeek commented 11 years ago

@jrgm great. We're hoping to do a push for Moz-IdP sometime this week when the QA is finished. That should resolve this issue for login.mozilla.org then.

shane-tomlinson commented 11 years ago

@jrgm - "lamer-than-ie8 stock browser on Android 2.2" has just made my day.