#932 Firefox refuses connection to almost all Fedora sites.
Closed: Invalid 5 years ago by ryanlerch. Opened 5 years ago by sujiniku.

If I will to see Fedora's site in Firefox, Firefox show that there is a problem with the security and certificate ,and Firefox refused the connection .

Not only Pagure but also the site of GetFedora etc, refused to connect almost everything.

It is displayed as follows.
"
Your connection is not secure

The owner of pagure.io has configured their website improperly. To protect your information from being stolen, Firefox has not connected to this website.

This site uses HTTP Strict Transport Security (HSTS) to specify that Firefox may only connect to it securely. As a result, it is not possible to add an exception for this certificate.

Learn more…

Report errors like this to help Mozilla identify and block malicious sites

pagure.io uses an invalid security certificate.

The certificate is not trusted because the issuer certificate is unknown.
The server might not be sending the appropriate intermediate certificates.
An additional root certificate may need to be imported.

Error code: SEC_ERROR_UNKNOWN_ISSUER
"


It's working fine for me with Firefox 64.0.2 on Fedora 29.

Which version of Firefox and what operating system are you using?

I'm also using the same version of Fedora.
That is, My PC's Firefox version is "Firefox Quantum" 64.0.2 (64 bit) , on Fedora 29.

And The repository "updates-testing" is enabled in my Fedora 29.
I'm accessing from Japan.

I thought about uploading to rawhide a couple of days ago,
https://fedoraproject.org/wiki/Upgrading_Fedora_using_package_manager#To_Rawhide

but since I manipulated it halfway and canceled it,
Perhaps it may have rewritten my PC's certificate settings.

Hi,

It depends on what part of the process you cancelled the procedure.
Could you open a terminal, and run "file /etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt" and paste the output?

You might have some luck by running update-ca-trust, although if your system was left without a working certificate trust list, you might have to either retry the distro-sync, distro-sync back to what you have, or worst case reinstall.

and paste the output?

/etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt: UTF-8 Unicode text

Such as "# Amazon Root CA 1" etc are exist at the file "/etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt:" .

This one doesnt appear to be an issue with fedora-websites specificially, so closing.

Thanks!

Metadata Update from @ryanlerch:
- Issue close_status updated to: Invalid
- Issue status updated to: Closed (was: Open)

5 years ago

Login to comment on this ticket.

Metadata