Opened 6 years ago

Last modified 10 months ago

#2482 assigned defect

TLS issues with Torbutton

Reported by: mikeperry Owned by: tbb-team
Priority: Very High Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-torbutton
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description (last modified by mikeperry)

Torbutton is starting to accumulate a bunch of TLS-related issues and things we need to look into. This will serve as the parent ticket for all of those issues.

Child tickets:

#664
Torbutton should not present custom certs if tor is enabled
#975
Torbutton prevents PKCS#12 import/export
#1624
Use nsICrypto::logout() to clear SSL Session IDs instead of SSLv2 pref hack
#2777
Clear OCSP cache during toggle


Child Tickets

TicketSummaryOwner
#664Torbutton should not present custom certs if tor is enabledtbb-team
#975Torbutton prevents PKCS#12 import/exporttbb-team
#1624Use nsICrypto::logout() to clear SSL Session IDs instead of SSLv2 pref hackmikeperry
#2777Clear OCSP cache during togglemikeperry

Change History (5)

comment:1 Changed 6 years ago by mikeperry

  • Description modified (diff)

comment:2 Changed 6 years ago by Torrifictill1000

  • Keywords Torbutton 1.4.0 OCSP Error added
  • Version set to Torbutton: 1.4

_With Torbutton 1.4.0 toggled On_ (toggled Off = No Error Message)

Connection to e.g. https://check.torproject.org/ (all *.torproject.org URLs affected):


Secure Connection Failed


An error occurred during a connection to check.torproject.org.

Invalid OCSP signing certificate in OCSP response.

(Error code: sec_error_ocsp_invalid_signing_cert)


comment:3 Changed 5 years ago by mikeperry

  • Owner mikeperry deleted
  • Status changed from new to assigned

comment:4 Changed 17 months ago by bugzilla

  • Component changed from Torbutton to Tor Browser
  • Keywords tbb-torbutton added; Torbutton 1.4.0 OCSP Error removed
  • Severity set to Normal

comment:5 Changed 10 months ago by bugzilla

  • Owner set to tbb-team
  • Version Torbutton: 1.4.0 deleted

Cross-reference: #2877.

Note: See TracTickets for help on using tickets.