IPSCA SSL certificates not accepted in Mozilla (duplicate of bug 529286)
The bug report states that new IPSCA SSL certificates were not being accepted by Mozilla, while IE8 accepted them. The reporter compared access to https://collab.ctrip.ufl.edu in Mozilla versus IE8 and reported that IE8 loaded the page while Mozilla did not trust the certificate. During discussion, a participant from StartCom indicated the issue was related to DNS resolution rather than the certificate itself, noting SERVFAIL/timeouts when reaching the server. The reporter acknowledged the DNS issue and said they were following another thread related to IPSCA certs and believed the current thread could be closed. Another participant later stated that the problem appeared to be that new certificates were issued from a root not present in Mozilla, most likely the root from bug 529286, and suggested marking this bug as resolved. The bug was ultimately marked as a duplicate of bug 529286.
- A third party reported that IPSCA-issued SSL certificates were not trusted by Mozilla while IE8 accepted them.
- Participants discussed whether the issue was due to DNS or a missing Mozilla-trusted root and identified a likely link to bug 529286.
- The bug was marked as a duplicate of bug 529286.
- Ichp representative — Reported that new IPSCA SSL certificates were not accepted in Mozilla for https://collab.ctrip.ufl.edu, while IE8 accepted them, and asked whether an update was planned.
- Mit representative — Moved the issue to a more accurate component.
- Startcom representative — Said the issue was not the certificate and indicated Mozilla could not find/reach the server (DNS/SERVFAIL/timeouts).
- Ichp representative — Suggested it might be a DNS issue and confirmed the site is SSL-only.
- Startcom representative — Confirmed it was a DNS issue and referenced an IP lookup URL.
- Ichp representative — Acknowledged the DNS issue and said they thought the thread could be closed.
- Rossde representative — Asked whether this was a duplicate of bug 529286.
- Startcom representative — Agreed it was related and stated new certificates were issued from a root not in Mozilla, likely from bug 529286, and that the bug could be marked resolved.
- Mozilla representative — Marked the bug as a duplicate of bug 529286.