Quantcast
Channel: Symantec Connect - Products
Viewing all articles
Browse latest Browse all 21587

SHA1 certificate shown as insecure or with mix content warning on Google Chrome 39

$
0
0

As of late 2014, SHA1 certificates and it's SHA1 trust chain (not including the Root CA) will be considered insecure by Google Chrome.

A three step process will increase the severity of the warning:

  1. Initially SHA1 certificates that expire on/after 2017/1/1, and which contain SHA-1-based signatures in the validated chain, will be shown the "Secure, but minor errors" icon.  This is a lock with a yellow trianglealert icon
     
  2. Severity will increase thereafter, where:  
    SHA1 certificates that expire between 2016/6/1 and 2016/12/31, inclusively, and which contain SHA-1-based signatures in the validated chain, will be shown the "Secure, but minor errors" icon. This is a lock with a yellow triangle. alert icon

    SHA1 certificates that expire on/after 2017/1/1, and which contain SHA-1-based signatures in the validated chain, will be shown the "Neutral, no security" icon. This is the blank page icon, as shown by HTTP URLs.Blank page icon
     

  3. Finally Chrome will render websites with SHA1 certificates that expire on/after 2017/1/1 and which contain SHA-1-based signatures in the validated chain, with the "Affirmatively insecure, major errors" icon. The "Affirmatively insecure, major errors"icon is a lock with a red X. red https
     

To resolve this issue SHA2 certificates must be installed.

 


Viewing all articles
Browse latest Browse all 21587

Trending Articles