Firefox3: Difference between revisions

From BRF-Software
Jump to navigation Jump to search
m (9 revisions)
 
Line 1: Line 1:
__NOTOC__
__NOTOC__
= Firefox 3 and Certificates =
= Webbrowsers and certificate errors =


  Read this if you are experiencing trouble accessing our software pages with Firefox 3
  Read this if you are experiencing trouble accessing our software pages with your webbrowser


== Problem Description ==
== Problem Description ==


Users of the recently released Mozilla Firefox version 3 can experience problems when trying to access web-sites using secure connections and certificates such as our software pages (e.g. GenDB, EMMA). When accessing the secure page for the first time, Firefox 3 could show an alert message "www.cebitec.uni-bielefeld.de:443 uses an invalid security certificate".  
In some cases you may experience problems when trying to access web-sites using secure connections and certificates such as our software pages (e.g. GenDB, EMMA). When accessing the secure page for the first time, some webbrowsers such as the Mozilla Firefox up to version 5.0 may show an alert message "www.cebitec.uni-bielefeld.de:443 uses an invalid security certificate".  


The reason for this is that we are using a certificate that is not issued by a Certification Authority (CA) included into Mozilla products. Certificates are used to identify and authenticate the server of a secure web-site. Instead of purchasing such a certificate from a commercial CA included into Mozilla products, we use a certificate signed by the [[CeBiTec]]. User who have just upgraded from Firefox 2 and used our software before will most likely not be affected.
The reason for this is that we are using a certificate that is not issued by a Certification Authority (CA) included into a number of webbrowsers. Certificates are used to identify and authenticate the server of a secure web-site. A certificate can for example be purchased from a commercial CA. As an academic institution we use a certificate that is signed by the Deutsche Forschungs-Netz (DFN). Unfortunately, this CA (or better the German Telekom which is the root CA for the DFN) is, up to now, not included into some webbrowsers, for example older versions of Mozilla Firefox.


Due to reasons of cost efficiency we do not intend to purchase a certificate from a commercial vendor for our servers. However, Firefox 3 is  much more restrictive when it comes to unrecognized CAs and thus more complicated to configre for this than Firefox 2. We intend to obtain a certificate from the CA of the Deutsche Forschungs-Netz (DFN). Unfortunately,  this CA (or better German Telekom which is the root CA for DFN) is, up to now, not included into Mozilla.
See the Mozilla bug report at https://bugzilla.mozilla.org/show_bug.cgi?id=378882 to get an impressive overview of the bureaucratic process of getting a root certificate into this product.
See the Mozilla bug report  
https://bugzilla.mozilla.org/show_bug.cgi?id=378882 to get an impressive overview of the bureaucratic process of getting a root certificate into this product.


== Solution ==
== Solution ==

Latest revision as of 13:43, 26 October 2011

Webbrowsers and certificate errors

Read this if you are experiencing trouble accessing our software pages with your webbrowser

Problem Description

In some cases you may experience problems when trying to access web-sites using secure connections and certificates such as our software pages (e.g. GenDB, EMMA). When accessing the secure page for the first time, some webbrowsers such as the Mozilla Firefox up to version 5.0 may show an alert message "www.cebitec.uni-bielefeld.de:443 uses an invalid security certificate".

The reason for this is that we are using a certificate that is not issued by a Certification Authority (CA) included into a number of webbrowsers. Certificates are used to identify and authenticate the server of a secure web-site. A certificate can for example be purchased from a commercial CA. As an academic institution we use a certificate that is signed by the Deutsche Forschungs-Netz (DFN). Unfortunately, this CA (or better the German Telekom which is the root CA for the DFN) is, up to now, not included into some webbrowsers, for example older versions of Mozilla Firefox.

See the Mozilla bug report at https://bugzilla.mozilla.org/show_bug.cgi?id=378882 to get an impressive overview of the bureaucratic process of getting a root certificate into this product.

Solution

To access our software you may want to follow the procedure outlined below. This has to be done only once. We apologize for any complication caused by this.

  • In the alert box, click OK

Firefox3$bild 1.png

  • Click Or you can add an exception...

Firefox3$bild 2.png

  • Click Add Exception

Firefox3$bild 3.png

  • In the following dialogue click Get Certificate

Firefox3$bild 4.png

  • After the certificate has loaded, check the Permanently store exception checkbox. Otherwise, the procedure has to be repeated after each browser start.
  • Click Confirm Security Exception
  • The software page should appear, this has only to be done once for all cebitec pages

Firefox3$bild 5.png