General :  K-Meleon Web Browser Forum
General discussion about K-Meleon 
Invalid security certificates
Posted by: paulderdash
Date: April 03, 2017 10:16AM

I am trying the PortableApps.com version, but I seem to get invalid security cerificate on every site ('Error code: sec_error_unknown_issuer').

If I view the certificate, the issuer in each case is 'Adguard Personal CA', but I have the problem even if I disable Adguard.

Any ideas?

Options: ReplyQuote
Re: Invalid security certificates
Posted by: JohnHell
Date: April 03, 2017 02:44PM

Really, people out there have problem coming to K-meleon forum and posting directly to Bugs subforum and even though the problems have nothing related to K-meleon...


This is not a K-meleon bug. You have installed AdGuard proxy and now you don't know how to configure it.

Here are the instructions to solve the problem. Follow the Firefox instructions if you go through manual procedure. But have in mind that the certificate manager in K-meleon is under "Tools > Privacy > view data" menu.

https://kb.adguard.com/en/windows/solving-problems/connection-not-trusted

Options: ReplyQuote
Re: Invalid security certificates
Posted by: gordon451
Date: April 04, 2017 11:14AM

G'day paulderdash - You may want to consider that what Adguard is doing is actually a MITM attack, and as such is introducing a security hole in your system. Avast--and almost all security software--is also doing it now.

The Adguard Certificate will actually replace whatever Site Certificate is supposed to be presented to your browser. Read Security Week for more detail.

FWIW, I and many others disabled Avast WebShield for this reason, and I'm sure--with no research to back it up--that users of other AV systems have done the same. IMHO, no security system needs to fiddle with TLS which is our prime protection against MITM.

EDIT: Add reference.

____________________
Understanding the scope of the problem is the first step on the path to true panic. [Florence Ambrose, "Freefall" 01372 January 22, 2007 http://freefall.purrsia.com/ff1400/fv01372.htm]



Edited 2 time(s). Last edit at 04/04/2017 11:34AM by gordon451.

Options: ReplyQuote
Re: Invalid security certificates
Posted by: paulderdash
Date: April 07, 2017 11:26AM

OK I understand what is going on now.

The reinstall certificate soltion in Adguard does not work.
If I untick 'Filter HTTPS protocol' in AG all is OK.

I agree AV's etc. should not be the MITM ...

Options: ReplyQuote
Re: Invalid security certificates
Posted by: JohnHell
Date: April 07, 2017 02:52PM

Quote
paulderdash
The reinstall certificate soltion in Adguard does not work.


Have in mind that K-meleon is not firefox. What it does try to install it in Firefox, won't work in K-meleon.

Options: ReplyQuote


K-Meleon forum is powered by Phorum.