Bug 64235 - Continue on cert rejection message doesn't continue
Summary: Continue on cert rejection message doesn't continue
Status: UNCONFIRMED
Alias: None
Product: WebKit
Classification: Unclassified
Component: Page Loading (show other bugs)
Version: 528+ (Nightly build)
Hardware: Macintosh Intel Unspecified
: P2 Minor
Assignee: Nobody
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-07-09 17:48 PDT by cnep5ll3
Modified: 2011-07-15 23:20 PDT (History)
3 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description cnep5ll3 2011-07-09 17:48:46 PDT
I have chosen not to trust:
Go Daddy Class 2 Certificate Authority
I go to https://www.online-billpay.com/ which uses a cert signed by a cert signed by the above.
I get the (correct) message that ‘Safari can’t verify … ’.
One option is ‘Continue’.
That leads to a seemingly infinite loop of such messages.

Ditto Safari 5.05
Comment 1 cnep5ll3 2011-07-15 23:20:50 PDT
Here is probably the same bug acting more bizarrely.

I have chosen not to trust Equifax Secure Certificate Authority
SN 903804111
I launch Webkit. I empty the cache.
I enter the following into the address bar:
http://en.wikipedia.org/wiki/Canvas_(HTML_element)
and click on the 2nd link of the ‘References’ whose URL is:
https://developer.mozilla.org/en/DOM/HTMLCanvasElement
I get a dialog box saying "Safari can’t verify the identity of the website “developer.mozilla.org”."
The cert is signed by Equifax and so this is expected.
I click "Continue".
At this point I get two new items on the screen, both inappropriate:
First a new dialog box "Type your password to make changes to your Certificate Trust Settings." but I have made no changes and do not plan to.
Second the standard "Keyboard Viewer" which is active and shows characters as I type.
Version 535.1+
2.4 GHz Intel Core 2 Duo
OS X 10.6.8

This is reproducible.

There are no Console messages unless I cancel the password dialog box which produces:
11/7/15 22:54:00 	Safari[18911]	SecTrustSettingsSetTrustSettings returned -60006