Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #243578 > unrolled thread

telling firefox 91 to always accept self signed certificate.

Started byTim Woodall <debianuser@woodall.me.uk>
First post2022-01-02 11:50 +0100
Last post2022-01-02 13:50 +0100
Articles 2 — 2 participants

Back to article view | Back to linux.debian.user


Contents

  telling firefox 91 to always accept self signed certificate. Tim Woodall <debianuser@woodall.me.uk> - 2022-01-02 11:50 +0100
    Re: telling firefox 91 to always accept self signed certificate. "Alexander V. Makartsev" <avbetev@gmail.com> - 2022-01-02 13:50 +0100

#243578 — telling firefox 91 to always accept self signed certificate.

FromTim Woodall <debianuser@woodall.me.uk>
Date2022-01-02 11:50 +0100
Subjecttelling firefox 91 to always accept self signed certificate.
Message-ID<DB6B3-27I-3@gated-at.bofh.it>
I have a buster install where firefox-esr has just been updated. I
cannot work out how to tell it to always accept self-signed (and
expired) certificates without a warning.

I had a permanent exception set under about:preferences#privacy
ViewCertificates but that didn't seem to be working. And attempting to
add another exception changed the existing "permanent" exception to
temporary with no option to check the "add permanent exception" box.

I cannot get firefox to use http instead, it insists on changing to
https even though https only mode is turned off (I'm not 100% sure http
will work anyway but firefox won't even try)

I don't care about "security" for this connection. It's an IPMI console
that is only accessible on the same (trusted) physical lan and remote
access is only possible via a vpn.

I cannot find anything in about:config that seems to help this.

Before I downgrade back to the old version of firefox is there anything
I can do so that this "just works" without prompting?

Tim.

[toc] | [next] | [standalone]


#243580

From"Alexander V. Makartsev" <avbetev@gmail.com>
Date2022-01-02 13:50 +0100
Message-ID<DB8tc-3e4-1@gated-at.bofh.it>
In reply to#243578
On 02.01.2022 15:47, Tim Woodall wrote:
> I have a buster install where firefox-esr has just been updated. I
> cannot work out how to tell it to always accept self-signed (and
> expired) certificates without a warning.
>
> I had a permanent exception set under about:preferences#privacy
> ViewCertificates but that didn't seem to be working. And attempting to
> add another exception changed the existing "permanent" exception to
> temporary with no option to check the "add permanent exception" box.
This is not the only way to add an exception, but I think it is the best 
way.
You have to go to "Servers" tab and put exact URL and also port for the 
connection.
     Ex: https://my-nas.lan:443/
Also if your server will redirect connection to another port you have to 
add it also.
     Ex: https://my-nas.lan:5001/
Exceptions added this way will work as long as host:port and downloaded 
certificate matches the exception.
If they don't, your Firefox profile could be corrupted, so test it on a 
brand new profile, created with profile manager:
     $ firefox --ProfileManager

> I don't care about "security" for this connection. It's an IPMI console
> that is only accessible on the same (trusted) physical lan and remote
> access is only possible via a vpn.
>
> I cannot find anything in about:config that seems to help this.
Doing this via "about:config" (if that even possible) would leave your 
browser vulnerable for connections on the Internet, other than your 
local trusted servers.
There is also another way to add an exception like this. You can add 
server's self-signed certificate to 'ca-certificates' on your system as 
a trusted certificate authority.
This way browser should still display "not trusted connection" icon, but 
without warning page and confirming an exception.

And the real solution for this problem would be to spin-off your own 
certificate authority using 'Easy-RSA', add your CA certificate as 
trusted on your systems and/or browser, and create and replace 
client-server authentication certificates on your network hosts.
This way might be harder and longer to do, but it is a proper solution 
that is scalable and manageable.
As a bonus, you can use same CA to defend your WiFi networks with 
"Enterprise" level of protection, not just "WPA*-PSK".
Or create and manage certificates for OpenVPN hosts-clients.

-- 
With kindest regards, Alexander.

⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
⠈⠳⣄⠀⠀⠀⠀

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web