Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 1st, 2010, 08:36 AM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default SSL protocol checking breaks updates of FF Minefield 3.7 and MediaCenter

running update of FF Minefield with SSL checking on (4.2.40.0 on WIN 7 64bit) returns the following error

Name:  FF Minefield update.png
Views: 270
Size:  21.6 KB

for MediaCenter the error reads:

Failed to retrieve EpgListings (Error: The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel.)


no problems when SSL checking is off, hence please sort this bug out.

Last edited by vtol : May 4th, 2010 at 06:53 AM.
  #2  
Old May 20th, 2010, 06:33 PM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default Re: SSL protocol checking breaks updates of FF Minefield 3.7

this has not been fixed until date, SSL protocol checking breaking:

FF Minefield updates
WIN 7 64 bit MediaCentre Updates
  #3  
Old May 21st, 2010, 06:10 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,225
Default Re: SSL protocol checking breaks updates of FF Minefield 3.7

You can accomplish SSL scanning in FF Minefield by exporting the ESET root certificate (e.g. via IE) and importing it to FF manually.
  #4  
Old May 21st, 2010, 06:35 AM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default Re: SSL protocol checking breaks updates of FF Minefield 3.7

Quote:
Originally Posted by Marcos
You can accomplish SSL scanning in FF Minefield by exporting the ESET root certificate (e.g. via IE) and importing it to FF manually.
tried it, but it does not solve the matter.

there are two types of certificates to be exported from IE8 32bit, *.cert and *.p7b. latter cannot be imported into FF Minefield. hence leaves the *.cert.
the only FF store accepting is servers

Name:  21-05-2010 12-29-55.png
Views: 224
Size:  41.1 KB

having the certificate there gets me still the error when updating as shown in the initial post.

also leaves MediaCentre Updates, which for now excluded from SSL scanning, yet again just being a workaround but no fix
  #5  
Old May 21st, 2010, 07:27 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,225
Default Re: SSL protocol checking breaks updates of FF Minefield 3.7

Please follow the instructions mentioned in this KB article. If you have already added Mozilla's certificate to the Trusted certificates list, remove it. The next time you'll attempt to update FF, a pop-up window asking you whether to trust the certificate will appear, choose Exclude and FF will update fine.
  #6  
Old May 21st, 2010, 07:37 AM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default Re: SSL protocol checking breaks updates of FF Minefield 3.7

Quote:
Originally Posted by Marcos
Please follow the instructions mentioned in this KB article. If you have already added Mozilla's certificate to the Trusted certificates list, remove it. The next time you'll attempt to update FF, a pop-up window asking you whether to trust the certificate will appear, choose Exclude and FF will update fine.
thanks. wondering what is wrong with the *.mozilla.org certificate that it has to be excluded (which is just another workaround) by NOD? it will just not only impact the update but any website using the *.mozilla.org certificate

and what is wrong with the MediaCenterUpdate?
  #7  
Old May 21st, 2010, 07:48 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,225
Default Re: SSL protocol checking breaks updates of FF Minefield 3.7

That's so because there's no way to make the root certificate a built-in certificate and thus FF doesn't trust it.

As for MediaCenter, I'm not familiar with it. Could you provide me with a link where I could download it from so that I can test it?
  #8  
Old May 21st, 2010, 10:01 AM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default Re: SSL protocol checking breaks updates of FF Minefield 3.7

Quote:
Originally Posted by Marcos
That's so because there's no way to make the root certificate a built-in certificate and thus FF doesn't trust it.
strange, because according to the KB you referred to NOD is excluding the *.mozilla.org certificate and not FF excluding the Eset certifcate?

Quote:
Originally Posted by Marcos
As for MediaCenter, I'm not familiar with it. Could you provide me with a link where I could download it from so that I can test it?
it is actually build-in WIN 7, I reckon all flavours.

Name:  21-05-2010 15-53-09.png
Views: 205
Size:  75.0 KB

its updater is

Name:  21-05-2010 15-56-07.png
Views: 209
Size:  174.7 KB

and the error log is mentioned in the initial post
  #9  
Old May 25th, 2010, 01:50 PM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default Re: SSL protocol checking breaks updates of FF Minefield 3.7

before it gets forgotten
  #10  
Old June 5th, 2010, 07:06 AM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Unhappy Re: SSL protocol checking breaks updates of FF Minefield 3.7

not fixed yet
  #11  
Old June 6th, 2010, 03:17 PM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default Re: SSL protocol checking breaks updates of FF 3.7 / MC update / FileZilla update

on the MC update the error reads:
Quote:
The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel.
seems the list keeps on growing, next application failing update with SSL protocol checking enabled is FileZilla, error log:
Quote:
Status:Status: Resolving address of update.filezilla-project.org
Status: Connecting to 213.239.222.5:443...
Status: Connection established, initializing TLS...
Error: Root certificate is not trusted
Error: Disconnected from server: ECONNABORTED - Connection aborted

and the workaround, mozilla certificate excluded) for FF does not work around any more with the latest FF 3.7 64bit version.

when all of this getting fixed?

Last edited by vtol : June 6th, 2010 at 03:25 PM.
  #12  
Old June 6th, 2010, 04:23 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,225
Default Re: SSL protocol checking breaks updates of FF 3.7 / MC update / FileZilla update

Mozilla products will not work with SSL enabled unless an exception is set. As it's been said, it's because 3rd party cannot be set as built-in which are the only ones Mozilla trusts.
  #13  
Old June 6th, 2010, 08:17 PM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default Re: SSL protocol checking breaks updates of FF 3.7 / MC update / FileZilla update

Quote:
Originally Posted by Marcos
Mozilla products will not work with SSL enabled unless an exception is set. As it's been said, it's because 3rd party cannot be set as built-in which are the only ones Mozilla trusts.
that exception/workaround you pointed too does not work any more with the latest 64bit version of FF Minefield. if is stays that way FF 4 update will not be working with NOD32 SSL protocol checking enabled.

why would be a problem for Eset to get in touch with Mozilla and simply fix it?

having said that there are more incompatibilities mentioned.
  #14  
Old June 7th, 2010, 08:14 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,225
Default Re: SSL protocol checking breaks updates of FF 3.7 / MC update / FileZilla update

Quote:
Originally Posted by vtol
why would be a problem for Eset to get in touch with Mozilla and simply fix it?
Not possible as a new root certificate is generated dynamically when SSL scanning is enabled. The only possible option would be accepting other than built-in certificates by Mozilla which is against their strict policy.
  #15  
Old July 6th, 2010, 05:05 PM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default Re: SSL protocol checking breaks updates of FF Minefield 3.7

MC update / FileZilla update not fixed with 4.2.58.3
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:46 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums