SSL certification errors
Issues with their Root Cause
- When SSL certificate imported into chrome browser and still shows Your connection is not secured for HTTPS sites.
->Policies in HTTPS Inspection subsection may not be configured correctly.
- While successful configuration of HTTPS Inspection, accessing youtube.com shows error but all other HTTPS sites works fine.
->In HTTPS inspection section, if Global subsection is not set to Enabled as TRUE then this problem may arise.
- While SafeSquid certificate is installed inside browser however HTTPS sites showing error Secured connection fail.
->Either passphrases were not matched or Password encryption failed due to inappropriate input given.
- SSL certificate downloaded with size 0 bytes.
->When certificate is downloaded without encryption of password then certificate will be downloaded with 0 bytes.
- Displaying ERROR "SSL Connection to webmail.safesquid.net:2096 denied S_X509_DNS_MISMATCH: SSL Certificate has DNS errors."
->Remove HTTPS websites from SSL Certs/Cache if you get error Secured connection fail when you access HTTPS websites or some of theHTTPS websites are working without error but some of the HTTPS websites are not working.
Case 1 : Check whether SSL certificate was properly imported inside browser or not.
Case 2 : Check SSL Certs/Cache if you face issue mentioned below
SafeSquid certificate imported inside browser but still showing error Secured connection fail when you try to access HTTPS websites
Some HTTPS websites are working without error, but others are not working.
When you remove old activation key and install new activation key and then configure new SSL certificate.
If you face above issues you have to remove all the HTTPS websites which you access from path /var/db/safesquid/ssl
Run the below command and check for the file
Repeat above step for goodcerts/ and badcerts/ and access those websites from browser.
Case 3 : Displaying ERROR "SSL Connection to webmail.safesquid.net:2096 denied S_X509_DNS_MISMATCH: SSL Certificate has DNS errors."
When you access any website and face error "S_X509_DNS_MISMATCH: SSL Certificate has DNS errors" via proxy even you properly configured SSL certificate inside browser,
that means certificate of that website is broken.
SafeSquid stores all those websites whose certificates are broken under this path /var/db/safesquid/ssl/badcerts/
- You should find the domain of website at given path : /var/db/safesquid/ssl/badcerts/
- Go to that domain name folder by command : cd domain-name
- You should find FQDN of that website.(e.g. webmail.safesquid.net)
- Go to that FQDN by command :vi FQDN (e.g. vi webmail.safesquid.net
- Here you should find mismatch domain name
To ALLOW Block domain mismatch errors of HTTPS web-sites you have to create a policy