After an evaluation, GNOME has moved from Bugzilla to GitLab. Learn more about GitLab.
No new issues can be reported in GNOME Bugzilla anymore.
To report an issue in a GNOME project, go to GNOME GitLab.
Do not go to GNOME Gitlab for: Bluefish, Doxygen, GnuCash, GStreamer, java-gnome, LDTP, NetworkManager, Tomboy.
Bug 794930 - Invalid TLS Certificate -> white page with no warning
Invalid TLS Certificate -> white page with no warning
Status: RESOLVED NOTGNOME
Product: epiphany
Classification: Core
Component: Passwords, Cookies, & Certificates
3.28.x
Other Linux
: High critical
: ---
Assigned To: Epiphany Maintainers
Epiphany Maintainers
Depends on:
Blocks:
 
 
Reported: 2018-04-03 12:10 UTC by Dan Jacobson
Modified: 2018-04-07 02:08 UTC
See Also:
GNOME target: ---
GNOME version: ---



Description Dan Jacobson 2018-04-03 12:10:05 UTC
$ minibrowser https://summit.debconf.org/
says
Invalid TLS Certificate
Failed to load https://summit.debconf.org/: Do you want to continue ignoring the TLS errors?

But epiphany just shows a white page.

Wouldn't it be better to show a message instead of a white page?

Ah in Bug 444844 you say other browsers don't. OK I'll try one...
Comment 1 Dan Jacobson 2018-04-03 12:14:20 UTC
OK chromium acts like epiphany: no warning.
But ... it also loads the page, just fine.
Comment 2 André Klapper 2018-04-03 12:15:03 UTC
Going to https://summit.debconf.org/debconf15/ I get "This Connection is Not Secure" in epiphany-3.26.6-1.fc27.x86_64 with webkitgtk4-2.18.6-1.fc27.x86_64. If it does not for you then please provide exact version info for both.
Comment 3 Dan Jacobson 2018-04-03 12:32:23 UTC
3.28.0.1
# set https://summit.debconf.org/
# su - nobody -c 'HOME=/tmp/ffd; mkdir -p $HOME; epiphany '$@&
Comment 4 Dan Jacobson 2018-04-03 12:34:46 UTC
libwebkit2gtk-4.0-37       2.20.0-2
libwebkit2gtk-4.0-37-gtk2  2.20.0-2
Comment 5 Michael Catanzaro 2018-04-03 18:16:06 UTC
Works for me
Comment 6 Michael Catanzaro 2018-04-03 18:18:33 UTC
The only plausible explanation I can think of is that you might be getting a network process crash loop or something really bad like that, which would prevent even the normal crash page from appearing. This is a wild and unlikely guess, but that's my only guess. Do you see anything showing up in coredumpctl?
Comment 7 Dan Jacobson 2018-04-04 03:37:57 UTC
 is another such URL.
In the shell I see
Error sending IPC message: Broken pipe

On the Inspector I see Failed to load resource: Unacceptable TLS certificate.

But on the page itself: all white.

There is no coredump message anywhere.
Comment 8 Michael Catanzaro 2018-04-04 16:16:08 UTC
Can you reproduce this issue in an official build (from flathub, or epiphany tech preview)? I've never seen this before. Something seems weird about your system.
Comment 9 Dan Jacobson 2018-04-04 16:50:29 UTC
Today on amd64 I see

This Connection is Not Secure
This does not look like the real https://summit.debconf.org. Attackers might be trying to steal or alter information going to or from this site.

I will check back on i686...
Comment 10 Dan Jacobson 2018-04-07 02:08:14 UTC
OK, created
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=895099
as bug is only seen on Debian i386/i686.