That seems to fix it, thanks!

If so, please remove the CA&certs in ~/.mitmproxy and restart mitmproxy. Since mozilla::pkix doesn't handle that extension and since it's marked critical, the library bails with the error SEC_ERROR_UNKNOWN_CRITICAL_EXTENSION. Comment 21 David Keeler [:keeler] (use needinfo?) 2014-08-22 12:08:40 PDT Well, glad I used try: windows complained about an unused variable. We're just coming of a merger and it's ugly.

I suggest a different comment: The Netscape Certificate Type extension is an obsolete Netscape-proprietary mechanism that we ignore in favor of the standard extensions.

In particular: "Thus, for compatibility reasons, we "understand" this extension by ignoring it when it is not critical, and by ensuring that the equivalent standardized extensions are present when it is

After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server.

I couldn't figure out what was the problem (and still can't even now), but now I found a public website with the same error: https://nolb.dhl.de/Firefox 38 throws:An error occurred during a

In the Command Prompt (DOS), type: Date and press Enter. View January 29, 2011 The suggested "fix" doesn't work for me either, the value was already 2. Click Confirm Security Exception to add the website to the list of trusted ones. I suggest that you put all this comment text in the place where this is enforced and rename this to "criticalNetscapeCertificateType" or "netscapeCertificateTypeIfCritical".

Cheers, Max

Or maybe improving the documentation, I don't believe this quirk is mentioned anywhere.

Feel free to submit a pull request, I'd be happy to merge that in.

Please contact the website owners to inform them of this problem.

This entry was posted on Tuesday, October 21st, 2008 at 11:46 am by Anil Polat and is filed under Tutorial Tuesday. msyed1. 0 Comment Question by:msyed1 Facebook Twitter LinkedIn Email https://www.experts-exchange.com/questions/26991792/Internally-Generated-SSL-Cert-works-with-IE-does-not-work-with-FireFox.htmlcopy Best Solution bylchomycz There is an add o for firefox called IE Tab 2. Old versions generated certs with a netscape extension, for which Iceweasel 31 removed support (see https://github.com/mitmproxy/netlib/issues/39). Certificate contains unknown critical extension. (Error code: sec_error_unknown_critical_extension) Wondering whether this could be an issue with Mozilla's new PKI library that was released with FF 31 ( https://blog.mozilla.org/security/2014/04/24/exciting-updates-to-certificate-verification-in-gecko/ )? — Reply

Comment 26 David Keeler [:keeler] (use needinfo?) 2014-08-28 11:41:12 PDT (In reply to Sergio Oliveira Campos from comment #24) > Is this going to land only on 34? but to make sure - browse to the site in ie, click the padlock, and save the cert from there. Please contact the website owners to inform them of this problem. This is driving me crazy - I'm also using lots of internal sites with this problem - the biggest problem I have is that I'm using Selenium to auto-test many websites,

Problem solved. https://hg.mozilla.org/integration/mozilla-inbound/rev/45065d014c6c Comment 28 Carsten Book [:Tomcat] 2014-08-29 06:00:30 PDT https://hg.mozilla.org/mozilla-central/rev/45065d014c6c Comment 29 David Keeler [:keeler] (use needinfo?) 2014-09-03 14:33:55 PDT Created attachment 8483772 [details] [diff] [review] patch for beta (includes follow-up) Browsers, Web-Sites13 Comments » A lot of users are reporting  weird error certificates such as:  Sec_Error_Expired_Certificate while using Google, Gmail, Picasa, Firefox,Internet Explorer 9 and other applications or web applications relaying Before doing this you must be absolutely sure that the website you want to visit is legitimate.

I can't post a full sample certificate here, but it basically looks like this (yes, I'm aware these are quite weak): Certificate: Data: Version: 3 (0x2) Serial Number: You might want to comment on this bug, but possibly the certificate should be reissued.1008133 - mozilla::pkix does not canonicalize names when matching names during path buildingLike • Show 0 Likes0 How to Free Programs: The Best Free Programs and Applications to Enhance and Improve your Windows Operating System. Is this the only work around to re generate certificate?

Certificate contains unknown critical extension. (error code: sec_error_unknown_critical_extension). I can't access sites Brazilian government websites because they have their own chain (which is not included in Firefox). Covered by US Patent. Your connection to tenantsvr1.vmwaredomain.local is encrypted with 128-bit encryption.