This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

"Block invalid certificates" option blocks valid certificates

I've been trying out the "block invalid certificates" option under web protection and have noticed that some valid certificates are blocked with error message "SSL error: unable to get local issuer certificate". Most blocked sites are ad networks but unfortunately some more necessary sites as well. When verifying the blocked certificates on another internet connection they are all fine in Chrome/Internet Explorer/Safari etc.

Anyone else having these issues?

 



This thread was automatically locked due to age.
Parents
  • Thanks for the replies! The XG log says "server certificate does NOT include an ID which matches the server name" and ssllabs.com says "This server's certificate chain is incomplete. Grade capped to B." so I guess the XG is someway on the right track.

    The test result on badssl.com with https decryption on and without block invalid certificates enabled is horrible so the best solution must be to exclude affected sites from https decryption.

Reply
  • Thanks for the replies! The XG log says "server certificate does NOT include an ID which matches the server name" and ssllabs.com says "This server's certificate chain is incomplete. Grade capped to B." so I guess the XG is someway on the right track.

    The test result on badssl.com with https decryption on and without block invalid certificates enabled is horrible so the best solution must be to exclude affected sites from https decryption.

Children
No Data