NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Blitz2016's avatar
Blitz2016
Aspirant
Mar 27, 2016
Solved

Firmware 4.3.3-6 Using Self Signed Cerificates with Serial Number "0"

Firmware 4.3.3-6 has an embedded Cerificate used for security.  PROBLEM: The NetGear Self Signed Certificate has a Serial Number of "00" (or "0").

 

If any other self signed certificate is used elsewhere a security issue is raised and systems begin to fail.  Our site was down most of a day until we accidentally found the problem.  And worst of all the firewall dropped WAN connection and would not link and of course no messages were broadcast.

 

To compound the fact Browsers did not want to connect to the Admin pages because the certificate was deemed bad with a "0" serial number.

 

IMO, NetGear Engineers "must" release a new firmware version with a non-zero self signed certificate.  I believe OpenSSL has a "x509" parameter that will generate a non-zero serial number.  Using a "0' serial number in a self signed certificate inside firmware is a disaster waiting to happen -- and in our case it did.

 

PLEASE release a new firmware with the appropriate fix for the "0" serial number ASAP.

 

Under the right conditions the Firewall will not accept WAN connections or browser connections and there are no error messages or logs or any indications of what happened.  We found the problem "by accident" after hours of running blind.  PLEASE eliminate this problem from ever possibly occuring in the future by using self signed certificates in firmware with a non-zero serial number.

 

 

  • Life's so complicated... I was looking for a link saying online case or support ticket, etc.. Appreciate the response.

4 Replies

  • DaneA's avatar
    DaneA
    NETGEAR Employee Retired

    Hi Blitz2016,

     

    Welcome to the community! :) 

     

    It would be best that you open an online case with NETGEAR Support here regarding your concern.  It is possible that it will be escalated to the engineering team as feature request.

     

     

    Regards,

     

    DaneA
    NETGEAR Community Team

    • Blitz2016's avatar
      Blitz2016
      Aspirant

      Thanks Dane for the reply.  Well either I cannot see what's in front of my face or the link is not correct.  I cannot find any option for opening a case ticket with support.  Just options for premium support and a link back to the Forum and such.  If you have a better link I would appreciate it.

       


      • DaneA's avatar
        DaneA
        NETGEAR Employee Retired

        Hi Blitz2016,

         

        From the link that I have provided to you,  kindly click on "Get help on my NETGEAR product" as shown on the image below then proceed with it so that you can open an online case to get in touch with NETGEAR Support.

         

         

         

         

        Regards,

         

        DaneA

        NETGEAR Community Team

  • Life's so complicated... I was looking for a link saying online case or support ticket, etc.. Appreciate the response.

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More