NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

RupertGiles's avatar
RupertGiles
Apprentice
Jul 07, 2017
Solved

Self signed certificate error in Chrome 59

The self-signed certificate from the ReadyNAS O/S is no longer considered valid by Chrome 59. There are two errors:

  • Subject Alternative Name Missing
  • There are issues with the site's certificate chain (net::ERR_CERT_COMMON_NAME_INVALID).

Any plans for getting this fixed in a future release? I'd have thought it would have been taken care of with 6.7.5.

OS X (Sierra 10.12.5) Google Chrome Version 59.0.3071.115 (Official Build) (64-bit)

 

  • StephenB's avatar
    StephenB
    Jul 07, 2017

    RupertGiles wrote:

    It would be nice to never have to see that warning.


    True.  I used to use firefox with the NAS, since it's very simple to add a security exception there.  But the click-through has become pretty automatic (which of course defeats it's purpose).

8 Replies

Replies have been turned off for this discussion
  • StephenB's avatar
    StephenB
    Guru - Experienced User

     

    Just wondering - did you try regenerating the cert?

    • RupertGiles's avatar
      RupertGiles
      Apprentice

      Yes indeed. On Chrome 59, it's More Tools/Developer Tools/View Certificate

      I dragged the certificate to the desktop, then deleted the existing certificate in Keychain, and finally, imported the certificate from my desktop and set the permissions to "Always Trust".

       

      What's changed (from what I've gathered off Google boards) is the requirement for the SAN.

      If I've missed something in my procedure, please let me know, and I'll retry. Thanks!

      • StephenB's avatar
        StephenB
        Guru - Experienced User

        I meant regenerate the cert on the NAS.  I don't think the firmware upgrades do that automatically.

         

        You'd do this in system->settings->services->https.  It should regenerate the cert if you simply enter "apply".  

         

        But you could change the SSL key host, apply, then change it back, apply again if you want to be certain.

         

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More