NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
eeeehaw
Mar 18, 2019Aspirant
SSL Bad Certificate Format error blocking management interface
I ran into an unusual problem today on a new Win10Pro laptop where my Chromium engine based browser blocked access to my ReadyNAS Duo v1 (latest firmware 4.1.1.6) because of SSL certificate problem, ...
CplMulder
Jul 15, 2019Aspirant
The latest Chrome version has disabled click-through for the ERR_SSL_SERVER_CERT_BAD_FORMAT issue...
My work-around was to first access my admin page from Edge or IE (Firefox did not work for me) and after clicking-through the warnings, goto to settings>http and enable "Enable HTTP Admin" (screeshot attached will help to find it) .... after doing this using even Chrome over http works (remove the "s" from the https address)... launching from RAIDar NAS Control also works great
I appreciate this is not as secure but then again neither is a certificate with an untrusted issuing authority.
Screenshot attached of where to change setting....
schumaku
Jul 15, 2019Guru - Experienced User
CplMulder wrote:The latest Chrome version has disabled click-through for the ERR_SSL_SERVER_CERT_BAD_FORMAT issue...
Whatever Chrome version that is ... no problems here with Chrome 76, Chrome 77, and Chrome Canary 77.
CplMulder wrote:I appreciate this is not as secure but then again neither is a certificate with an untrusted issuing authority.
While there is a warning on connecting by https ....
===
Your connection is not private
Attackers might be trying to steal your information from rnXXXX (for example, passwords, messages or credit cards). Learn more
NET::ERR_CERT_AUTHORITY_INVALID
===
...which still can be bypassed ... it's not ERR_SSL_SERVER_CERT_BAD_FORMAT - re-create the self-signed cert by entring a new/different name on the https control of your RN.
...
- CplMulderJul 15, 2019Aspirant
Interesting...
I am on the same version of chrome..... however my chrome has no "continue" option (screenshot)... perhaps this is due to some settings within chrome, restrictions imposed by security software or even group policy applied by an employer....
My http link is the only option right now for me that works (on a very protected network tho)
Mulder
London
- CplMulderJul 15, 2019Aspirant
... and chrome version.....
- schumakuJul 15, 2019Guru - Experienced User
Buddy, the problem is not the browser - the problem is that the certificate on your ReadyNAS is bullocks why ever and needs to be re-created.
- eeeehawJul 15, 2019Aspirant
No amount of user recreation of the SSL certifcate will solve this problem, as the root cause is that the digital certificate issued to Netgear by the top level Certificate Authority via their Registration Authority is no longer trusted in the wild. Modern browsers either refer to a downloaded list of currently trusted top and subordinate CAs used to perform their validation checks, or by sending the public key of the questioned certificate to a Validation Authority. When it becomes known that a subordinate CA or VA has become breached and theft of a private key has occurred for a particular subordinate CA, such as Netgear, then the PKI system is notified along with the browser developer, such as Chrome, etc, and they mark that signature certificate as invalid, producing the error we're seeing. To solve the problem, Netgear needs to perform a product update that includes a new digital certificate issued by a trusted top-level CA that is trusted by the browser and other SSL applications.
Meanwhile, with the existing Netgear digital certificate in the product used for creating PKI keys for sessions with the product, there is a distinct possibility of a variety of malicious security attacks possible. Beyond the hassle of over-riding the errors produced by the browser, that can sometimes be band-aided by setting the browser to ignore the threat. Scary stuff. Us end users cannot "fix" this trust, as if we could then the entire Web Of Trust that PKI is based upon would collapse since a black hat could regularly do the same thing as we could.
This is a Netgear problem that only they can fix. They surely have already obtained a new top-level trusted CA-issued set of keys for their own subordinate CA to generate certificates for their products...they likely just haven't bothered to do that for this NAS product, at least I haven't yet seen a firmware update with it yet.
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!