[tor-bugs] #3877 [EFF-HTTPS Everywhere]: IETF rule broken with OCSP verification enabled.
Tor Bug Tracker & Wiki
torproject-admin at torproject.org
Wed Aug 31 08:16:13 UTC 2011
#3877: IETF rule broken with OCSP verification enabled.
----------------------------------+-----------------------------------------
Reporter: cypherpunks | Owner: pde
Type: defect | Status: new
Priority: minor | Milestone:
Component: EFF-HTTPS Everywhere | Version:
Keywords: | Parent:
Points: | Actualpoints:
----------------------------------+-----------------------------------------
I'm using firefox with OCSP verification turned on (security.OCSP.require
set to true in about:config).
When I try to read an RFC at ietf.org (e.g.
http://www.ietf.org/rfc/rfc4086.txt ) I consistently get the error
message:
Secure Connection Failed
An error occurred during a connection to www.ietf.org.
The OCSP server has refused this request as unauthorized.
(Error code: sec_error_ocsp_unauthorized_request)
The only "solution" is to turn off ocsp verification globally (or to
disable the https everywhere IETF rule).
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/3877>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list