Bad SSL certs that SecureBridge is failing to detect

Discussion of open issues, suggestions and bugs regarding network security and data protection solution - SecureBridge
Post Reply
onlinesolutions
Posts: 8
Joined: Mon 28 Jan 2019 15:21

Bad SSL certs that SecureBridge is failing to detect

Post by onlinesolutions » Tue 05 Feb 2019 14:36

Some bad SSL certs that Secure Bridge is not catching in my testing so far.
Bad Certs CORRECTLY detected by Secure Bridge:

https://expired.badssl.com/
https://self-signed.badssl.com/
https://untrusted-root.badssl.com/

Bad Certs not detected by Secure Bridge:

https://wrong.host.badssl.com/
https://revoked.badssl.com/
https://pinning-test.badssl.com/

I am using the trial version of SecureBridge 9.0 for RAD Studio 10 Seattle
(sbridge23.exe is the install from your downloads page)
What would it take to handle these?
Thanks,

- Scott

ViktorV
Devart Team
Posts: 3168
Joined: Wed 30 Jul 2014 07:16

Re: Bad SSL certs that SecureBridge is failing to detect

Post by ViktorV » Wed 06 Feb 2019 08:58

Thank you for information.
We fixed the error for the site https://wrong.host.badssl.com/. This fix will be included in the next SecureBridge build.
The site https://revoked.badssl.com/ uses a revoked certificate. Support for verifying such certificates will be added in the next release of SecureBridge.
The site https://pinning-test.badssl.com/ uses the HPKP technology, which is currently not supported. Checking this site through https://ssllabs.com/ssltest/analyze.htm ... badssl.com shows that this site is safe.
Note, this technology is no longer supported by the latest browsers. (https://chromestatus.com/feature/5903385005916160)

onlinesolutions
Posts: 8
Joined: Mon 28 Jan 2019 15:21

Re: Bad SSL certs that SecureBridge is failing to detect

Post by onlinesolutions » Wed 06 Feb 2019 22:41

Excellent to hear.
Thank you.

ViktorV
Devart Team
Posts: 3168
Joined: Wed 30 Jul 2014 07:16

Re: Bad SSL certs that SecureBridge is failing to detect

Post by ViktorV » Thu 07 Feb 2019 12:27

Thank you for the interest to our product.
If you have any questions during using our products, please don't hesitate to contact us - and we will try to help you solve them.

Post Reply