FCM cert errors

512 views
Skip to first unread message

ashok Bellur

unread,
Feb 21, 2018, 1:26:23 PM2/21/18
to Firebase Google Group
hello, 

We recently had cert errors and when we looked up the chain it was complaining about ```http://pki.goog/gsr2/GTSGIAG3.crt``` not being in our cert chain. Unfortunately there is no reference or documentation about this anywhere on the PKI website.

After including the cert, the errors stopped. We just want to confirm that this is the way to go.

Thanks,
Ashok

Alexey Dubovenko

unread,
Mar 21, 2018, 5:41:19 PM3/21/18
to Firebase Google Group
Hi ,

after investigating it closer it app[ears trhat google moved that certificate from http://pki.goog/gsr2/GTSGIAG3.crt to httpS://pki.goog/gsr2/GTSGIAG3.crt

In my case MS CAPI makes request to get it by HTTP but pki.goog returns HTTP301, and by the wikipedia "The HTTP response status code 301 Moved Permanently is used for permanent URL redirection, meaning current links or records using the URL that the response is received for should be updated. The new URL should be provided in the Location field included with the response. The 301 redirect is considered a best practice for upgrading users from HTTP to HTTPS.[1]

But looks like MS CAPI does not handle it and treat this code as "certificate not available". if you go by HTTPS link and install this certificate - problem gone.. 
Reply all
Reply to author
Forward
0 new messages