the dynamically generated certificates raise a NET::ERR_CERT_COMMON_NAME_INVALID in chrome 76

231 views
Skip to first unread message

Delia Vasile

unread,
Jul 18, 2018, 11:26:22 AM7/18/18
to OWASP ZAP User Group
Hello, 

I imported the ZAP root certificate as a trusted authority in google chrome 67 on Ubuntu, but when I am trying to navigate to the website that I want to attack with ZAP, I am getting a security error from chrome: NET:ERR_CERT_COMMON_NAME_INVALID that the certificate does not specify Subject Alternative Names - you can see it in the attached screenshot. 

Is there a solution for this issue? Chrome in headless mode does not start properly because of this error. 


ssl_error.PNG

kingthorin+owaspzap

unread,
Jul 18, 2018, 1:41:19 PM7/18/18
to OWASP ZAP User Group
1) You forgot to redact the target in the bottom half of your image.
2) Click "Proceed to ________ (Unsafe)"

Simon Bennetts

unread,
Jul 18, 2018, 2:57:34 PM7/18/18
to OWASP ZAP User Group
You need to import the cert into the "Trusted Root Certificate Authorities" store - is that the one you used?

Delia Vasile

unread,
Jul 18, 2018, 3:09:54 PM7/18/18
to zaprox...@googlegroups.com
Yes, I realised afterwards. Still I checked the sources of zaproxy on github and it looks like subject alternative name is added:


I just tested with zap version 2.7.0 for mac and I can see the Subject Alternative Name in Chrome when I inspect the certificate, I tested also with the owasp/zap2docker stable image which has zap 2.7.0 and it is fixed, after I import the zap root certificate, chrome doesn't give any errors. I got the error when I tested with version 2.4.0 

Any idea in which version was this fixed? 

--
You received this message because you are subscribed to the Google Groups "OWASP ZAP User Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to zaproxy-user...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/zaproxy-users/e3c5600a-abff-4ecf-ba5d-0616f2a597ef%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

thc...@gmail.com

unread,
Jul 18, 2018, 3:48:36 PM7/18/18
to zaprox...@googlegroups.com

Delia Vasile

unread,
Jul 18, 2018, 4:26:51 PM7/18/18
to zaprox...@googlegroups.com
We have all kinds of corporate rules and I need to get the version with the fix approved such that it becomes available on our internal repository. Boring organisational stuff :)

Simon Bennetts

unread,
Jul 19, 2018, 2:54:33 AM7/19/18
to OWASP ZAP User Group
Unfortunately we're a relatively small team and can therefore only support the latest version of ZAP.
Good luck getting it approved :)

>> To view this discussion on the web visit
>> https://groups.google.com/d/msgid/zaproxy-users/e3c5600a-abff-4ecf-ba5d-0616f2a597ef%40googlegroups.com
>> <https://groups.google.com/d/msgid/zaproxy-users/e3c5600a-abff-4ecf-ba5d-0616f2a597ef%40googlegroups.com?utm_medium=email&utm_source=footer>
>> .
>> For more options, visit https://groups.google.com/d/optout.
>>
>

--
You received this message because you are subscribed to the Google Groups "OWASP ZAP User Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to zaproxy-users+unsubscribe@googlegroups.com.
Reply all
Reply to author
Forward
0 new messages