Announcement

Collapse
No announcement yet.

Keep gettng certificate errors but only for one user and only when using the nxfilter

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Keep gettng certificate errors but only for one user and only when using the nxfilter

    It doesn't matter what PC the user is logged into, but there are certain sites that confuse a websites certificate with an internal one the error is...
    NET::ERR_CERT_COMMON_NAME_INVALID

    I have confirmed that it doesn't happen when just using the internal DNS servers (most definitely nxfilter). I tried to delete the account in nxfilter and re import it and I also created a new user account in AD but it still keeps happening and it is getting worse.

  • #2
    Which site is it? You know you get an SSL certificate error when it gets blocked on HTTPS? https://nxfilter.org/tutorial/i-faq.php#hide-ssl

    And what do you mean by 'getting worse'? Was it randomly happen and now you get more with the site and the user?

    DNS only tells the browser the IP of the webserver. And SSL certificate error happens when the IP of the server is different from the real owner of the domain. Try to find the IP he gets then. Which IP he gets from other DNS and which IP he gets from NxFilter? You can find it by using nslookup.

    Comment


    • #3
      So that is not it. It is somehow confusing websites with an internal certificate. I don't know why exactly but I can definitely show you. I think that there is something corrupt but specifically for this one user in the nx filter database if i was to guess.... the only thing that fixes it, is to use our regular DNS servers instead of nxfilter on any PC this user logs into. It's not just the one website doing it, it is a bunch. you click on a secure website and it says the certificate is invalid for the website that I am trying to reach, but technically it is because it thinks the certificate is *.mydomain.com. I do use a certificate like that from godaddy, and it may be on the server that nxfilter is installed on. I can't explain it either but I am 100 % sure it has something to do with nxfilter.

      Comment


      • #4
        So what's IP address he gets when he has the problem? Or do you see him blocked on 'Logging > Request'? If it's NxFilter and your DNS doesn't make the problem then there must be something different between them. And the only different thing NxFilter can make is its DNS response. So try to find what was the answer from NxFilter when your user gets the problem.

        Comment


        • #5
          Ok so I figured it out, the sites this is happening are actually being blocked, so I whitelisted them. the issue is when a site is being blocked, they dont get a notification, they get this weird SSL error instead. I am guessing the blocked redirect page is trying to do HTTPS?

          Comment


          • #6
            What did I tell you in the first reply? "You know you get an SSL certificate error when it gets blocked on HTTPS? https://nxfilter.org/tutorial/i-faq.php#hide-ssl". Read that part of our tutorial. We also provide a way of showing block page on https.

            Comment


            • #7
              Ok sorry thanks for the help

              Comment

              Working...
              X