Untrusted Connection over VPN

Author
Discussion

Mr Pointy

Original Poster:

11,218 posts

159 months

Saturday 25th April 2015
quotequote all
I'm currently in one of the Arabian states & am having problems connecting to some https sites over VPN. When I try to connect I get an "Untrusted Connection" warning from Firefox. I've tried VyperVPN & Tunnelbear & via the Wifi at two sites & the wired connection at the hotel. I had thought that using a VPN would give me the ability to log on to my bank in the UK, but it seems not. I'm using Kaspersky AV.

A couple of samples of the errors I get:

bcol.barclaycard.co.uk uses an invalid security certificate.
The certificate is not trusted because the issuer certificate is unknown.
(Error code: sec_error_unknown_issuer)

www.paypal.com uses an invalid security certificate.
The certificate is not trusted because the issuer certificate is unknown.
(Error code: sec_error_unknown_issuer)

Can anyone help? Is it a result of using a VPN or some other more sinister problem?


poing

8,743 posts

200 months

Saturday 25th April 2015
quotequote all
That seems to happen a lot in the recent FF update, have you tried another browser?

Mr Pointy

Original Poster:

11,218 posts

159 months

Saturday 25th April 2015
quotequote all
I don't seem to get the errors using Chrome so maybe it is a FF issue. Thanks.

Martin4x4

6,506 posts

132 months

Saturday 25th April 2015
quotequote all
Mr Pointy said:
I don't seem to get the errors using Chrome so maybe it is a FF issue. Thanks.
This is likely to be an issue with the website using older security standards/insecure conventions.

Mozilla have been increasing the default security model of Firefox and as a result it has started issuing warnings that are real risks. The purpose being to pressure sites using the older standards/conventions to upgrade. You can turn the new features off (or Use Chrome) but the sites is actually compromising your security. Ideally you should be complaining to the website(business) to get them to adopt the latest security standards.

The underlying issue is that some sites still serve some content, usually embedded images etc, from http servers even when it appears on secure https pages when they should no longer be doing this. They do it to save money, the insecure http using a lot less computing power than https.

cornet

1,469 posts

158 months

Tuesday 28th April 2015
quotequote all
Make sure SSL scanning is disabled in Kaspersky

http://support.kaspersky.co.uk/6851

With it enabled it basically performs a man in the middle attack and presents its own cert to the browser which is probably what firefox is complaining about.

Quite how anti-virus software is allowed to get away with this crap I've no idea frown

bitchstewie

51,206 posts

210 months

Tuesday 28th April 2015
quotequote all
Given the regimes in some states, whilst I wouldn't think it would inspecting a connection via VPN, I would check who/what the cert you're being presented with is from.

cornet

1,469 posts

158 months

Tuesday 28th April 2015
quotequote all
I don't believe the problem is anything to do with the VPN. Just the stupid anti virus smile

bitchstewie

51,206 posts

210 months

Tuesday 28th April 2015
quotequote all
cornet said:
I don't believe the problem is anything to do with the VPN. Just the stupid anti virus smile
Oh I suspect you're right, but if I was in that neck of the woods and I got an "Untrusted SSL certificate" error I'd be double checking.

Mr Pointy

Original Poster:

11,218 posts

159 months

Thursday 4th June 2015
quotequote all
Apologies, I've just noticed that I haven't replied to this thread; it was indeed the Kaspersky SSL scanning that was causing the issue. I disabled it & can now pay my bills.

Thanks to all for for the help.

SwissJonese

1,393 posts

175 months

Thursday 4th June 2015
quotequote all
Mr Pointy said:
Apologies, I've just noticed that I haven't replied to this thread; it was indeed the Kaspersky SSL scanning that was causing the issue. I disabled it & can now pay my bills.

Thanks to all for for the help.
Interesting as we have similar SLL issues with our company VPN and they use Kaspersky. Will let the network guys know.