Jump to content

Root Certificates and Revoked Certificates for Windows XP


Recommended Posts


Posted (edited)

When I access the website https://www.deepl.com/translator with Chrome 43.0.2357.134, the padlock is green.
A different certification path is listed here than in 360Chrome.

Is it possible to set which certification is used?

 

Screenshot.jpg

Edited by Anbima
Posted

Re -update.

The contents of the updroots.sst file have been changed; the contents of the other * .sst files are unchanged.

Updroots.jpg

Posted
On 5/29/2024 at 1:23 PM, Anbima said:

Is it possible to set which certification is used?

Not directly, the web server decides which cert chain to present.

At some sites it depends on what device, OS or browser it thinks you are using, or what location it thinks your IP is at. You can try experimenting with different user agent strings, but some web sites use additional javascript libraries or other fingerprinting methods to get past a simple UA string spoof. Or you can try different VPNs to get IP addresses from different locations.

Posted

If anyone is interested, I have found a way to get the padlock back to green on most pages in 360Chrome.
This involves limiting the TLS to a maximum of 1.2 and blocking certain ciphers.
However, it happens that some websites no longer work, such as msfn.

Simply add the following to the start parameters:
--ssl-version-max=tls1.2 --cipher-suite-blacklist=0xcca9,0xc02b,0xc02c

Posted
5 hours ago, Anbima said:

However, it happens that some websites no longer work, such as msfn.

And that's why it makes no sense at all. nimportequoi.gif Using ProxHTTPSProxy does it definitely better. Or a more recent Chromium version as, for example, Thorium:P

Posted

I looked at the network traffic with Wireshark and even if the padlock is not green and https is crossed out, the data is transmitted in encrypted form.
I also tested with an unencrypted page (http) and the transmitted data is readable.

I assume that the faulty certificate is then only decisive for the identity of the server and that this cannot be confirmed.

Thorium or Supermium may be good, but it is nowhere near as fast as 360Chrome on my computer.
And the memory consumption is also much higher.

  • 5 months later...
Posted

I would like to know why I do not see any ads anymore (e.g. on videocardz.com and linuxliteos.com) after updating root certificates with v1.6 of this tool... was my problem, then (as I've written in Roytam1's browser topic):

Mighty fine! I've searched around and found this fine site: Cert_updates for legacy Windows - imported root and intermediate certificates and everything works correctly, e.g. Tomshardware site.

  • 4 weeks later...
  • 1 month later...
Posted
4 hours ago, egrabrych said:

The delroots.sst and updroots.sst files have changed, the authroots.sst and roots.sst file remains unchanged.

CAupdater.jpg

Thanks for reporting! TBH, I didn't expect any further root certificate updates via  CAupdater 1.0 or Certificate Updater 1.6. Great news! :thumbup

Posted

Yep, they're still working, I've just updated as well. Thanks for the heads up! I'm glad to see that they're still going. :) 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...