Stories
Slash Boxes
Comments

SoylentNews is people

posted by mrpg on Saturday May 04 2019, @04:46AM   Printer-friendly
from the FFS! dept.

Armagadd-on 2.0, Mozilla expired certificate disables add-ons

No, the culprit you are losing add-ons isn't your computer, or maybe your old FF, or dropping of Webextensions API. Twitter, Reddit, everyone is wondering what is going on. This Armagadd-on 2.0 has a simple explanation: Mozilla forgot to renew certificates, and so add-ons are failing like if they were not properly signed, because technically they are not. Even signing of new add-ons is down (see comment 9). Great weekend at Mozilla HQ!

Some workarounds, until they clean up the mess, include playing with the computer clock (NTP? forget it) or disabling signature checks (not possible in default releases).

All Firefox extensions disabled due to expiration of intermediate signing cert

User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:66.0) Gecko/20100101 Firefox/66.0

Steps to reproduce:

Wait until it's past midnight on 2019-05-04 UTC.

Actual results:

All addons got disabled due not having valid signature.

Expected results:

If the signature was due to expire, it should have been renewed weeks ago. Not all extensions were disabled. Fakespot and Google Scholar Button were left in their disabled state.

Some reports on reddit says that they had their clocks a day forward, but they may be just early canaries for the actual widespread issue.

Going backwards in time allows installation from AMO (Mozilla Add-ons) but do not remove the unsupported mark from the add-ons already installed.

https://bugzilla.mozilla.org/show_bug.cgi?id=1548973

Workaround: Go to about:config and set xpinstall.signatures.required to false


Original Submission #1Original Submission #2

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 5, Informative) by Bot on Saturday May 04 2019, @06:16AM (10 children)

    by Bot (3902) on Saturday May 04 2019, @06:16AM (#838740) Journal

    an ordinary snafu? bigger fish than mozilla have fucked up with stupid things like renewals of certificates and even domains, but mozilla has already boycotted extensions in the past and:
    - mozilla gets money from google, the competitor
    - mozilla gets money from microsoft, the competitor
    - advertisers do not like extensions
    - deep state does not like extensions

    never attribute to stupidity what is perfectly in line with past behavior and current objectives

    --
    Account abandoned.
    Starting Score:    1  point
    Moderation   +3  
       Informative=3, Total=3
    Extra 'Informative' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   5  
  • (Score: 4, Insightful) by takyon on Saturday May 04 2019, @07:08AM

    by takyon (881) <reversethis-{gro ... s} {ta} {noykat}> on Saturday May 04 2019, @07:08AM (#838743) Journal

    Mozilla is a founder of Let's Encrypt. How embarrassing.

    --
    [SIG] 10/28/2017: Soylent Upgrade v14 [soylentnews.org]
  • (Score: 0) by Anonymous Coward on Saturday May 04 2019, @09:34AM (7 children)

    by Anonymous Coward on Saturday May 04 2019, @09:34AM (#838773)

    "deep state"?

    • (Score: -1, Troll) by Anonymous Coward on Saturday May 04 2019, @01:20PM (6 children)

      by Anonymous Coward on Saturday May 04 2019, @01:20PM (#838796)

      Ask Eisenhower or Kennedy. Or travel back in time 5 years ago before Democrats fell in love with the CIA and ask one of them.

      • (Score: 0) by Anonymous Coward on Saturday May 04 2019, @03:51PM (3 children)

        by Anonymous Coward on Saturday May 04 2019, @03:51PM (#838847)

        Just give a straight answer? Or an alignment unknown or equal opportunity answer. Something.

        • (Score: 2, Informative) by Anonymous Coward on Saturday May 04 2019, @04:10PM (2 children)

          by Anonymous Coward on Saturday May 04 2019, @04:10PM (#838859)

          The intricate web of corporate lobbyists, military interests, bankers, intelligence agencies and other non-elected (sometimes non-government) entities that control the country outside of the political process you learn in middle school civics class. Oil companies, tech giants, the CIA, Goldman Sachs, all are entities which could be labeled part of the "deep state".

          It's inaccurate to describe it as a singular entity with a unified ideology and motive; it's more inaccurate to pretend that it doesn't exist.

          Is that straight enough for you?

          • (Score: 1, Informative) by Anonymous Coward on Saturday May 04 2019, @04:16PM

            by Anonymous Coward on Saturday May 04 2019, @04:16PM (#838863)
          • (Score: 0, Flamebait) by Anonymous Coward on Saturday May 04 2019, @09:08PM

            by Anonymous Coward on Saturday May 04 2019, @09:08PM (#838969)

            Of course the establishment ass-suckers here would mod this 'troll'. This might as well be the green site.

      • (Score: 2) by srobert on Saturday May 04 2019, @09:38PM (1 child)

        by srobert (4803) on Saturday May 04 2019, @09:38PM (#838983)

        LOL. The CIA lied us into war and got a few hundred thousand people killed.
        But now that they parrot the Russiagate narrative, we trust them.

        • (Score: 0) by Anonymous Coward on Wednesday May 08 2019, @04:01PM

          by Anonymous Coward on Wednesday May 08 2019, @04:01PM (#840825)

          Because an intelligence agency needs to 1) always lie 2) always tell the truth. That will really keep the opponents guessing...

  • (Score: 0) by Anonymous Coward on Sunday May 05 2019, @12:47AM

    by Anonymous Coward on Sunday May 05 2019, @12:47AM (#839038)

    There should many people shown the door and shamed by all for this stupid thing.

    First should not have 1 cert but 2. That are 365 days out of sync (assuming 2 yr life).

    If one does not validate - use the other. Then if the failure - idiot who cannot use a calendar, or file corruption, or ... to continue and allow for the processing to continue.

    second use a FUCKING calendar!! It on your smart phone. The techs over this cert, probably treat their dentist better.
    .