Jump to content

Recommended Posts

Posted
Although we have an idea where our particular issue lies it's odd that Google and Google get the error but google.ie, google.fr etc. work fine. Very strange!

 

Clean up cookies & cached files yet?

Posted

I've resolved this issue at our site (windows 7) by doing the following:

 

Installing the latest GPO templates for chrome and setting the following GPO to "Enabled"

 

user config----admin templates----Classic administrative templates(ADM)------Google-----Google Chrome------ "Whether to allow certificates issued by local trust anchors that are missing the subjectalternativename extension"

 

From what i understand, come chrome version 64, this policy will no longer work but hopefully SOPHOS (in our case) will have updated the certs to have the missing info.

 

Capture.JPG

  • Thanks 2
Posted
I've resolved this issue at our site (windows 7) by doing the following:

 

Installing the latest GPO templates for chrome ...

If you have Windows 7 (or newer) PCs you really should be using the Chrome ADMX templates that Google provide and not the ADM templates which are designed for NT4 to Windows XP PCs.

 

ADMs have quite a few disadvantages too (no central store support which means each GPO that references them stores their own copy of the templates and increases the size of the SYSVOL folder unnecessarily, no multi-language support etc.).

Posted
Just an update on our Chrome issues, turns out it was a bit of software called eSafe which we use to manage safeguarding. It was issuing certificates that were SHA1 and not SHA2, we were just looking at certificates on the Smoothwall box (which all seemed ok). Anyway we got an updated version and all seems ok.
  • Thanks 1
Posted (edited)
Just an update on our Chrome issues, turns out it was a bit of software called eSafe which we use to manage safeguarding. It was issuing certificates that were SHA1 and not SHA2, we were just looking at certificates on the Smoothwall box (which all seemed ok). Anyway we got an updated version and all seems ok.
@duzzie ours didn't resolve with the SHA2 update, most sites OK but Google still has issues. What version are you running of each product? Edited by gshaw
Posted
@duzzie ours didn't resolve with the SHA2 update, most sites OK but Google still has issues. What version are you running of each product?

 

Chrome is version 58.0.3029.81 and the eSafe software was version 4.1.1.23 we have now updated it to 4.3.6.67, and all is good again.

Posted
Chrome is version 58.0.3029.81 and the eSafe software was version 4.1.1.23 we have now updated it to 4.3.6.67, and all is good again.

And you use Smoothwall as a proxy with HTTPS inspection? What version of Smoothwall is it?

 

What happens if you visit

 

www.google.com
www.google.co.uk
www.google.ie

Posted
And you use Smoothwall as a proxy with HTTPS inspection? What version of Smoothwall is it?

 

What happens if you visit

 

www.google.com
www.google.co.uk
www.google.ie

 

Yes we use Smoothwall as a proxy and HTTPS inspection is turned on for students (not staff). It's the latest version (Inverness 5). Google.com and co.uk redirect to forcesafesearch.google.com (our DNS does this) Google.ie is blocked.

Posted

Ive got this issue this morning - everything was fine yesterday but I am getting "your connection is not private" issues all over the place. Mine is fine, oddly.

What can I do?

We use ESET

Posted (edited)
Ive got this issue this morning - everything was fine yesterday but I am getting "your connection is not private" issues all over the place. Mine is fine, oddly.

What can I do?

We use ESET

 

I went the registry edit route, pushed out by GPP. Under HKLM\SOFTWARE\Policies\Google\Chrome add EnableCommonNameFallbackForLocalAnchors as a REG_Dword value of 1. Not had any issues yet.

 

EDIT: Just realised at the bottom of page 2 jahilton2002 has found the GPO setting, which will probably be better.

Edited by TechMonkey
  • Thanks 1
Posted

Cant find the setting specified: ""Whether to allow certificates issued by local trust anchors that are missing the subjectalternativename extension"

 

Can only find this: "Whether to allow certificates issued by local trust anchors "

 

is that good enough?

Posted (edited)
Cant find the setting specified: ""Whether to allow certificates issued by local trust anchors that are missing the subjectalternativename extension"

 

Can only find this: "Whether to allow certificates issued by local trust anchors "

 

is that good enough?

 

make sure you have the latest Google chrome GPO templates

 

try these locations:

Capture.JPG

Edited by Jaan
Posted (edited)

@jahilton2002

I don't have the "classic administrative templates" setting. I tried to download the Chrome ones but whatever I did didnt work even though I followed a nice tutorial on YouTube!

Edited by witch
Posted (edited)
@jahilton2002

 

I downloaded that latest GPO templates from Google. In my case i had to use the adm templates as the adml ones didn't work (or appear) for me.

 

I had it to right click the "admin templates" in user config and import it there.

 

"classic templates" then appears in the GPO and i could assign the setting. I had to do a "gpupdate /force" on the client and after a reboot issue solved.

 

hope that helps.

 

That was all i did.

Edited by Jaan
Posted

FYI, this is also a problem with RM/SEGFL

 

Update - The changes required to fix this issue are being planned for a phased roll out starting Fri 28th Apr through to Thurs 4th May.

Update - We have identified a fix for this problem. The fix will be tested tomorrow. Once proven successful we will complete a phased roll out of the fix to the rest of the proxy farm starting Thursday.

Identified - A wider issue has been identified between version 58.0.3 of Google Chrome, Staff/User proxy and the SSL certificate. When you try to browse to in Chrome a security warning is displayed.

 

We are currently investigating a fix at the moment and hope to have this deployed soon.

 

As a workaround using an alternative proxy other than Staff/Userproxy or a different browser will temporarily resolve the issue.

 

Further updates will be provided when a resolution has been applied.

 

https://status.rm.com/

Posted (edited)
@jahilton2002

 

I downloaded that latest GPO templates from Google. In my case i had to use the adm templates as the adml ones didn't work (or appear) for me.

 

I had it to right click the "admin templates" in user config and import it there.

 

"classic templates" then appears in the GPO and i could assign the setting. I had to do a "gpupdate /force" on the client and after a reboot issue solved.

 

hope that helps.

 

That was all i did.

 

Thats pretty much what I did too...still no classic templates :(

 

EDIT: I went round again - as you do - and this time it worked!! Thanks a lot :)

Edited by witch

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...