Bonjour,

I haven't checked FF's code, but your websites loads elements from external 
websites that use SHA1-signed certificates (fonts.googleapis.com and 
maps.google.com). If the security warning code has no trigger based on end 
validity date of the certificate, that may be the reason.

Le mardi 31 mars 2015 18:26:17 UTC+2, Innovify Agile a écrit :
> Hi everyone,
> 
> https://wiki.mozilla.org/CA:Problematic_Practices#SHA-1_Certificates
> 
>  Mozilla had add a security warning to the Web Console "This site makes use 
> of a SHA-1 Certificate; it's recommended you use certificates with signature 
> algorithms that use hash functions stronger than SHA-1."
> 
> But i had verified a lot that site is using SHA2 only.
> 
> Here is link : https://staging.landbay.co.uk/
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to