SSL Certificate invalid for many websites
-
theblindrat
- Posts: 6
- Joined: 4. Jun 2015, 16:53
SSL Certificate invalid for many websites
When I browse from Windows7 or Debian Linux (Kali VM) sites like twitter[dot]com are showing invalid certifcates in NAT mode.
I disconnect from the VPN and bridge mode works just fine for both Guest VMS. NAT mode continues to not work.
I have no idea how to resolve this and closest I saw was ESET SSL scans but i disabled antivirus on windows no luck and Kali Linux has no AV setup.
Thanks in advance for your help.
I disconnect from the VPN and bridge mode works just fine for both Guest VMS. NAT mode continues to not work.
I have no idea how to resolve this and closest I saw was ESET SSL scans but i disabled antivirus on windows no luck and Kali Linux has no AV setup.
Thanks in advance for your help.
-
theblindrat
- Posts: 6
- Joined: 4. Jun 2015, 16:53
Re: SSL Certificate invalid for many websites
It seems all the sites I fail on are HSTS enabled with header "strict-transport-security: "
so like support[dot]google[dot]com/ fails
but www[dot]google[dot]com/ works
so like support[dot]google[dot]com/ fails
but www[dot]google[dot]com/ works
-
noteirak
- Site Moderator
- Posts: 5231
- Joined: 13. Jan 2012, 11:14
- Primary OS: Debian other
- VBox Version: OSE Debian
- Guest OSses: Debian, Win 2k8, Win 7
- Contact:
Re: SSL Certificate invalid for many websites
Please read Minimum information needed for assistance.
Hyperbox - Virtual Infrastructure Manager - https://apps.kamax.lu/hyperbox/
Manage your VirtualBox infrastructure the free way!
Manage your VirtualBox infrastructure the free way!
-
theblindrat
- Posts: 6
- Joined: 4. Jun 2015, 16:53
Re: SSL Certificate invalid for many websites
1. VirtualBox version 4.3.28 r100309
2. Host - Windows 7 64bit 16GB RAM, Guest 1 Windows 7 64bit 11GB RAM, Guest 2 Linux 2.6/3.x 64bit. Both configured in NAT mode and running in a VPN
3. Logs for both attached
2. Host - Windows 7 64bit 16GB RAM, Guest 1 Windows 7 64bit 11GB RAM, Guest 2 Linux 2.6/3.x 64bit. Both configured in NAT mode and running in a VPN
3. Logs for both attached
- Attachments
-
Kali Linux-2015-06-04-12-00-44.log- (118.13 KiB) Downloaded 10 times
-
Windows7-64bit Clone-2015-06-04-10-36-41.log- (97.86 KiB) Downloaded 13 times
-
noteirak
- Site Moderator
- Posts: 5231
- Joined: 13. Jan 2012, 11:14
- Primary OS: Debian other
- VBox Version: OSE Debian
- Guest OSses: Debian, Win 2k8, Win 7
- Contact:
Re: SSL Certificate invalid for many websites
Nothing strikes me as odd in the logs. Can you a nslookup <website-domain> on both guests with NAT & Bridged and VPN on & off for each? that means 4 results.
make sure to run ipconfig /flushdns on the windows VM before each attempt
make sure to run ipconfig /flushdns on the windows VM before each attempt
Hyperbox - Virtual Infrastructure Manager - https://apps.kamax.lu/hyperbox/
Manage your VirtualBox infrastructure the free way!
Manage your VirtualBox infrastructure the free way!
-
theblindrat
- Posts: 6
- Joined: 4. Jun 2015, 16:53
Re: SSL Certificate invalid for many websites
Here is that information.
VPN on + bridged does not work -- those two left out
VPN on + NAT linux
Server: 10.x.x.x
Address: 10.x.x.x#yy
Non-authoritative answer:
Name: twitter.com
Address: 199.16.156.230
Name: twitter.com
Address: 199.16.156.198
Name: twitter.com
Address: 199.16.156.6
Name: twitter.com
Address: 199.16.156.102
VPN ON + NAT Windows 7
nslookup twitter.com
Server: google-public-dns-a.google.com
Address: 8.8.8.8
Non-authoritative answer:
Name: twitter.com
Addresses: 199.16.156.6
199.16.156.38
199.16.156.198
199.16.156.230
VPN OFF + NAT Windows 7
nslookup twitter.com
Server: google-public-dns-a.google.com
Address: 8.8.8.8
Non-authoritative answer:
Name: twitter.com
Addresses: 199.16.156.38
199.16.156.198
199.16.156.6
199.16.156.102
VPN OFF + NAT Linux
Server: 192.168.1.1
Address: 192.168.1.1#53
Non-authoritative answer:
Name: twitter.com
Address: 199.16.156.198
Name: twitter.com
Address: 199.16.156.70
Name: twitter.com
Address: 199.16.156.38
Name: twitter.com
Address: 199.16.156.6
VPN OFF + Bridged Windows
Server: google-public-dns-a.google.com
Address: 8.8.8.8
Non-authoritative answer:
Name: twitter.com
Addresses: 199.16.156.38
199.16.156.102
199.16.156.70
199.16.156.230
VPN OFF + Bridged Linux
Server: 192.168.1.1
Address: 192.168.1.1#53
Non-authoritative answer:
Name: twitter.com
Address: 199.16.156.70
Name: twitter.com
Address: 199.16.156.230
Name: twitter.com
Address: 199.16.156.198
Name: twitter.com
Address: 199.16.156.6
VPN on + bridged does not work -- those two left out
VPN on + NAT linux
Server: 10.x.x.x
Address: 10.x.x.x#yy
Non-authoritative answer:
Name: twitter.com
Address: 199.16.156.230
Name: twitter.com
Address: 199.16.156.198
Name: twitter.com
Address: 199.16.156.6
Name: twitter.com
Address: 199.16.156.102
VPN ON + NAT Windows 7
nslookup twitter.com
Server: google-public-dns-a.google.com
Address: 8.8.8.8
Non-authoritative answer:
Name: twitter.com
Addresses: 199.16.156.6
199.16.156.38
199.16.156.198
199.16.156.230
VPN OFF + NAT Windows 7
nslookup twitter.com
Server: google-public-dns-a.google.com
Address: 8.8.8.8
Non-authoritative answer:
Name: twitter.com
Addresses: 199.16.156.38
199.16.156.198
199.16.156.6
199.16.156.102
VPN OFF + NAT Linux
Server: 192.168.1.1
Address: 192.168.1.1#53
Non-authoritative answer:
Name: twitter.com
Address: 199.16.156.198
Name: twitter.com
Address: 199.16.156.70
Name: twitter.com
Address: 199.16.156.38
Name: twitter.com
Address: 199.16.156.6
VPN OFF + Bridged Windows
Server: google-public-dns-a.google.com
Address: 8.8.8.8
Non-authoritative answer:
Name: twitter.com
Addresses: 199.16.156.38
199.16.156.102
199.16.156.70
199.16.156.230
VPN OFF + Bridged Linux
Server: 192.168.1.1
Address: 192.168.1.1#53
Non-authoritative answer:
Name: twitter.com
Address: 199.16.156.70
Name: twitter.com
Address: 199.16.156.230
Name: twitter.com
Address: 199.16.156.198
Name: twitter.com
Address: 199.16.156.6
-
theblindrat
- Posts: 6
- Joined: 4. Jun 2015, 16:53
Re: SSL Certificate invalid for many websites
Any other ideas? It's very odd to me it only seems to be HTTP Strict Transport Security (HSTS) enabled websites.
-
noteirak
- Site Moderator
- Posts: 5231
- Joined: 13. Jan 2012, 11:14
- Primary OS: Debian other
- VBox Version: OSE Debian
- Guest OSses: Debian, Win 2k8, Win 7
- Contact:
Re: SSL Certificate invalid for many websites
Not much to go on. Could you get the certificate of twitter per example, once on NAT and once on Bridged mode, and attach both here?
Hyperbox - Virtual Infrastructure Manager - https://apps.kamax.lu/hyperbox/
Manage your VirtualBox infrastructure the free way!
Manage your VirtualBox infrastructure the free way!
-
theblindrat
- Posts: 6
- Joined: 4. Jun 2015, 16:53
Re: SSL Certificate invalid for many websites
What is the best way to do that?
-
noteirak
- Site Moderator
- Posts: 5231
- Joined: 13. Jan 2012, 11:14
- Primary OS: Debian other
- VBox Version: OSE Debian
- Guest OSses: Debian, Win 2k8, Win 7
- Contact:
Re: SSL Certificate invalid for many websites
Go on the website and in your browser address bar, you'll have certificate info. Press "View certificate" or similar, and then in the new window you should be able to save it.
Hyperbox - Virtual Infrastructure Manager - https://apps.kamax.lu/hyperbox/
Manage your VirtualBox infrastructure the free way!
Manage your VirtualBox infrastructure the free way!