LXR Software Support
Tech Notes
Technical Bulletin: Issues with Internet Explorer 7 and SSL
Certificates (2/06/2007)
The Problem:
If you use the newest release of Microsoft’s Internet Explorer Version 7 aka IE
7 which is being deployed in many offices to access your web tests and you are using
SSL certificates, you will notice that IE 7 will display a warning message indicating
that there may be a security issue with the site. This message occurs because using
an SSL (security) certificate ensures traffic to and from the site is encrypted.
The message will look something similar to this:
There is a problem with this website’s
security certificate.
The security certificate presented by this website was issued for a different website’s
address. Security certificate problems may indicate an attempt to fool you or intercept
any data you send to the server.
We recommend you close this website and do not continue to this website.
Click here to close.
Continue to this website (not recommended).
More information.
Resolution:
In most instances, if you were to see this message you should be wary of connecting
to the site as the warning implies. If you are connecting to an AMP or LXR site
you may safely ignore this warning message and click the link to continue to the
site. Once you connect securely to the site, you can optionally verify the certificate
and will see that the certificate is valid.
However, AMP and LXR cannot guarantee that a site not affiliated with AMP or LXR
but hosting LXR*TEST Web Tests has a valid SSL certificate. You should verify with
the organization that you are testing with that their SSL certificates are in fact
valid.
Notes:
If the internal users (within the LAN hosting the web testing server) are not seeing
the IE7 warning when they connect to a web test using https but the external users
are seeing the error when they connect using https, then the firewall would most
likely be the source of the problem. The internal users would normally connect directly
to the web server within the LAN and not go through the firewall so they may not
see the error in this case, but external users would. Many firewalls publish web
services using their own SSL certificate. The certificate name on both the web server
and the firewall if used, must match the name of the web in the user's URL exactly
or an error is flagged by Internet Explorer (all versions).
If the error message is about a problem with the certificate, it can mean several
things:
The SSL certificate has expired or been revoked.
The SSL certificate name doesn’t match exactly the name of the web server specified
in the URL (the certificate can still be perfectly ok).
(If they connect to the site and continue despite the warning, then click on the
red shield with the X on it in IE7, it will display the reason for the error and
has a link to view the certificate information.) Older versions will also display
this info, but you had to click on the Lock icon to get it.
The error has nothing to do with incompatibility with LXRTEST, it is strictly an
issue of the SSL certificate used for the web. Internet Explorer has always provided
a warning when there was an issue with a certificate, but with IE7, it is being
much more aggressive with the warning because this can be a source of.