Categories: Web Technology

HSTS Settings, What they are and how to manage them.

This Site Is Not Secure?!

We’ve come across some problems with a website secured by a valid SSL certificate, but users getting an error message when they try to visit the site, with error codes similar to NET::ERR_CERT_COMMON_NAME_INVALID.

When trying to open a HTTPS webpage, you might get an error message if the server is configured to deliver HSTS (HTTP Strict Transport Security) HSTS is used to mitigate possible downgrade hijacking by forcing browsers to only use the secure HTTPS channel. Your browser caches HSTS settings, and this can sometimes lead to erroneous errors.

The error message is:

This site is not secure

This might mean that someone’s trying to fool you or steal any info you send to the server. You should close this site immediately.

With and option to close the tab, or a More Information button that shows:

Your PC doesn’t trust this website’s security certificate.
The hostname in the website’s security certificate differs from the website you are trying to visit.
Error Code: DLG_FLAGS_INVALID_CA
DLG_FLAGS_SEC_CERT_CN_INVALID.

The error may be presented differently in different browsers, some examples are:

  • NET::ERR_CERT_AUTHORITY_INVALID
  • DLG_FLAGS_INVALID_CA
  • DLG_FLAGS_SEC_CERT_CN_INVALID
  • NET::ERR_CERT_COMMON_NAME_INVALID

Clear the HSTS Settings

The fix the error, you need to clear the HSTS settings in your browser, here are the steps:

CHROME

  • Type in chrome://net-internals/#hsts into the address bar and click enter to open the HSTS Settings pages
  • In the ‘QUERY DOMAIN‘ search box, enter the website where your having the problem and click QUERY
  • If the website is listed, enter it into the ‘DELETE DOMAIN‘ selection and click the button

FIREFOX

  • Open the History page (CTRL + SHIFT + H)
  • Find the site you’re having problems with
  • Right-click the site and choose FORGET ABOUT THIS SITE
  • Restart Firefox

EDGE

  • Go into EDGE settings
  • Click CHOOSE WHAT TO CLEAR
  • Make sure at least CACHED DATA AND FILES is ticked and click CLEAR
  • Restart Edge

#WeCanHelp

That should sort out your broken HSTS security and allow you to access the HSTS protected website.

If you need any help with managing your website, browser or web server, contact us.


it@tinsleynet.co.uk


07825 650122


Contact Us

Share
Leave a Comment