Need a fix for Firefox SEC_ERROR_INADEQUATE_KEY_USAGE error

  • Thread starter Thread starter Borg
  • Start date Start date
  • Tags Tags
    Error Firefox
Click For Summary

Discussion Overview

The discussion revolves around troubleshooting the SEC_ERROR_INADEQUATE_KEY_USAGE error encountered in Firefox when accessing a site with a self-signed certificate. Participants explore various potential causes and solutions, including server settings, profile data management, and antivirus interference.

Discussion Character

  • Exploratory
  • Technical explanation
  • Debate/contested
  • Mathematical reasoning

Main Points Raised

  • One participant describes a workaround involving installing an older version of Firefox to accept the certificate, then upgrading again, but notes administrative access issues on work computers.
  • Another participant suggests checking for non-TLS settings on the server as a possible cause of the error.
  • Several participants mention the possibility of antivirus software blocking untrusted certificates and recommend adding the certificate to the trusted store.
  • One participant provides a method for copying Firefox profile data from a home computer to a work computer, indicating that it should not require admin rights.
  • Another participant confirms they have attempted to copy profile data but did not find the expected Firefox folder in one of the appdata locations and considers trying to copy both profile sections.
  • Participants discuss checking TLS security settings in Firefox and adjusting configurations to resolve the issue.

Areas of Agreement / Disagreement

Participants express multiple competing views regarding the causes of the error and potential solutions. There is no consensus on a definitive fix, and various approaches are suggested without agreement on which is most effective.

Contextual Notes

Some participants mention limitations related to profile data management and server configurations, as well as the impact of different Firefox versions on the troubleshooting process.

Who May Find This Useful

This discussion may be useful for users experiencing similar certificate errors in Firefox, particularly those using self-signed certificates or managing Firefox profiles across different systems.

Borg
Science Advisor
Gold Member
Messages
2,343
Reaction score
5,121
I figured that I would post this in case someone may know the answer. I have a small server at home that is using a self-signed certificate. Firefox used to give a warning about this and then let you accept the certificate. However, newer versions just block the site without being able to override the warning.
FirefoxError.jpg

I did find a fix that required you to install an older version of Firefox, go to the site, override the warning and then install the newer version of Firefox. That worked great at home but I don't have that kind of administrative access on one of my work computers.

I suspect that there is something being set in my profile that is saving the overrides. If so, I should be able to copy that to the profile on my work computer. However, all of my searches have turned up nothing. The best resource that I've found so far is this one describing where Firefox stores profile data. Unfortunately, I haven't had any success yet.

Does anyone know which file may have this data so that I might be able to copy it from my other computer?
 
Computer science news on Phys.org
One of the articles that I looked at led me to think that I might be using a non-TLS setting on my server. I will check later to see if that's the case. Then, I just have to update one line on the server and restart.
 
It can be your antivirus as well. It may be blocking the untrusted certificates and preventing you from going to the site. Actually a really good thing in production scenarios.

Have you tried adding the certificate in question to your trusted store?
 
  • Like
Likes   Reactions: Borg
Routaran said:
It can be your antivirus as well. It may be blocking the untrusted certificates and preventing you from going to the site. Actually a really good thing in production scenarios.

Have you tried adding the certificate in question to your trusted store?
Yes, I have added the root CA that I created to Firefox. The problem didn't start until I was upgraded and the admin rebuilt my profile on the machine. That killed the previous override.
 
In windows the profile data should be stored under c:\users\yourname\appdata\
there are 3 folders, roaming, local and one other.
Look under each and find the firefox/mozilla folder.
Copy the contents of that folder and paste it into the same location at your work system. That will effectively copy your profile from home to work.

since it's under your account, you should not require admin rights to do this.
 
  • Like
Likes   Reactions: Borg
Routaran said:
In windows the profile data should be stored under c:\users\yourname\appdata\
there are 3 folders, roaming, local and one other.
Look under each and find the firefox/mozilla folder.
Copy the contents of that folder and paste it into the same location at your work system. That will effectively copy your profile from home to work.

since it's under your account, you should not require admin rights to do this.
Yes, I've tried that with the roaming part of the profile where most of the profile stuff is located. There wasn't a Firefox folder in the third one (LocalLow). I guess that I could try copying both completely to see if it works but the version at work is a little older and is an ESR version. I can give it a try with both profile sections.

I looked at the server's cert and it seems OK.
BorgPiEncryption.jpg


This is exactly the same that you see if you look at PF's Tools -> Page Info -> Security tab.
PFEncryption.jpg
 
Check your TLS security settings on firefox
in the address bar, type in about:config
then in the search box, tls

and check these settings
https://lh6.googleusercontent.com/WpSdMF2vCj1hP1pxR60L9U118tPm8mLdK9K0tRCWLg5zAKSicTbBBWBhBJTckFt_FzuK6B5MjuCILaA=w1920-h904
 
  • Like
Likes   Reactions: Borg
Yup. Been there also. I even added my IP to the security.tls.insecure_fallback_hosts to see if that would help. I'll double check the settings again tomorrow along with attempting to use a full copy of my Mozilla profile.
 

Similar threads

  • · Replies 34 ·
2
Replies
34
Views
5K
Replies
17
Views
2K
  • · Replies 10 ·
Replies
10
Views
3K
Replies
1
Views
3K
Replies
4
Views
3K
Replies
1
Views
2K
  • · Replies 5 ·
Replies
5
Views
2K
  • · Replies 5 ·
Replies
5
Views
2K
  • · Replies 11 ·
Replies
11
Views
3K
  • · Replies 32 ·
2
Replies
32
Views
5K