{"id":3128,"date":"2016-10-21T13:42:28","date_gmt":"2016-10-21T13:42:28","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=3128"},"modified":"2020-12-16T14:36:39","modified_gmt":"2020-12-16T19:36:39","slug":"browser-watch-chrome-54","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/browser-watch-chrome-54\/","title":{"rendered":"Browser Watch: Tracking SSL Changes in Chrome 54"},"content":{"rendered":"<h2>Chrome 54 Features Better Messaging For Server Admins.<\/h2>\n<p>Google Chrome 54 <a href=\"https:\/\/googlechromereleases.blogspot.com\/2016\/10\/stable-channel-update-for-desktop.html\" rel=\"nofollow\">released last week<\/a>, and like every new version of Chrome, there have been some changes to Chrome\u2019s SSL\/TLS and networking capabilities and features.<\/p>\n<p>The most notable changes in Chrome 54 are expanded information in the <em>Security <\/em>panel in Developer Tools, along with fixes for two problematic bugs in macOS Sierra.<\/p>\n<h2>Improved Messaging In Developer Tools<\/h2>\n<p>Lots of useful information about a site\u2019s SSL configuration lives in the <em>Security <\/em>panel in Chrome\u2019s Developer Tools. This is where you must now go for any serious information after Chrome removed the <em>Connection <\/em>panel (which was accessible by clicking the lock icon in the address bar) a few versions ago.<\/p>\n<p>With the release of Chrome 54, the Security panel now provides additional information about bad SSL configurations, giving server admins a helping hand to improve their site\u2019s SSL security.<\/p>\n<p>The Security panel will specifically call out weak ciphers and blocked mixed content in grey <em>info bullets<\/em>, as seen in the screenshot below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3129\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/10\/Chrome54.png\" alt=\"Chrome 54\" width=\"837\" height=\"685\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/10\/Chrome54.png 837w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/10\/Chrome54-300x246.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/10\/Chrome54-768x629.png 768w\" sizes=\"auto, (max-width: 837px) 100vw, 837px\" \/><\/p>\n<p>Another small, but helpful improvement has been made to the full-page interstitial errors that appear for major problems with a site\u2019s SSL configuration (expired certificate, obsolete protocol, etc). A \u201cLearn More\u201d link to a support page about how to \u201c<a href=\"https:\/\/support.google.com\/chrome\/answer\/6098869\">Fix connection errors<\/a>\u201d has <a href=\"https:\/\/chromium.googlesource.com\/chromium\/src\/+\/911ba12253b14bfe874a321c57031f5ac534ce31\" rel=\"nofollow\">been added to these Interstitial error pages<\/a> to provide a bit more context to people who encounter them.<\/p>\n<h2>Certificate Chain Fetching Bug Fixed In Sierra<\/h2>\n<p>Google Chrome has a functionality known as <a href=\"https:\/\/www.thesslstore.com\/blog\/aia-fetching\/\">AIA fetching<\/a> to retrieve the needed intermediate certificates when a server has not been properly configured to provide them. This allows Chrome to successfully make an HTTPS connection to a site and avoids a \u201cYour connection is not private\u201d interstitial error.<\/p>\n<p>Changes to OS functions in macOS X Sierra broke this functionality, causing a <a href=\"https:\/\/bugs.chromium.org\/p\/chromium\/issues\/detail?id=645629#c25\" rel=\"nofollow\">four-fold increase<\/a> in errors related to missing\/incorrect certificate chains.<\/p>\n<p>Chrome 54 for Mac ships with <a href=\"https:\/\/bugs.chromium.org\/p\/chromium\/issues\/detail?id=645629\" rel=\"nofollow\">a fix for this bug<\/a> that restores AIA fetching. Chrome\u2019s team refers to this as a \u201chack\u201d because it will introduce some performance penalties and they are still looking for a proper solution.<\/p>\n<h2>New Certificate Transparency Logs<\/h2>\n<p>Certificate Transparency allows Certificate Authorities (CAs) to publically log certificates, providing proof of their issuance and allowing third-parties to audit their activity. In just a few short years Certificate Transparency has become one of the most important tools for strengthening the CA model and closing the gap on CA malfeasance.<\/p>\n<p>As a technical mechanism, Certificate Transparency is quite complex. It is important to have a variety of \u201clogs\u201d where certificates can be publicly recorded in order to insure the accuracy, reliability, and diversity of the system.<\/p>\n<p>In Chrome 54 <a href=\"https:\/\/www.certificate-transparency.org\/known-logs\">two new logs have been approved<\/a>, and are now accepted as valid sources for CT information. These logs are operated by <a href=\"https:\/\/bugs.chromium.org\/p\/chromium\/issues\/detail?id=605415#c2\" rel=\"nofollow\">WoSign<\/a> and <a href=\"https:\/\/bugs.chromium.org\/p\/chromium\/issues\/detail?id=611672\" rel=\"nofollow\">StartCom<\/a>, and both are public logs that will provide free logging of any certificates issued from roots in Mozilla\u2019s CA Program. These two join a short list of internationally hosted logs.<\/p>\n<p>These logs are also now indexed by <a href=\"https:\/\/crt.sh\/\" rel=\"nofollow\">crt.sh<\/a>, a Certificate Transparency search engine operated by Comodo.<\/p>\n<h2>Post-Quantum Cipher Support<\/h2>\n<p>CECPQ1 is Google\u2019s first attempt at designing a <a href=\"https:\/\/www.thesslstore.com\/blog\/cipher-suites-algorithms-security-settings\/\">cipher suite<\/a> that is resistant to quantum computing. Google originally launched this cipher a few months ago in Canary, and has now enabled it in a select number of clients in the <a href=\"https:\/\/www.chromestatus.com\/feature\/5749214348836864\" rel=\"nofollow\">stable release of Chrome 54<\/a>.<\/p>\n<p>This is primarily a research experiment that is collecting real world data for future cipher designs. Unless you are looking out for it, you will likely never notice its existence.<\/p>\n<p>Only a few websites are configured to use this cipher. If you want to see if your client has support enabled, visit <a href=\"https:\/\/www.play.google.com\" rel=\"nofollow\">play.google.com<\/a> and look for \u201cCECPQ1\u201d listed as the Key Exchange method.<\/p>\n<h2>Certificate Viewer Bug Fixed in Sierra<\/h2>\n<p>Sierra has another bug, this one affecting the OS\u2019 Certificate Viewer Window where you can view the certificate\u2019s details. It currently has a bug where the Window\u2019s height is set higher than the screen height and it cannot be used.<\/p>\n<p>Chrome has another \u201chack\u201d fix for this one that should restore functionality while a more permanent solution is sought.<\/p>\n<h2>HTTP\/0.9 Disabled Over Non-Default Ports<\/h2>\n<p>At this point, HTTP\/0.9 is absolutely ancient. While the internet is busy migrating to HTTP\/2, there are still some legacy and consumer networking devices holding onto the past.<\/p>\n<p>In order to encourage a timely move away from HTTP\/0.9, and also reduce compatibility issues some users are experiencing, HTTP\/0.9 will only work over default ports (80 and 443) in Chrome 54.<\/p>\n<p>Chrome plans on removing support for HTTP\/0.9 altogether within a few versions.<\/p>\n<h2>Wrap Up<\/h2>\n<p>That\u2019s is for Chrome 54! Lots of small changes this release.<\/p>\n<p>If Chrome Canary is an accurate indicator, we will see some bigger changes coming in Chrome 55\/56 \u2013 including the addition of a \u201cSecure\u201d indicator next to HTTPS sites, <a href=\"https:\/\/www.thesslstore.com\/blog\/google-chrome-security-indicators\/\">which Google designed based on new user research conducted earlier this year<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chrome 54 Features Better Messaging For Server Admins. Google Chrome 54 released last week, and like every new version of Chrome, there have been some changes to Chrome\u2019s SSL\/TLS and&#8230;<\/p>\n","protected":false},"author":2,"featured_media":3130,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[243,244,131,245,136,161],"class_list":["post-3128","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-browser-watch","tag-chrome-54","tag-google","tag-macos-sierra","tag-ssl","tag-tls","post-with-tags"],"views":9955,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/10\/iStock_83614541_MEDIUM.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3128","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=3128"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3128\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/3130"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=3128"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=3128"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=3128"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}