Fix slowness, crashing, error messages and other problems - How to troubleshoot the error code "SEC_ERROR_UNKNOWN_ISSUER" on secure websites in Firefox

On websites which are supposed to be secure (the URL begins with "https://"), Firefox must verify that the certificate presented by the website is valid. If the certificate cannot be validated, Firefox will stop the connection to the website and show a "Your connection is not secure" error message instead. This article explains why you might see the error code "SEC_ERROR_UNKNOWN_ISSUER" on websites and how to troubleshoot it.

What does this error code mean?

During a secure connection a website needs to provide a certificate issued by a trusted certificate authority in order to ensure that the user is connected to the intended target and the connection is encrypted. If you get a "Your connection is not secure" error page and see the error code "SEC_ERROR_UNKNOWN_ISSUER" after you click on Advanced, it means that the certificate provided was issued by a certificate authority that is not known by Firefox and therefore cannot be trusted by default.
Fx44 SEC_ERROR_UNKNOWN_ISSUER error
Warning: You should never add a certificate exception for a legitimate major website or sites where financial transactions take place – in this case an invalid certificate can be an indication that your connection is compromised by a third party.

The error occurs on multiple secure sites

In case you get this problem on multiple unrelated HTTPS-sites, it indicates that something on your system or network is intercepting your connection and injecting certificates in a way that is not trusted by Firefox. The most common causes are security software scanning encrypted connections or malware listening in, replacing legitimate website certificates with their own.

Antivirus Products

Generally, if your security product contains a feature to scan encrypted connections, you could try to reinstall the security product, which might trigger the software to place its certificates into the Firefox trust store again. Try the following solutions for particular security products:

Avast

In Avast security products you can disable the interception of secure connections:
  1. Open the dashboard of your Avast application.
  2. Go to Settings > Active Protection and click Customize next to Web Shield.
  3. Uncheck the Enable HTTPS Scanning setting and confirm this by clicking OK.
More Information about this feature is available on this Avast Blog.

Bitdefender

In Bitdefender security products you can disable the interception of secure connections:
  1. Open the dashboard of your Bitdefender application.
  2. For the 2016 version of the Bitdefender security product, click on Modules.
    For the 2015 version of Bitdefender, click on Protection.
  3. Click on Web Protection.
  4. Toggle off the Scan SSL setting.
For corporate Bitdefender products, please refer to this Bitdefender Support Center page.

Bullguard

In Bullguard security products you can disable the interception of secure connections on particular major websites like Google, Yahoo and Facebook:
  1. Open the dashboard of your Bullguard application.
  2. Click on Antivirus settings > Browsing.
  3. Uncheck the Show safe results option for those websites which are showing an error message.

ESET

In ESET security products you can try to disable and re-enable SSL/TLS protocol filtering or generally disable the interception of secure connections as described in ESET’s support article.

Kaspersky

In Kaspersky security products you can disable the interception of secure connections:
  1. Open the dashboard of your Kaspersky application.
  2. Click on Settings on the bottom-left.
  3. Click Additional and then Network.
  4. If you use a 2016 version of Kaspersky: In the Encrypted connections scanning section check the Do not scan encrypted connections option and confirm this change.
    Alternatively you can click on Advanced Settings in order to try to trigger a reinstallation of Kaspersky's certificate. In the dialog that opens click on Install certificate… and follow the on-screen instructions.
    If you use a 2015 version of Kaspersky: uncheck the Scan encrypted connections option.

Family Safety settings in Windows accounts

In Microsoft Windows accounts protected by Family Safety settings, secure connections on popular websites like Google, Facebook and YouTube might be intercepted and their certificates replaced by a certificate issued by Microsoft in order to filter and record search activity.
Read this Microsoft FAQ page on how to turn off these family features for accounts. In case you want to manually install the missing certificates for affected accounts, you can refer to this Microsoft support article.

Monitoring/Filtering in corporate networks

Some traffic monitoring/filtering products used in corporate environments might intercept encrypted connections by replacing a website's certificate with their own, at the same time possibly triggering errors on secure HTTPS-sites. If you suspect this might be the case, please contact your IT department to ensure the correct configuration of Firefox to enable it working properly in such an environment.

Malware

Some forms of malware intercepting encrypted web traffic can cause this error message - refer to the article Troubleshoot Firefox issues caused by malware on how to deal with malware problems.

The error occurs on one particular site only

In case you get this problem on one particular site only, this type of error indicates that the web server is not configured properly: The website's certificate might not have been issued by a trusted certificate authority itself and no complete certificate chain to a trusted authority was provided either (a so-called "intermediate certificate" is missing). You should contact the owner of the website and inform him of the error.
If the website allows it, you can add an exception in order to visit the site, in spite its certificate is not being trusted by default:
  1. On the warning page, click Advanced.
  2. Click Add Exception…. The Add Security Exception dialog will appear.
  3. Read the text describing the problems with the website. You can click View… in order to closer inspect the untrusted certificate as well.
  4. Click Confirm Security Exception if you are sure you want to trust the site. 
Next PostNewer Post Previous PostOlder Post Home

2 comments:

  1. There can be other issues that a user can face while dealing with Bitdefender. To enjoy the complete services of Bitdefender 360, one needs to enter the Bitdefender Product Security Key. The software may not always accept the Bitdefender Activation Code. In such cases, there can be a problem with the version chosen by the user. Furthermore, there may be installation errors in some cases, which can cause problems. In such cases, the user must not panic and immediately contact our Bitdefender Antivirus support. If you need any help regarding setup and installation for bitdefender antivirus. Directly call our expert technician @ +1- 844-636-0656 or Visit our website 800pcare.com for more details.
    Visit: http://800pcare.com/Bitdefender_Internet_Security.php

    ReplyDelete
  2. Yes correct. sorry for delayed reply

    ReplyDelete

Post your experience here.your valuable comments are welcome by us