HTTPS not working with Konqueror 3.5.8

Bug #152449 reported by Tvrtko Ursulin
260
Affects Status Importance Assigned to Milestone
KDE PIM
Fix Released
Medium
kdebase (Ubuntu)
Fix Released
Undecided
Daniel Hahler

Bug Description

I've noticed today that with Konqueror 3.5.8 HTTPS sites are not working properly. URL bar does show https:// prefix, but the padlock icon is missing and View->Security reports the connection are not SSL secured.

I think that is also the reason I couldn't file this bug report from Konqueror but had to use Firefox.

Unfortunately I don't know when this bug appeared - I am updating ot latest Gutsy stuff on a daily basis and as I noticed there was a big KDE update recently I am inclined to associate it with that. But as I said - I am not sure about it.

I'll attach two screenshots which show the behavior. As far as I can tell it happens on all HTTS sites.

Related branches

Revision history for this message
Tvrtko Ursulin (tvrtko) wrote :

This is when I go to paypal.com for the first time and SSL security works.

Revision history for this message
Tvrtko Ursulin (tvrtko) wrote :

And then when I click on 'Log in' SSL security turns off.

Revision history for this message
Daniel Hahler (blueyed) wrote :

Cannot confirm. https://www.paypal.com/ works correctly in Konqueror (3.5.8-0ubuntu2 - from today).
Please install the latest updates.
If it still occurs, please try starting Konqueror from a terminal, e.g. "Konsole" and see if there's any output, which may indicate what fails exactly.
Is this a cosmetic problem? Can't you access e.g. https://launchpad.net/ at all?

Revision history for this message
Tvrtko Ursulin (tvrtko) wrote :

It's the same for me with the latest updates. I am attaching two new screenshots. First one is when I open the URL directly, and the second one when I get to in steps. Only the first page I visit is then secured with SSL.

There are no error messages in the konsole from where I started konqueror.

When submitting this bug report initially launchpad.net gave me an error when I tried to submit it which I suspected might be related with the SSL problem.

I'll try removing ~/.kde ie. trying with a clean user because my $HOME is inherited from 7.04 later today.

Revision history for this message
Tvrtko Ursulin (tvrtko) wrote :
Revision history for this message
Pete (pete123) wrote :

I would like to add this is also a problem for me, but it seems to be cosmetic. Logon's etc work, but there is no indication that the connection is secured, bar the HTTPS in the URL. However, it seems if you open the link to a HTTPS page in a new tab or window, you receive the usual yellow address bar, padlock etc. It only seems to occur if the link is followed in the current tab.

However, it could be quite confusing for people to be logging onto banks etc with Konqueror but to not receive the usual indications that its actually a secure connection.

I include an image showing that the connection is apparently unsecured (as others), although see the URL.

Revision history for this message
Pete (pete123) wrote :

Tvrtko Ursulin Said: "I'll try removing ~/.kde ie. trying with a clean user because my $HOME is inherited from 7.04 later today."

I created a new user for testing (home is inherited from Feisty also) and the problem still exists with the default kde configuration.

Revision history for this message
Pete (pete123) wrote :

Sorry for the repeat posts, just some more clarification. If a https site is visited in a new Konqueror session, this bug does not occur. HTTPS from bookmarks also work as expected.

It appears the data is actually encrypted after inspection with wireshark, so its a cosmetic problem. However, this could be quite a problem as users who are unaware that the data is actually encrypted, when they usually expect the padlocks and yellow address bar to indicate this!

Revision history for this message
Pete (pete123) wrote :

Here is a simple way to reproduce, visit http://www.ubuntu.com/community/participate/TechnicalUsers and click on the link 'Report Bugs'. This is not a particularly obscure bug considering almost all people visiting https sites will be linked to them (eg to account login pages).

Revision history for this message
Jonathan Riddell (jr) wrote :

Confirmed

Changed in kdebase:
status: Incomplete → Confirmed
Revision history for this message
Scott Kitterman (kitterman) wrote :

Up to date Gutsy system with kdelibs-data (4:3.5.8-0ubuntu2) and kdelibs4c2a (4:3.5.8-0ubuntu2) I cannot replicate this problem.

Revision history for this message
Jonathan Riddell (jr) wrote :

fixed in 3.5.8-0ubuntu2

Changed in kdebase:
status: Confirmed → Fix Released
Changed in kdepim:
status: Unknown → Confirmed
Changed in kdepim:
status: Confirmed → Fix Released
Changed in kdepim:
importance: Unknown → Medium
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.