Chrome 57 blocking all Google sites due to SHA1 policy

Hello support,

Chrome 57 - preventing all Google sites from opening due to sha1 certificate issue.

On my machine running Chrome 57,  Linux Ubuntu 14.04 64bits when I open any Google site  - the cert chain used is the following.  Detected using a packet analytics tool.

/C=US/ST=California/L=Mountain View/O=Google Inc/CN=*.google.com
  C=US, O=Google Inc, CN=Google Internet Authority G2
/C=US/O=Google Inc/CN=Google Internet Authority G2
  C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA
  C=US, O=Equifax, OU=Equifax Secure Certificate Authority

You can see that the last cert in the chain Issued by Equifax to GeoTrust uses sha1, I suppose that is the reason for the block.

on a colleagues machine GeoTrust is treated as the root and not Equifax and hence he is able to go online.

I also tried the following.

1. Tried setting EnableSha1ForLocalAnchors = true and restarting the Chrome processes and machine but no luck.

2. Tried importing the GeoTrust as the root CA ; failed because it already exists.

Any ideas how I can resolve this.


Vivek Rajagopal

Hi Vivek,

Following are some issues for you to review:
  1. The *.google.com certificate is rooted by GeoTrust Global CA.  If you show otherwise, perhaps you have some bad certs cached?  Try clear all your cert caches.
  2. If visiting secure HTTPS websites on Linux Chrome produces error ERR_CERT_WEAK_SIGNATURE_ALGORITHM, please check if the fix that works on Debian also solves the problem for you:  https://productforums.google.com/d/msg/chrome/oG8tEdIfYuA/aH1s9STYBgAJ
    # apt-get install libnss3-1d

In Chrome57 if Google sites arent working any more due to SHA1 signing block

1.  Open Settings -> Advanced  -> HTTS/SSL -> Manage Certificates
2, Go to Authorities Tab 
3. Scroll down the list and find "Equifax Secure CA" - then press "Edit.."
4. Uncheck all the boxes (Basically Dont Trust this CA )
5. Close everything 

Now it works !

Thanks for the help. 

I tried those things. Untrusting Equifax did the trick for me. See my update.

Thanks again
