1. irra7ional's Avatar
    Hey guys,

    I have been running into more and more sites that I give me the dreaded red stop because of not trusted certificate.

    The thing is I can't figure how to white list them. Show more on these sites does nothing and there seems to be no way to add an exception.

    Help is much appreciated!

    Posted via CB10
    05-25-17 11:27 AM
  2. Bla1ze's Avatar
    05-25-17 11:51 AM
  3. thurask's Avatar
    If it's Let's Encrypt certificates causing trouble, and you're on 10.3.2 (or prior), yeah, install MultiCERT. Installing 10.3.3 also adds Let's Encrypt support.
    05-25-17 02:00 PM
  4. Richard Buckley's Avatar
    The only sites I haven't been able to white list are for pretty serious reasons. Strict transport security turned on and the certificate is for the wrong site, revoked certificates, and others. If the issue is that BlackBerry doesn't have the CA certificates for the sites you need it is quite easy to get them from the CA's site and install them.

    LeapSTR100-2/10.3.3.2205
    05-25-17 03:52 PM
  5. irra7ional's Avatar
    Ty guys the issue was indeed Let's Encrypt certificates

    You guys are life savers :-) 10.3.3 is not available in my country yet

    Posted via CB10
    05-26-17 03:25 AM
  6. dbq10's Avatar
    MultiCERT couldn't fix my sites. I'm having issues with Amazon certificates; someone commented on another site that Amazon got into the CA business in 2015. I will have to go to 10.3.3 and hope for the best.
    05-26-17 09:17 AM
  7. bb10adopter111's Avatar
    Feel free to post the problematic URLs and those of us on 10.3.3 can tell you if there are issues.

    Posted with my trusty Z10
    05-27-17 02:36 PM
  8. dbq10's Avatar
    10.3.3 can't resolve the problem with Starfield Services root certificates provided by Amazon for online retailers. Since the sites aren't blocked on my Android 5.0 tablet I'd say it's just a BlackBerry problem.
    06-12-17 12:44 PM
  9. Richard Buckley's Avatar
    10.3.3 can't resolve the problem with Starfield Services root certificates provided by Amazon for online retailers. Since the sites aren't blocked on my Android 5.0 tablet I'd say it's just a BlackBerry problem.
    If you post the URL that is giving you a problem maybe someone could help.

    LeapSTR100-2/10.3.3.2205
    06-12-17 04:37 PM
  10. dbq10's Avatar
    Hi Richard, try this respectable but blocked news site:
    Sciencedaily.com
    I have the valid, up to date certificates but I'm only blocked using my Passports (10.3.2 & 10.3.3) My best non-engineer guess is that since Amazon has been providing certs for just the last two years they figured BlackBerry was either out of the picture or so marginal that it wasn't worth testing for compatibility.
    06-13-17 10:03 AM
  11. thurask's Avatar
    This is what it looks like on an Android device:
    06-13-17 10:09 AM
  12. bb10adopter111's Avatar
    Hi Richard, try this respectable but blocked news site:
    Sciencedaily.com
    I have the valid, up to date certificates but I'm only blocked using my Passports (10.3.2 & 10.3.3) My best non-engineer guess is that since Amazon has been providing certs for just the last two years they figured BlackBerry was either out of the picture or so marginal that it wasn't worth testing for compatibility.
    I have no problem with that site on my Z10 running 10.3.3 with the native browser.


    Posted with my trusty Z10
    06-13-17 10:24 AM
  13. Vistaus's Avatar
    That site works fine on my Passport with 10.3.3



    Posted via CB10 using my amazing  Passport (OG Red)
    06-13-17 04:20 PM
  14. oystersourced's Avatar
    Hi Richard, try this respectable but blocked news site:
    Sciencedaily.com
    I have the valid, up to date certificates but I'm only blocked using my Passports (10.3.2 & 10.3.3) My best non-engineer guess is that since Amazon has been providing certs for just the last two years they figured BlackBerry was either out of the picture or so marginal that it wasn't worth testing for compatibility.
    BlackBerry 10.3.2 didn't have the Amazon CA certificates (whether that's because they are new, misused or untrusted is fairly irrelevant now if they have been added to 10.3.3), you can obtain them from their website if you wish and install them very simply (there is no need for third-party apps), a simple tap to open and BlackBerry 10 leads you the rest of the way.

    I'm running 10.3.2 and can access the website, just because you can add certificates from a CA doesn't equate to a website being trustworthy however.

    Posted via CB10
    Richard Buckley likes this.
    06-13-17 07:24 PM
  15. Richard Buckley's Avatar
    Hi Richard, try this respectable but blocked news site:
    Sciencedaily.com
    I have the valid, up to date certificates but I'm only blocked using my Passports (10.3.2 & 10.3.3) My best non-engineer guess is that since Amazon has been providing certs for just the last two years they figured BlackBerry was either out of the picture or so marginal that it wasn't worth testing for compatibility.
    Oystersourced has the solution. But I will mention that this is not only limited to versions but also decisions BlackBerry makes as to which CAs to include. BlackBerry has always shipped with fewer CAs that the popular browsers. But if you trust and need a particular CA they will always have their roots certificates available so that users can add them to their browsers.

    LeapSTR100-2/10.3.3.2205
    06-14-17 06:39 AM
  16. dbq10's Avatar
    Thanks for everyone's input. I think I may have older but un-expired Starfield Services certificates, and nothing showing up specifically as 'Amazon', even after running MultiCERT.
    I can't find any download information for Amazon certificates - does anyone have a link?
    06-15-17 12:00 PM
  17. thurask's Avatar
    I can't find any download information for Amazon certificates - does anyone have a link?
    https://www.amazontrust.com/repository/
    RichardHBB likes this.
    06-15-17 01:42 PM
  18. dbq10's Avatar
    I went to the above Amazontrust.com/repository site and didn't find any download options, just lots of legal documents regarding licensing and partners best practices, plus many lines of programing code; nothing there that I could interpret.
    06-17-17 02:57 PM
  19. thurask's Avatar
    I went to the above Amazontrust.com/repository site and didn't find any download options, just lots of legal documents regarding licensing and partners best practices, plus many lines of programing code; nothing there that I could interpret.
    Certification Authorities > Root CAs > Self-Signed Certificate > .cer or .pem format
    RichardHBB and Vladislavt like this.
    06-17-17 03:12 PM
  20. bb10adopter111's Avatar
    Why not just upgrade to 10.3.3, which includes the certs?

    Posted with my trusty Z10
    06-17-17 03:42 PM
  21. dbq10's Avatar
    I found the correct download path for all four Amazon certificates and now all of my sites are accessible again
    These are the download files, valid starting May 2015:
    www.awstrust.com/repository/amazonrootCA1.cer
    www.awstrust.com/repository/amazonrootCA2.cer
    www.awstrust.com/repository/amazonrootCA3.cer
    www.awstrust.com/repository/amazonrootCA4.cer

    ( I already had 10.3.3 on one of my Passports and was still missing these certs, and I prefer to keep the other Passport on 10.3.2, just because you never know when you might need it.)
    I found this info in a Mozilla foundation article, 1172401-Add Amazon root certificates
    https://bugzilla.mozilla.org/show_bug.cgi?id=1172401
    RichardHBB likes this.
    06-17-17 05:30 PM
  22. RichardHBB's Avatar
    I found the correct download path for all four Amazon certificates and now all of my sites are accessible again
    The above linked Amazon certificates are no longer valid links, but following Thurasks' post to simply download the root certificates from Amazon's page will get you the current files. I just got them and my previously blocked sites appear to be working.

    Richard
    04-25-18 08:18 PM
  23. dbq10's Avatar
    Thanks for the update. Do you have the link to the Amazon page?
    (My sites still work, fingers crossed.)
    04-26-18 10:41 AM
  24. RichardHBB's Avatar
    The same as in post #17 and #18 here. https://www.amazontrust.com/repository/

    You will need to download the "DER" files under "Root CAs", then click on them in the file manager to import the certificates. There are currently 5 there. It's a very easy process.

    Richard
    04-27-18 04:37 PM

Similar Threads

  1. Browser constantly crashes
    By TreDawg07 in forum BlackBerry Z30
    Replies: 30
    Last Post: 10-02-17, 06:26 PM
  2. April Security update killed my Priv
    By craig428 in forum BlackBerry Priv
    Replies: 10
    Last Post: 05-26-17, 07:02 AM
  3. Curious What how BlackBerry Browsers Show This Site
    By Richard Buckley in forum General BlackBerry News, Discussion & Rumors
    Replies: 6
    Last Post: 05-26-17, 05:36 AM
  4. Replies: 7
    Last Post: 05-24-17, 11:29 PM
  5. Keyboard Browser update brings Reader Mode and various bug fixes!
    By CrackBerry News in forum CrackBerry.com News Discussion & Contests
    Replies: 0
    Last Post: 05-23-17, 06:00 PM
LINK TO POST COPIED TO CLIPBOARD