Announcement

Collapse
No announcement yet.

128-bit encryption "issue"

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    128-bit encryption "issue"

    Looking for some help here. Running Firefox Developer Edition (35.0a2 (2014-11-10) on both my 32- and 64-bit Utopic's. I have one government web site that refuses to allow me to log in with my CaC, returning:

    Server Error

    403 - Forbidden: Access is denied.

    You do not have permission to view this directory or page using the credentials that you supplied.




    My other Government web sites have no issues.

    The site that is giving me issues is the myPay Web Site. Their FAQ says:

    1) Which browsers can I use to access this site?
    • [*=left]
      Browsers Supported by myPay:
      Browsers Blocked from accessing myPay:
      Browsers Which May Be Used to Access myPay, But for Which No Support Will be Provided by myPay:
      • Internet Explorer version 6.0 or later on Windows
      • Internet Explorer before version 5.0 on ALL Operating Systems
      • All browsers without 128-bit encryption on ALL Operating Systems
      • Netscape
      • All other 128-bit encryption browsers not in the supported or blocked groups above may be used to access myPay. However, no support will be provided by myPay if there are problems with the browser interacting with myPay.



    My ssl settings in Firefox Developer Edition (about:config search on ssl)
    Click image for larger version

Name:	SSLSettings.png
Views:	1
Size:	79.0 KB
ID:	648798

    Report of the browsers capabilities from https://www.opm.gov/e-QIP/browser-check.asp
    Click image for larger version

Name:	128-bitSupportIssue.jpg
Views:	1
Size:	87.0 KB
ID:	648799

    What must I do so that the browsers 128-bit encryption, which it does support, is properly reported?
    Windows no longer obstructs my view.
    Using Kubuntu Linux since March 23, 2007.
    "It is a capital mistake to theorize before one has data." - Sherlock Holmes

    #2
    Have you tried changing the useragent string?

    Seems there are a lot of people/browsers for whom there are problems involving this. The check shows the same result with me, using the stable firefox 33, but using a user-agent switcher to make it IE 8 gets rid of the warning.


    A quick dive seems to indicate that e-qip is looking for a no-longer used "U" in the user agent string to identify the capability, or rather no longer needed marker and long since removed from FF
    http://en.wikipedia.org/wiki/User_ag...ngth_notations

    Comment


      #3
      Doesn't make a difference.
      Windows no longer obstructs my view.
      Using Kubuntu Linux since March 23, 2007.
      "It is a capital mistake to theorize before one has data." - Sherlock Holmes

      Comment


        #4
        Hmmm I wonder if you may have to update or import any certs for this? I vaguely recall stumbling across info on Linux and CAC logins on DoD sites somewhere. It involved importing certs, I think. I wonder if that explains the specific 403 error?

        Sent from my Verizon HTC Droid DNA Android smartphone running ViperRom Kit Kat, using Tapatalk, like all that really matters

        Comment


          #5
          I don't think so. I have the proper DoD certificates installed and I can log in to:

          Army Knowledge Online (AKO)
          Defense Travel System (DTS)

          Not sure why myPay won't permit me to log in with my CAC when the other two will.
          Windows no longer obstructs my view.
          Using Kubuntu Linux since March 23, 2007.
          "It is a capital mistake to theorize before one has data." - Sherlock Holmes

          Comment


            #6
            Paul,

            I was curious so I googled it, and the answers to this mozilla support question indicated that it is a problem with the user agent string.

            I've just tried the test with my user agent set to Windows / IE10 (chosen pretty much at random) and the test showed no issues.

            I had trouble actually changing my user agent string with the first addon I tried (this one) but the second one I tried worked fine.

            I took a snapshot but I can't upload it as an attachment for some reason (endless progress wheel).
            samhobbs.co.uk

            Comment


              #7
              Thank you, but I already tried User Agent Overrider; it didn't help.
              Windows no longer obstructs my view.
              Using Kubuntu Linux since March 23, 2007.
              "It is a capital mistake to theorize before one has data." - Sherlock Holmes

              Comment


                #8
                That's weird, which user agent did you try?

                I found this other addon quite useful for checking that my user agent had actually been changed:

                https://addons.mozilla.org/en-US/fir...-http-headers/

                I wonder if it's something different in the developer edition, I'm using the standard ed.



                ^ my image isn't showing, but it's here:

                https://samhobbs.co.uk/sites/default...patibility.png
                Last edited by Feathers McGraw; Nov 16, 2014, 02:23 PM.
                samhobbs.co.uk

                Comment


                  #9
                  The browser check page is using the user-agent string to (falsely) determine available encryption, however, the actual mypay site is where the problem lies, which is why I wondered about certs. There is a lot Google hits, and even websites for helping with this, primarily for cac cards though.

                  I don't remember how or why I remember coming across this info, but I found militarycac.com and other places. Maybe something useful there.



                  Sent from my Verizon HTC Droid DNA Android smartphone running LiquidSmooth Rom, with Kit Kat 4.4.4, via Tapatalk, as if phone stats ready matter

                  Comment


                    #10
                    I think it must be something on the myPay site and the way it polls for credentials. Sometimes I'll be prompted for my CAC pin, but then doesn't prompt for which certificate on the card to use (and I have more than one on the CAC). The other sites behave normally; ask for my CAC pin and then display the certificates on the CAC for me to choose from.
                    Windows no longer obstructs my view.
                    Using Kubuntu Linux since March 23, 2007.
                    "It is a capital mistake to theorize before one has data." - Sherlock Holmes

                    Comment


                      #11
                      Sheesh, if they're using the user agent to determine encryption strength, they're doing it wrong! As you've seen here, agents can be spoofed. They're useless as reliable mechanisms for anything.

                      OWASP has some information on how to correctly determine a browser's cipher suite capability. And Qualys has a page that will give you correct answers. The e-QIP folks need some edumacashun, obviously.

                      Comment

                      Working...
                      X