duplicate root certificates, some in sha-1

Google Chrome is labeling many websites I visit as insecure, due to sha-1 certificates.


The problem isn't with the site, it's that i've got sha-1 versions of root certificates on my system keychain.


Is anyone else seeing this?



Here are related actions for this computer:


  • Open new 12" macbook running 10.10.3
  • login using apple id, enable keychain sync
  • install 10.11 dev preview

I am seeing something similar with our corporate root certs.

Safari will not take me to an internal site because it's unsecure, Chrome lets me go but calls it out as insecure as well.

10.11 beta 2


where as 10.10.4 beta is not having this issue.


any update on this?

having the same issue, seems like only chrome is warning against sha-1, firefox and safari seems fine with a sha-1 encryption of root certificates. My guess the fix: Apple should issue sha-256 encrypted root certificates.

duplicate root certificates, some in sha-1
 
 
Q