<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[SSL Error: smth wrong with Certificate Transparency policy]]></title><description><![CDATA[<p dir="auto">Today I found out that Opera no longer lets me to access <code>mail.ru</code>. However, in other browsers on my OS all works fine, so certificate is ok.<br />
"The server presented a certificate that was not publicly disclosed using the Certificate Transparency policy."<br />
But according to Certificate Transparency report (<a href="https://www.google.com/transparencyreport/https/ct/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.google.com/transparencyreport/https/ct/</a>) for this site - it's cert is listed, so it should be trusted by opera, but it doesn't.<br />
What could be the problem?</p>
]]></description><link>https://forums.opera.com/topic/18069/ssl-error-smth-wrong-with-certificate-transparency-policy</link><generator>RSS for Node</generator><lastBuildDate>Wed, 17 Jun 2026 23:30:48 GMT</lastBuildDate><atom:link href="https://forums.opera.com/topic/18069.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 13 Nov 2016 20:57:12 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to SSL Error: smth wrong with Certificate Transparency policy on Sat, 26 Nov 2016 09:59:42 GMT]]></title><description><![CDATA[<p dir="auto">And... here's a list of sites that hardcoded to use HSTS. Theoretically, all these sites should give the problem and not pull up. <a href="http://mail.ru" target="_blank" rel="noopener noreferrer nofollow ugc">mail.ru</a> and <a href="http://amazon.com" target="_blank" rel="noopener noreferrer nofollow ugc">amazon.com</a> are included</p>
]]></description><link>https://forums.opera.com/post/111075</link><guid isPermaLink="true">https://forums.opera.com/post/111075</guid><dc:creator><![CDATA[quaternium]]></dc:creator><pubDate>Sat, 26 Nov 2016 09:59:42 GMT</pubDate></item><item><title><![CDATA[Reply to SSL Error: smth wrong with Certificate Transparency policy on Sat, 26 Nov 2016 09:42:22 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">My only guess is that this has something to do with Opera's VPN feature, as I've been using the VPN when this notification was received. This is of concern to say the least, as it brings to mind SSL man-in-the-middle exploits.</p>
</blockquote>
<p dir="auto">MY NEXT GUESS: This appears to be an issue with HSTS (HTTP Strict Transport Security).<br />
From Wikipedia: "TTP Strict Transport Security (HSTS) is a web security policy mechanism which helps to protect websites against protocol downgrade attacks and cookie hijacking. It allows web servers to declare that web browsers (or other complying user agents) should only interact with it using secure HTTPS connections,[1] and never via the insecure HTTP protocol."</p>
<p dir="auto">It also seems that <em>some</em> users may tweak Opera settings regarding HSTS by going to opera://net-internals/#hsts I suppose by adding some sort of exception as per: <a href="http://classically.me/blogs/how-clear-hsts-settings-major-browsers" target="_blank" rel="noopener noreferrer nofollow ugc">http://classically.me/blogs/how-clear-hsts-settings-major-browsers</a> BUT...</p>
<p dir="auto">I get forwarded to a web search when I try to go to that blog post about clearing HSTS for specific domains, so perhaps it is a bug or only perhaps the customization page is available in other Opera versions, like the one for Windows? EDIT: Now all of a sudden the link chrome://net-internals/#hsts IS working for me</p>
<p dir="auto">Considering that the blog post was written in Feb 2014, it's strange that the issue would just be seen now, so I'm leaning towards bug.</p>
]]></description><link>https://forums.opera.com/post/111074</link><guid isPermaLink="true">https://forums.opera.com/post/111074</guid><dc:creator><![CDATA[quaternium]]></dc:creator><pubDate>Sat, 26 Nov 2016 09:42:22 GMT</pubDate></item><item><title><![CDATA[Reply to SSL Error: smth wrong with Certificate Transparency policy on Sat, 26 Nov 2016 09:03:03 GMT]]></title><description><![CDATA[<p dir="auto">My only guess is that this has something to do with Opera's VPN feature, as I've been using the VPN when this notification was received. This is of concern to say the least, as it brings to mind SSL man-in-the-middle exploits.</p>
]]></description><link>https://forums.opera.com/post/111073</link><guid isPermaLink="true">https://forums.opera.com/post/111073</guid><dc:creator><![CDATA[quaternium]]></dc:creator><pubDate>Sat, 26 Nov 2016 09:03:03 GMT</pubDate></item><item><title><![CDATA[Reply to SSL Error: smth wrong with Certificate Transparency policy on Fri, 18 Nov 2016 19:19:04 GMT]]></title><description><![CDATA[<p dir="auto">It does the same thing when I try to go to the Amazon website. A bug maybe?</p>
]]></description><link>https://forums.opera.com/post/110729</link><guid isPermaLink="true">https://forums.opera.com/post/110729</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Fri, 18 Nov 2016 19:19:04 GMT</pubDate></item><item><title><![CDATA[Reply to SSL Error: smth wrong with Certificate Transparency policy on Mon, 14 Nov 2016 14:14:01 GMT]]></title><description><![CDATA[<p dir="auto">I'm having the same issue with yahoo login <a href="https://login.yahoo.com" target="_blank" rel="noopener noreferrer nofollow ugc">https://login.yahoo.com</a>.  I can login using Firefox or Chrome but Opera generates the message "The server presented a certificate that was not publicly disclosed using the Certificate Transparency policy." and only lets me "Return to Safety".  As above the the certificate for <a href="http://login.yahoo.com" target="_blank" rel="noopener noreferrer nofollow ugc">login.yahoo.com</a> is listed</p>
]]></description><link>https://forums.opera.com/post/110505</link><guid isPermaLink="true">https://forums.opera.com/post/110505</guid><dc:creator><![CDATA[goginan]]></dc:creator><pubDate>Mon, 14 Nov 2016 14:14:01 GMT</pubDate></item></channel></rss>