• April 25, 2024, 02:21:59 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: Java certificate revoked problem on v2.20b01 firmware  (Read 9478 times)

tiredcam

  • Guest
Java certificate revoked problem on v2.20b01 firmware
« on: September 26, 2015, 03:58:36 AM »

I was asking about the validity of the 2.20b01 firmware a while back and FurryNutz very kindly answered me.

I finally got around to updating the firmware and discovered to my horror that I can no longer access live video nor playback via my browser (Firefox, latest version). Java reports a certificate revocation that I am unable to get around unless I disable certificate checking which is not acceptable to me. Nothing changed on my desktop prior to the firmware update and I was able to access live video and playback just immediately before making the update. I am also running the latest version of Java.

Poking around online further, I came across this article from a Dutch site, dated 17 Sep 15 that claims that D-Link accidentally released private keys for signing certificates:

http://tweakers.net/nieuws/105137/d-link-blundert-met-vrijgeven-privesleutels-van-certificaten.html

Google translate to English of the site above here:

https://translate.google.com/translate?sl=nl&tl=en&js=y&prev=_t&hl=nl&ie=UTF-8&u=http%3A%2F%2Ftweakers.net%2Fnieuws%2F105137%2Fd-link-blundert-met-vrijgeven-privesleutels-van-certificaten.html&edit-text=&act=url

Can anyone advise on the certificate revocation issue I am facing and/or comment on the alleged certificate blunder by D-link?
Logged

philphil61

  • Level 3 Member
  • ***
  • Posts: 256
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #1 on: September 26, 2015, 05:00:11 AM »

I was asking about the validity of the 2.20b01 firmware a while back and FurryNutz very kindly answered me.

I finally got around to updating the firmware and discovered to my horror that I can no longer access live video nor playback via my browser (Firefox, latest version). Java reports a certificate revocation that I am unable to get around unless I disable certificate checking which is not acceptable to me. Nothing changed on my desktop prior to the firmware update and I was able to access live video and playback just immediately before making the update. I am also running the latest version of Java.

Poking around online further, I came across this article from a Dutch site, dated 17 Sep 15 that claims that D-Link accidentally released private keys for signing certificates:

http://tweakers.net/nieuws/105137/d-link-blundert-met-vrijgeven-privesleutels-van-certificaten.html

Google translate to English of the site above here:

https://translate.google.com/translate?sl=nl&tl=en&js=y&prev=_t&hl=nl&ie=UTF-8&u=http%3A%2F%2Ftweakers.net%2Fnieuws%2F105137%2Fd-link-blundert-met-vrijgeven-privesleutels-van-certificaten.html&edit-text=&act=url

Can anyone advise on the certificate revocation issue I am facing and/or comment on the alleged certificate blunder by D-link?

This might help

http://forums.dlink.com/index.php?topic=56962.msg259581#msg259581
Logged

tiredcam

  • Guest
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #2 on: September 27, 2015, 07:59:19 PM »

This might help

http://forums.dlink.com/index.php?topic=56962.msg259581#msg259581

The post and links from it suggests either disabling Java's certificate checking function or using Dlink's cloud service. I am sure everyone will agree fiddling with Java's security settings is not a good idea and given Dlink's spotty security history, I am not sure making my camera feeds available on cloud is a good idea.
Logged

philphil61

  • Level 3 Member
  • ***
  • Posts: 256
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #3 on: September 28, 2015, 04:41:09 AM »

This might help

http://forums.dlink.com/index.php?topic=56962.msg259581#msg259581

The post and links from it suggests either disabling Java's certificate checking function or using Dlink's cloud service. I am sure everyone will agree fiddling with Java's security settings is not a good idea and given Dlink's spotty security history, I am not sure making my camera feeds available on cloud is a good idea.

see my comment here  http://forums.dlink.com/index.php?topic=56962.msg259643#msg259643
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #4 on: September 29, 2015, 09:55:37 AM »

This issue is two fold. D-Link is aware of the Java issue and is working on getting it fixed.  Also Java mfr is also included in this so they also need to update there software as well.

I also noticed a Java update this morning. Not sure if this has any fixes or not.

Please be patient.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

NDLBox

  • Level 1 Member
  • *
  • Posts: 6
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #5 on: September 29, 2015, 10:38:56 AM »

I got new 942L and could not run the setup wizard I downloaded this morning because of the cert revocation.  I re-downloaded a few hours later and it ran no issue, looks like they reposted installers that were resigned this past Saturday with new certs, even though they did not update the version numbers or dates on the website.  So hopefully they are slowly working through all their software and firmware and recompiling with the new certs.
« Last Edit: September 29, 2015, 10:41:48 AM by NDLBox »
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #6 on: September 29, 2015, 11:03:16 AM »

Thanks for sharing your experience. Fix is in the works.  ;)
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

NDLBox

  • Level 1 Member
  • *
  • Posts: 6
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #7 on: October 13, 2015, 06:50:31 AM »

Any updates from DLink?  The site still shows 8/11/2015 on all the firmware, but based on my experience with some of the cameras, that isn't necessarily accurate.  At least I found a work-around, you can to use the desktop playback software... but annoying I can't get the live-view.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #8 on: October 13, 2015, 07:34:10 AM »

Nothing as of yet.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

NDLBox

  • Level 1 Member
  • *
  • Posts: 6
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #9 on: October 20, 2015, 10:33:16 AM »

They released a new firmware on the 16th.  Notes say includes new cert.  upgrading now.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #10 on: October 20, 2015, 10:55:41 AM »

Let us know how it turns out.  :)
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

NDLBox

  • Level 1 Member
  • *
  • Posts: 6
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #11 on: October 21, 2015, 10:36:56 AM »

It resolved the certificate issue, live view and playback work again - though it doesn't seem to save the display preferences like it used to.
Still having the strange issue of it overwriting the settings on one particular camera noted below.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #12 on: October 21, 2015, 10:38:44 AM »

Glad it's working now. Thank you for sharing this info.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

renus

  • Level 1 Member
  • *
  • Posts: 4
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #13 on: November 12, 2015, 01:19:47 AM »

I worked around the issue by installing and older version of Java. Version Java 7 update 55. I have not tried newer to test if it works but I am now able to see live view, motion detection grid or anything related to Java.
Some IP Cameras donīt have a firmware update to solve this problem. I think.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Java certificate revoked problem on v2.20b01 firmware
« Reply #14 on: November 12, 2015, 07:58:18 AM »

Thank you for the information. D-Link is aware of these issues and is working hard to resolve them. I presume that the next FW update will resolve this and users should be able to use the most current Java software or plug-in available. Please be patient while they work on getting it resolved. If users are needed immediate help and information, I recommend that you phone contact your regional D-Link support office and ask for help and information regarding this. We find that phone contact has better immediate results over using email.
Let us know how it goes please.

I worked around the issue by installing and older version of Java. Version Java 7 update 55. I have not tried newer to test if it works but I am now able to see live view, motion detection grid or anything related to Java.
Some IP Cameras donīt have a firmware update to solve this problem. I think.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.