Burp Suite User Forum

Create new post

Firefox and SEC_ERROR_REUSED_ISSUER_AND_SERIAL

Simon | Last updated: Jan 17, 2017 12:42PM UTC

Firefox 50.1.0, Mac OS X 10.12.2, Burp Suite 1.7.16 (from tarball, never got the hang of the mac package). I started receiving this for www.facebook.com requests whilst scanning a server that linked out to Facebook using the intercepting proxy. Tried various things, but ended up having to delete old CA, regenerate the CA Cert, importing it, and restarting firefox, and it is working again. Is this a "bug" or expected behaviour of the intercepting proxy and firefox combination, didn't seem to be many relevant hits on SEC_ERROR_REUSED_ISSUER_AND_SERIAL

PortSwigger Agent | Last updated: Jan 17, 2017 01:53PM UTC

Thanks for this report. We'll try to reproduce a case where Burp creates CA-signed certificates with duplicate serial numbers. If this problem recurs, then we believe simply restarting both Burp and the browser should resolve the issue.

PortSwigger Agent | Last updated: Feb 01, 2017 02:02PM UTC

Just to let you know that we have fixed this issue in today's release (1.7.17). Thanks again for your feedback, and please do let us know if you run into any other problems.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.