For example, try https://www.cloudflarechallenge.com/ . This was deliberately revoked (after the Heartbleed challenge) to test brower behavior (http://blog.cloudflare.com/certificate-revocation-and-heartbleed). Firefox correctly blocks the user from visiting the site. Reproducible: Always Steps to Reproduce: 1. Visit a site with a revoked TLS certificate. Actual Results: It loads normally. Expected Results: It does not load, and notifies the user of the security problem.
Confirmed in 4.13.0 Not only that but there is no option to turn on such functionality.
This is an upstream issue. We use Qt's networking classes for SSL support and currently it does provide a means for checking certificate revokation. IOW, it does not yet support OCSP. See https://bugreports.qt-project.org/browse/QTBUG-12812.
Thank you for reporting this bug in KDE software. As it has been a while since this issue was reported, can we please ask you to see if you can reproduce the issue with a recent software version? If you can reproduce the issue, please change the status to "CONFIRMED" when replying. Thank you!
According to the upstream bug report that Dawit referenced the issue should be fixed since Qt 5.13.
Dear Bug Submitter, This bug has been in NEEDSINFO status with no change for at least 15 days. Please provide the requested information as soon as possible and set the bug status as REPORTED. Due to regular bug tracker maintenance, if the bug is still in NEEDSINFO status with no change in 30 days the bug will be closed as RESOLVED > WORKSFORME due to lack of needed information. For more information about our bug triaging procedures please read the wiki located here: https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging If you have already provided the requested information, please mark the bug as REPORTED so that the KDE team knows that the bug is ready to be confirmed. Thank you for helping us make KDE software even better for everyone!
This bug has been in NEEDSINFO status with no change for at least 30 days. The bug is now closed as RESOLVED > WORKSFORME due to lack of needed information. For more information about our bug triaging procedures please read the wiki located here: https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging Thank you for helping us make KDE software even better for everyone!