Package: iceweasel
Version: 24.4.0esr-1~deb7u2
Severity: normal
File: /usr/bin/iceweasel

Dear Maintainer,

trying to load a single encrypted websites, such as
https://bugs.debian.org now takes more than 30 minutes during which
(according to tcpdump, ifttop) firefox keeps talking to
ocsp.commodoca.com, downloading over 70 Mbyte in the process.  No, my
internet connection is not the bottleneck here (> 10mbit).

Seems to depend on certifcate authority, I was only able to reproduce
this particlar problem for websites that use Comodo's CA.

This may be result of the heartbleed bug causing lots of certificates to
be revoked?  Unfortunately it makes HTTPS (or OCSP) completely unusable.

Once the site is loaded, further operation is nominal, but the delay
occurs again when Iceweasel is restarted (note: I have disabled harddisk
cache for privacy reasons, don't know whether configuring a sufficiently
large cache would help).

Update: It gets worse: during my last test Iceweasel crashed after 78
Megabyte had been downloaded from ocsp.comodoca.com, ca 45 minutes after
initiating the loading of https://bugs.debian.org

cheers,

David


-- Package-specific info:
-- Extensions information
Name: 4or6
Location: ${PROFILE_EXTENSIONS}/4...@hunen.net.xpi
Status: enabled

Name: Adblock Plus
Location: 
/usr/share/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}/{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
Package: xul-ext-adblock-plus
Status: enabled

Name: CipherFox
Location: ${PROFILE_EXTENSIONS}/cipher...@mkfly.xpi
Status: user-disabled

Name: Default theme
Location: 
/usr/lib/iceweasel/browser/extensions/{972ce4c6-7e08-4474-a285-3208198ce6fd}
Package: iceweasel
Status: enabled

Name: Facebook Disconnect
Location: ${PROFILE_EXTENSIONS}/faceb...@disconnect.me.xpi
Status: enabled

Name: Flashblock
Location: ${PROFILE_EXTENSIONS}/{3d7eb24f-2740-49df-8937-200b1cc08f8a}
Status: enabled

Name: Flash Video Downloader - Full HD Download
Location: ${PROFILE_EXTENSIONS}/artur.dubo...@gmail.com
Status: user-disabled

Name: Flash Video Resources Downloader
Location: ${PROFILE_EXTENSIONS}/m...@subfighter.com
Status: app-disabled

Name: Google Disconnect
Location: ${PROFILE_EXTENSIONS}/goo...@disconnect.me.xpi
Status: enabled

Name: Greasemonkey
Location: 
/usr/share/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}/{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
Package: xul-ext-greasemonkey
Status: user-disabled

Name: HTTPS-Everywhere
Location: ${PROFILE_EXTENSIONS}/https-everywh...@eff.org
Status: user-disabled

Name: lori (Life-of-request info)
Location: ${PROFILE_EXTENSIONS}/{6dfc4f52-26f0-4e5f-89c7-31d6de480db9}
Status: user-disabled

Name: NoScript
Location: 
/usr/share/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}/{73a6fe31-595d-460b-a920-fcc0f8843232}
Package: xul-ext-noscript
Status: enabled

Name: NoSquint
Location: ${PROFILE_EXTENSIONS}/nosqu...@urandom.ca.xpi
Status: enabled

Name: Twitter Disconnect
Location: ${PROFILE_EXTENSIONS}/twit...@disconnect.me.xpi
Status: enabled

Name: User Agent Switcher
Location: ${PROFILE_EXTENSIONS}/{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
Status: user-disabled

-- Plugins information
Name: DivX Web Player
Location: /usr/lib/mozilla/plugins/libtotem-mully-plugin.so
Package: totem-mozilla
Status: enabled

Name: Gnome Shell Integration
Location: /usr/lib/mozilla/plugins/libgnome-shell-browser-plugin.so
Package: gnome-shell
Status: enabled

Name: iTunes Application Detector
Location: /usr/lib/mozilla/plugins/librhythmbox-itms-detection-plugin.so
Package: rhythmbox-plugins
Status: enabled

Name: Java(TM) Plug-in 1.6.0_26
Location: /usr/lib/jvm/java-6-sun-1.6.0.26/jre/lib/amd64/libnpjp2.so
Package: sun-java6-bin
Status: disabled

Name: MozPlugger 1.14.1 handles QuickTime and Windows Media Player Plugin 
(1.14.1)
Location: /usr/lib/mozilla/plugins/mozplugger.so
Package: mozplugger
Status: enabled

Name: QuickTime Plug-in 7.6.6
Location: /usr/lib/mozilla/plugins/libtotem-narrowspace-plugin.so
Package: totem-mozilla
Status: enabled

Name: Shockwave Flash
Location: /usr/lib/flashplugin-nonfree/libflashplayer.so
Status: enabled

Name: VLC Multimedia Plugin (compatible Totem 3.0.1)
Location: /usr/lib/mozilla/plugins/libtotem-cone-plugin.so
Package: totem-mozilla
Status: enabled

Name: Windows Media Player Plug-in 10 (compatible; Totem)
Location: /usr/lib/mozilla/plugins/libtotem-gmp-plugin.so
Package: totem-mozilla
Status: enabled


-- Addons package information
ii  gnome-shell    3.4.2-7+deb7 amd64        graphical shell for the GNOME des
ii  iceweasel      24.4.0esr-1~ amd64        Web browser based on Firefox
ii  mozplugger     1.14.1-1     amd64        Plugin allowing external viewers 
ii  rhythmbox-plug 2.97-2.1     amd64        plugins for rhythmbox music playe
ii  sun-java6-bin  6.26-0squeez amd64        Sun Java(TM) Runtime Environment 
ii  totem-mozilla  3.0.1-8      amd64        Totem Mozilla plugin
ii  xul-ext-adbloc 2.1-1+deb7u1 all          Advertisement blocking extension 
ii  xul-ext-grease 0.9.20-1     all          extension that enables customizat
ii  xul-ext-noscri 2.1.4-1      all          Javascript/plugins permissions ma
*** Please consider answering these questions, where appropriate ***

   * What led up to the situation?
   * What exactly did you do (or not do) that was effective (or
     ineffective)?
   * What was the outcome of this action?
   * What outcome did you expect instead?

*** End of the template - remove these lines ***


-- System Information:
Debian Release: 7.4
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.2.0-4-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages iceweasel depends on:
ii  debianutils         4.3.2
ii  fontconfig          2.9.0-7.1
ii  libc6               2.13-38+deb7u1
ii  libgdk-pixbuf2.0-0  2.26.1-1
ii  libglib2.0-0        2.33.12+really2.32.4-5
ii  libgtk2.0-0         2.24.10-2
ii  libsqlite3-0        3.7.13-1+deb7u1
ii  libstdc++6          4.7.2-5
ii  procps              1:3.3.3-3
ii  xulrunner-24.0      24.4.0esr-1~deb7u2

iceweasel recommends no packages.

Versions of packages iceweasel suggests:
pn  fonts-mathjax          <none>
ii  fonts-oflb-asana-math  000.907-4
ii  fonts-stix [otf-stix]  1.1.0-1
ii  libgssapi-krb5-2       1.10.1+dfsg-5+deb7u1
ii  mozplugger             1.14.1-1

Versions of packages xulrunner-24.0 depends on:
ii  libasound2                1.0.25-4
ii  libatk1.0-0               2.4.0-2
ii  libbz2-1.0                1.0.6-4
ii  libc6                     2.13-38+deb7u1
ii  libcairo2                 1.12.2-3
ii  libdbus-1-3               1.6.8-1+deb7u1
ii  libdbus-glib-1-2          0.100.2-1
ii  libevent-2.0-5            2.0.19-stable-3
ii  libfontconfig1            2.9.0-7.1
ii  libfreetype6              2.4.9-1.1
ii  libgcc1                   1:4.7.2-5
ii  libgdk-pixbuf2.0-0        2.26.1-1
ii  libglib2.0-0              2.33.12+really2.32.4-5
ii  libgtk2.0-0               2.24.10-2
ii  libhunspell-1.3-0         1.3.2-4
ii  libmozjs24d               24.4.0esr-1~deb7u2
ii  libpango1.0-0             1.30.0-1
ii  libstartup-notification0  0.12-1
ii  libstdc++6                4.7.2-5
ii  libvpx1                   1.1.0-1
ii  libx11-6                  2:1.5.0-1+deb7u1
ii  libxext6                  2:1.3.1-2+deb7u1
ii  libxrender1               1:0.9.7-1+deb7u1
ii  libxt6                    1:1.1.3-1+deb7u1
ii  zlib1g                    1:1.2.7.dfsg-13

Versions of packages xulrunner-24.0 suggests:
ii  libcanberra0  0.28-6
ii  libgnomeui-0  2.24.5-2

-- no debconf information

-- 
GnuPG public key: http://dvdkhlng.users.sourceforge.net/dk2.gpg
Fingerprint: B63B 6AF2 4EEB F033 46F7  7F1D 935E 6F08 E457 205F

Attachment: pgpzLa8oAsIbx.pgp
Description: PGP signature

Reply via email to