{"id":33846,"date":"2024-04-27T00:05:41","date_gmt":"2024-04-26T22:05:41","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=33846"},"modified":"2024-04-27T11:49:30","modified_gmt":"2024-04-27T09:49:30","slug":"edge-version-124-0-2478-51-causes-issues-with-http-pages","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2024\/04\/27\/edge-version-124-0-2478-51-causes-issues-with-http-pages\/","title":{"rendered":"Edge version 124.0.2478.51 causes issues with http pages"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline; border-width: 0px;\" title=\"Edge\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2020\/01\/Edge.jpg\" alt=\"Edge\" width=\"65\" height=\"67\" align=\"left\" border=\"0\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2024\/04\/23\/edge-version-124-0-2478-51-macht-probleme-mit-http-seiten\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Brief information for blog readers that Maksymilian has just pointed out to me. Microsoft's developers updated the Edge browser to version 124.0.2478.51 on April 19, 2024. However, this causes problems with (insecure) http pages and blocks downloads, for example. It's stupid when this happens on an intranet in a corporate environment. Incidentally, this also applies to the Chromium counterpart. But there is a workaround that Maksymilian provided me with (thanks for that).<\/p>\n<p><!--more--><\/p>\n<h2>Edge 124.0.2478.51 has issues with http<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg07.met.vgwort.de\/na\/890c86de0daf426dbc14d50cc26571a8\" alt=\"\" width=\"1\" height=\"1\" \/>Microsofts Edge and Google's Chromium developers are always good for surprises. Edge version 124.0.2478.51 is intended to close various bugs and vulnerabilities. It also introduces some new features. Today Maksymilian contacted me by email and wrote:<\/p>\n<blockquote><p>Hello G\u00fcnter,<\/p>\n<p>I wanted to draw your attention to something that has been occurring since 19.4.24 with the latest Edge update version 124.0.2478.51:<\/p>\n<p>Pages that still function as HTTP (often in companies as intranet pages) and users want to download files from them, this is blocked. Unfortunately, this was not mentioned in the changelog, but was uncovered by the frustration of the community.<\/p><\/blockquote>\n<p>Maksymilian provided me with several sources on the web where the problem is addressed. On Reddit.com you can find<a href=\"https:\/\/www.reddit.com\/r\/MicrosoftEdge\/comments\/1c7qzpt\/edge_1240247851_pdf_cant_be_downloaded_since_the\/\" target=\"_blank\" rel=\"noopener\"> this post<\/a> with the following content:<\/p>\n<blockquote><p>Edge 124.0.2478.51 PDF cant be downloaded. Since the newest update we cant download Pdf files which are viewed through the edge. If you can press the save button and it will start to download, but after that it will show you an error message that it cant be downloaded. Has anyone else this issue?<\/p><\/blockquote>\n<p><a href=\"https:\/\/www.reddit.com\/r\/MicrosoftEdge\/comments\/1c7qzpt\/edge_1240247851_pdf_cant_be_downloaded_since_the\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"Edge: Empty download\" src=\"https:\/\/i.postimg.cc\/KzvXw96c\/image.png\" alt=\"Edge: Empty download\" \/><\/a><\/p>\n<p>In this specific case, the affected person can no longer download PDF files with Edge 24.0.2478.51. The download starts, but there is an error stating that the file cannot be downloaded. Another user confirms this and writes that he also has this problem in his work environment. It affects file downloads from all internal http sites, although it is unclear whether all file types are affected or just a selection.<\/p>\n<p>In the Microsoft Techcommunity there is a user post <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/enterprise\/mixed-mode-content-download-warning\/m-p\/4118977\" target=\"_blank\" rel=\"noopener\">Mixed mode content download warning<\/a>, which also deals with the issue. The affected person writes that after the recent update to Edge v124 Stable, he suddenly has the problem that a number of internal websites that issue mixed mode content download warnings and blocked file downloads. Someone wrote that it also affects the Chromium browser and posted <a href=\"https:\/\/issues.chromium.org\/issues\/336490879\" target=\"_blank\" rel=\"noopener\">this bug report<\/a> on Google.<\/p>\n<h2>Workaround for the problem<\/h2>\n<p>Those affected in the reddit.com thread wrote that they hope to be able to solve the problem with a GPO change. Maksymilian included the link to the relevant Microsoft policy <a href=\"https:\/\/learn.microsoft.com\/en-us\/deployedge\/microsoft-edge-policies#control-where-security-restrictions-on-insecure-origins-apply\" target=\"_blank\" rel=\"noopener\">Control where security restrictions on insecure origins apply<\/a>\u00a0in his email. With this policy, administrators can specify permitted origins for legacy applications that cannot provide TLS. This involves specifying a list of sources (URLs) or hostname patterns (e.g. \"*.contoso.com\") to which the security restrictions on insecure origins do not apply.<\/p>\n<p>This policy also prevents the origin in the omnibox from being marked as \"Not secure\". Setting a list of URLs in this policy has the same effect as setting the command line flag '&#8211;unsafely-treat-insecure-origin-as-secure' on a comma-separated list of the same URLs. When this policy is enabled, it takes precedence over the command line flag. Maybe it will help someone.<\/p>\n<h2>Problem with SSL inspection for https pages<\/h2>\n<p>German blog reader Dirk contacted me by email afterwards because he had read the article. He writes that problems have been occurring in his company environment since yesterday with https pages that are subjected to SSL inspection. This affects Chromium browsers, while it works with Firefox. The problem occurs randomly, writes Dirk and adds: \"Strangely, we are currently only seeing it on Windows 10\/Windows 11, but not on the server variants under Citrix with the same proxy and Edge version.\" Has anyone from the readership made similar observations?<\/p>\n<p>A reader wrote to me on Facebook that he had also encountered the issue with SSL inspection on some clients &#8211; but not on all of them, despite the latest Chrome and Edge versions. The reader is still looking into why this is the case, but suspects that the <em>enable-tls13-kyber<\/em> flag in Chrome is the problem because it is now set to active by default. If you deactivate the option, the affected clients no longer have any problems.<\/p>\n<h2>Microsofts confirmation<\/h2>\n<p><strong>Addendum:<\/strong> In an <a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnote-stable-channel#version-1240247867-april-26-2024\" target=\"_blank\" rel=\"noopener\">update to Edge Version 124.0.2478.67<\/a> from April 26, 2024, Microsoft confirmed the issue als accidental &#8211; and wrote:<\/p>\n<blockquote><p><strong>Announcement: Insecure downloads over HTTP<\/strong><\/p>\n<p>Users that download potentially dangerous content on HTTP sites will receive a UI warning, (for example, \"sample.exe can't be downloaded securely\"). The user can still choose to proceed by selecting \"Keep\" on the downloaded item's \"&#8230;\" menu. Admins can also use the\u00a0<a href=\"https:\/\/learn.microsoft.com\/en-us\/deployedge\/microsoft-edge-policies#insecurecontentallowedforurls\" target=\"_blank\" rel=\"noopener\" data-linktype=\"absolute-path\">InsecureContentAllowedForUrls<\/a>\u00a0policy to specify HTTP sites where the warning will be suppressed. The warning's enablement in Edge 124 was accidental. We have reverted the warning in this Stable Release. Admins can use the\u00a0<code>InsecureDownloadWarnings<\/code>\u00a0feature flag to test the impact of this upcoming feature.<\/p><\/blockquote>\n<p>In a Note Microsoft wrote, that the warning is planned to be turned on in Microsoft Edge version 127.<\/p>\n<p><strong>Similar articles<br \/>\n<\/strong><a href=\"https:\/\/borncity.com\/win\/2024\/03\/20\/new-microsoft-timeline-for-the-introduction-of-the-adobe-acrobat-pdf-engine-in-edge-chromium\/\" rel=\"bookmark\">New Microsoft timeline for the introduction of the Adobe Acrobat PDF engine in Edge Chromium<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/03\/30\/microsoft-edge-bug-cve-2024-21388-erlaubte-beliebiger-erweiterungen-zu-installieren\/\" rel=\"bookmark\">Microsoft Edge Bug CVE-2024-21388 allowed to install arbitrary extensions<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/04\/18\/windows-edge-123-0-2420-65-update-from-march-2024-unintentionally-brings-co-pilot-app-no-spy-function\/\" rel=\"bookmark\">Windows: Edge 123.0.2420.65 update from March 2024 unintentionally brings co-pilot app; no \"spy function\"<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Brief information for blog readers that Maksymilian has just pointed out to me. Microsoft's developers updated the Edge browser to version 124.0.2478.51 on April 19, 2024. However, this causes problems with (insecure) http pages and blocks downloads, for example. It's &hellip; <a href=\"https:\/\/borncity.com\/win\/2024\/04\/27\/edge-version-124-0-2478-51-causes-issues-with-http-pages\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[872,463,1547],"tags":[2854],"class_list":["post-33846","post","type-post","status-publish","format-standard","hentry","category-browser","category-issue","category-software","tag-edge-issue"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33846","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=33846"}],"version-history":[{"count":3,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33846\/revisions"}],"predecessor-version":[{"id":33856,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33846\/revisions\/33856"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=33846"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=33846"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=33846"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}