I'm using Chromium on Ubuntu 16, and I've been trying to visit https://www.nist.gov/ but I don't even get an option to 'browse insecurely' under the 'Advanced' link. In my experience that past couple days, I get the warning on about 10-25% of major web sites.
Ugh that's the worst. I work on servers where the GUI can only be accessed using HTTPS, but its all internal so many clients don't bother. And I don't know why browsers sometimes don't let me say "continue anyway" but it's super frustrating.
Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate
31–40 of 95 posts
Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate
#32Author here. It has gotten kind of hard to follow what has happened, so here's a chronology: 1. In September, Chrome 53 was released, which enabled mandatory Certificate Transparency for Symantec certificates due to Symantec's history of incompetence. Some website operators, such as Chase, asked Symantec to submit their certificates to Certificate Transparency logs in such a way that the certificate wouldn't be trust…
After reading the blogpost, it seems like it was working as intended. Why "fix" it?
Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate
#33Author here. It has gotten kind of hard to follow what has happened, so here's a chronology: 1. In September, Chrome 53 was released, which enabled mandatory Certificate Transparency for Symantec certificates due to Symantec's history of incompetence. Some website operators, such as Chase, asked Symantec to submit their certificates to Certificate Transparency logs in such a way that the certificate wouldn't be trust…
Is there any reason, in 2016, to use Symantec over LetsEncrypt?
Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate
#34Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate
#35Earlier quoted context omitted.
Is there any reason, in 2016, to use Symantec over LetsEncrypt?
Wildcards.
Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate
#36Earlier quoted context omitted.
Ugh that's the worst. I work on servers where the GUI can only be accessed using HTTPS, but its all internal so many clients don't bother. And I don't know why browsers sometimes don't let me say "continue anyway" but it's super frustrating.
Using HSTS on a website will generally prevent your browser from allowing you to continue, which is fair: the website owner has explicitly indicated the website should only ever be used over a encrypted connection, and that is not the case..
Who owns my browser?
Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate
#37Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate
#38Author here. It has gotten kind of hard to follow what has happened, so here's a chronology: 1. In September, Chrome 53 was released, which enabled mandatory Certificate Transparency for Symantec certificates due to Symantec's history of incompetence. Some website operators, such as Chase, asked Symantec to submit their certificates to Certificate Transparency logs in such a way that the certificate wouldn't be trust…
A) why is this possible, and B) isn't the whole point of the expiring list to provide a stick? Why remove the stick at the last moment?
Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate
#39Earlier quoted context omitted.
Wildcards.
We use wildcard certs for a number of domains to support affiliate subdomains. So affiliate.example.com and affiliate2.example.com are all served by the same servers and thus all need to validate with one cert.
They don't even need to be subdomains.
Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate
#40Author here. It has gotten kind of hard to follow what has happened, so here's a chronology: 1. In September, Chrome 53 was released, which enabled mandatory Certificate Transparency for Symantec certificates due to Symantec's history of incompetence. Some website operators, such as Chase, asked Symantec to submit their certificates to Certificate Transparency logs in such a way that the certificate wouldn't be trust…
Is there any reason, in 2016, to use Symantec over LetsEncrypt?