Live data from Hacker News

Government shutdown: TLS certificates not renewed, many websites are down

zdnet.com

1–10 of 153 posts

Re: Government shutdown: TLS certificates not renewed, many websites are down

#2
From reddit:

> This article is overly hyperbolic. Some obscure subdomains of government websites are serving expired x509 certificates. They're not down and this definitely doesn't compromise the encryption that protects any login credentials. Anyway, it is embarassing to see certificate renewal is not automated - it's something any good sysadmin would have set up.

https://www.reddit.com/r/technology/comments/aeps41/governme...

Re: Government shutdown: TLS certificates not renewed, many websites are down

#3
My bet what will trigger the next recession proper was on Brexit, but 45 is beating the Brits to it. Not shabby for a temper tantrum.

This week I read up on Reagan's firing of 11000 flight controllers because the union that formerly supported him demanded better working conditions. It took a decade for air traffic control to regain the old levels.

Re: Government shutdown: TLS certificates not renewed, many websites are down

#4

From reddit: > This article is overly hyperbolic. Some obscure subdomains of government websites are serving expired x509 certificates. They're not down and this definitely doesn't compromise the encryption that protects any login credentials. Anyway, it is embarassing to see certificate renewal is not automated - it's something any good sysadmin would have set up. https://www.reddit.com/r/technology/comments/aeps41/…

I've dealt with expired ssl certs on api servers run by school districts and no, they don't automate this stuff, neither do i for my own servers, shamefully.

Re: Government shutdown: TLS certificates not renewed, many websites are down

#5

From reddit: > This article is overly hyperbolic. Some obscure subdomains of government websites are serving expired x509 certificates. They're not down and this definitely doesn't compromise the encryption that protects any login credentials. Anyway, it is embarassing to see certificate renewal is not automated - it's something any good sysadmin would have set up. https://www.reddit.com/r/technology/comments/aeps41/…

They can’t spend any money right now, it would have to be prepaid not just auto-renewed

Re: Government shutdown: TLS certificates not renewed, many websites are down

#6

From reddit: > This article is overly hyperbolic. Some obscure subdomains of government websites are serving expired x509 certificates. They're not down and this definitely doesn't compromise the encryption that protects any login credentials. Anyway, it is embarassing to see certificate renewal is not automated - it's something any good sysadmin would have set up. https://www.reddit.com/r/technology/comments/aeps41/…

Some of these pages are on he HSTS preload list. Browsers won’t let you manually click through to accept the expired cert. Those are effectively down for all intents and purposes.

Re: Government shutdown: TLS certificates not renewed, many websites are down

#7
post #5

From reddit: > This article is overly hyperbolic. Some obscure subdomains of government websites are serving expired x509 certificates. They're not down and this definitely doesn't compromise the encryption that protects any login credentials. Anyway, it is embarassing to see certificate renewal is not automated - it's something any good sysadmin would have set up. https://www.reddit.com/r/technology/comments/aeps41/…

They can’t spend any money right now, it would have to be prepaid not just auto-renewed

It could also be free and automated (let’s encrypt)

Re: Government shutdown: TLS certificates not renewed, many websites are down

#8

From reddit: > This article is overly hyperbolic. Some obscure subdomains of government websites are serving expired x509 certificates. They're not down and this definitely doesn't compromise the encryption that protects any login credentials. Anyway, it is embarassing to see certificate renewal is not automated - it's something any good sysadmin would have set up. https://www.reddit.com/r/technology/comments/aeps41/…

Nothing to do with SSL, but a fair amount of US government websites are hard down, on purpose, due to the funding dilemma.

Like: https://www.data.gov

"Due to a lapse in government funding all Data.gov websites will be unavailable until further notice."

Which is pretty odd, because putting up these blocker pages probably costs more than just letting the sites run unattended.

Re: Government shutdown: TLS certificates not renewed, many websites are down

#9
post #8

From reddit: > This article is overly hyperbolic. Some obscure subdomains of government websites are serving expired x509 certificates. They're not down and this definitely doesn't compromise the encryption that protects any login credentials. Anyway, it is embarassing to see certificate renewal is not automated - it's something any good sysadmin would have set up. https://www.reddit.com/r/technology/comments/aeps41/…

Nothing to do with SSL, but a fair amount of US government websites are hard down, on purpose, due to the funding dilemma. Like: https://www.data.gov "Due to a lapse in government funding all Data.gov websites will be unavailable until further notice." Which is pretty odd, because putting up these blocker pages probably costs more than just letting the sites run unattended.

Maybe. I know nothing about the offerings of these sites but they may be replacing interactive sites where you can access services with a static page.

Re: Government shutdown: TLS certificates not renewed, many websites are down

#10
post #8

From reddit: > This article is overly hyperbolic. Some obscure subdomains of government websites are serving expired x509 certificates. They're not down and this definitely doesn't compromise the encryption that protects any login credentials. Anyway, it is embarassing to see certificate renewal is not automated - it's something any good sysadmin would have set up. https://www.reddit.com/r/technology/comments/aeps41/…

Nothing to do with SSL, but a fair amount of US government websites are hard down, on purpose, due to the funding dilemma. Like: https://www.data.gov "Due to a lapse in government funding all Data.gov websites will be unavailable until further notice." Which is pretty odd, because putting up these blocker pages probably costs more than just letting the sites run unattended.

Maybe the worry is letting them run unattended when no one is allowed to do maintenance/security work in the event of a problem?
Post reply on HN