Live data from Hacker News

Government shutdown: TLS certificates not renewed, many websites are down

zdnet.com

31–40 of 153 posts

Re: Government shutdown: TLS certificates not renewed, many websites are down

#31
post #25
post #23

Earlier quoted context omitted.

Government departments are legally required to budget for the possibility of a shutdown, which means they have to keep the money around that they will use to shut down. https://en.wikipedia.org/wiki/Antideficiency_Act

Yes, but this coupled with the fact they shut down things that don't otherwise really require a human to actively working proves that it's all just a political ploy.

Some bits no doubt require some human intervention, and if it wasn't updated, would cause confusion.

The census site seems to be a decent middle ground. Banner at the top says "NOTICE: Due to a lapse in federal funding portions of this website are not being updated." Still functional, but if something's not updated, you know why.

Re: Government shutdown: TLS certificates not renewed, many websites are down

#32

Serious question for US members of HN: how do you tolerate these shutdowns? I mean, apart from the loss of services, including websites, it seems like many federal workers aren't being paid. Will they be paid back after the shutdown impasse is resolved or is the money they didn't/couldn't earn lost to them. This seems unfair and, in the meantime, how are they supposed to go about their lives? Overall it seems potenti…

A lot of people just aren't affected visibly, and I guess people don't usually riot about things that don't anger them. Not sure how those that are affected are getting by. To me these shutdowns (and lack of pay) should be bringing down the US government's credit rating.

Re: Government shutdown: TLS certificates not renewed, many websites are down

#33
post #3

My bet what will trigger the next recession proper was on Brexit, but 45 is beating the Brits to it. Not shabby for a temper tantrum. This week I read up on Reagan's firing of 11000 flight controllers because the union that formerly supported him demanded better working conditions. It took a decade for air traffic control to regain the old levels.

Trump is asking for less than 1/1000 of our annual budget for border security. We spend 10x that on foreign aid annually. This entire thing is political BS over what amounts to a rounding error while congress almost unanimously approved $38 billion in money for Israel

Maybe we can stop being obtuse? The senate can end this by passing a budget and override the president's veto. They're choosing not to.

Re: Government shutdown: TLS certificates not renewed, many websites are down

#34
post #19

Earlier quoted context omitted.

Trump is asking for less than 1/1000 of our annual budget for border security. We spend 10x that on foreign aid annually. This entire thing is political BS over what amounts to a rounding error while congress almost unanimously approved $38 billion in money for Israel

As a European I find the US system to bind packages of laws slightly idiotic. The current fight is about a few sticks of steel yet unrelated federal agencies are cut off their funding. This is sabotage!

They don't have to do it this way. They call the packages Omnibus bills and its supposed to be some sort of way to make the process more efficient and strike deals. You get your pet project and I get mine.

https://en.m.wikipedia.org/wiki/Omnibus_bill

Re: Government shutdown: TLS certificates not renewed, many websites are down

#35
post #3

My bet what will trigger the next recession proper was on Brexit, but 45 is beating the Brits to it. Not shabby for a temper tantrum. This week I read up on Reagan's firing of 11000 flight controllers because the union that formerly supported him demanded better working conditions. It took a decade for air traffic control to regain the old levels.

Trump is asking for less than 1/1000 of our annual budget for border security. We spend 10x that on foreign aid annually. This entire thing is political BS over what amounts to a rounding error while congress almost unanimously approved $38 billion in money for Israel

It’s not about the money at this point, but about not setting a precedent that the president can get anything he wants by threatening to veto any budget bill that doesn’t include it.

Re: Government shutdown: TLS certificates not renewed, many websites are down

#36

Serious question for US members of HN: how do you tolerate these shutdowns? I mean, apart from the loss of services, including websites, it seems like many federal workers aren't being paid. Will they be paid back after the shutdown impasse is resolved or is the money they didn't/couldn't earn lost to them. This seems unfair and, in the meantime, how are they supposed to go about their lives? Overall it seems potenti…

Because most of the government is a waste of money and exists merely to perpetuate itself. The fact that it just shuts down sometimes is a great indicator of just that. It’s an entity that is accountable to nobody because no matter how well or poorly it performs it just collects revenue anyway. You can’t #deletegovt. The sooner people move away from viewing it as a good employer, the better. There’s no smooth or elegant way to make this happen, unfortunately.

Re: Government shutdown: TLS certificates not renewed, many websites are down

#37
post #33

Earlier quoted context omitted.

Trump is asking for less than 1/1000 of our annual budget for border security. We spend 10x that on foreign aid annually. This entire thing is political BS over what amounts to a rounding error while congress almost unanimously approved $38 billion in money for Israel

Maybe we can stop being obtuse? The senate can end this by passing a budget and override the president's veto. They're choosing not to.

This is the part that people so easily forget. The power is truley in Congress' hands. That said, appropriations bills must originate in the House and the new speaker and flock of freshman Representatives haven't passed anything yet.

Re: Government shutdown: TLS certificates not renewed, many websites are down

#38
post #25
post #23

Earlier quoted context omitted.

Government departments are legally required to budget for the possibility of a shutdown, which means they have to keep the money around that they will use to shut down. https://en.wikipedia.org/wiki/Antideficiency_Act

Yes, but this coupled with the fact they shut down things that don't otherwise really require a human to actively working proves that it's all just a political ploy.

I don’t dispute that shutdowns are political ploys, but I don’t think that the actual implementations of shutting down are necessarily part of that ploy. Whether a human is required to run something is not the relevant factor. What’s relevant is the cost.

Re: Government shutdown: TLS certificates not renewed, many websites are down

#39

From reddit: > This article is overly hyperbolic. Some obscure subdomains of government websites are serving expired x509 certificates. They're not down and this definitely doesn't compromise the encryption that protects any login credentials. Anyway, it is embarassing to see certificate renewal is not automated - it's something any good sysadmin would have set up. https://www.reddit.com/r/technology/comments/aeps41/…

>Anyway, it is embarassing to see certificate renewal is not automated - it's something any good sysadmin would have set up. From the original article[1]: " One such example is https://ows2.usdoj.gov , a U.S. Department of Justice website which uses a certificate that expired in the week leading up the shutdown . The certificate has been signed by a trusted certificate authority, GoDaddy, but it has not been renewed…

You can probably verify this yourself with crt.sh! I’m on mobile and busy, but it’s a fun game mucking through the certificates for various domain names.

Re: Government shutdown: TLS certificates not renewed, many websites are down

#40
post #4

From reddit: > This article is overly hyperbolic. Some obscure subdomains of government websites are serving expired x509 certificates. They're not down and this definitely doesn't compromise the encryption that protects any login credentials. Anyway, it is embarassing to see certificate renewal is not automated - it's something any good sysadmin would have set up. https://www.reddit.com/r/technology/comments/aeps41/…

I've dealt with expired ssl certs on api servers run by school districts and no, they don't automate this stuff, neither do i for my own servers, shamefully.

i did some work for my state, and I couldn't automate ssl stuff, because the dept who handled the certs didn't provide for automation to be consumed - I got emailed certs (IIRC - been a couple of years now).

By contrast, for most projects, I have standard cert/le automatically updating every 2-3 months. LE was just becoming a thing a couple years ago, and they'd never heard of it. I'm not saying they should all use LE, but the initial time investment of providing an automated process to renew and update via API would pay dividends in the long run (but the people that feel that the most don't have the clout/power to lobby for such things, usually).

Post reply on HN