Live data from Hacker News

Even Akamai screws up their SSL certs

akamai.com

1–10 of 36 posts

Re: Even Akamai screws up their SSL certs

#2
Actually, they probably don't intend for people to use www.akamai.com with HTTPS. If you add an override for the bad cert, you end up getting redirected to a non-HTTPS site anyways. I don't see anything like a login link on www.akamai.com so this is probably OK. (Of course it would be nice if everything were HTTPS...)

Re: Even Akamai screws up their SSL certs

#5
post #2

Actually, they probably don't intend for people to use www.akamai.com with HTTPS. If you add an override for the bad cert, you end up getting redirected to a non-HTTPS site anyways. I don't see anything like a login link on www.akamai.com so this is probably OK. (Of course it would be nice if everything were HTTPS...)

> Of course it would be nice if everything were HTTPS...

Nice try, Certificate Authorities!

Re: Even Akamai screws up their SSL certs

#6
post #5
post #2

Actually, they probably don't intend for people to use www.akamai.com with HTTPS. If you add an override for the bad cert, you end up getting redirected to a non-HTTPS site anyways. I don't see anything like a login link on www.akamai.com so this is probably OK. (Of course it would be nice if everything were HTTPS...)

> Of course it would be nice if everything were HTTPS... Nice try, Certificate Authorities!

>> Of course it would be nice if everything were HTTPS...

> Nice try, Certificate Authorities!

Nice try, NSA.

Re: Even Akamai screws up their SSL certs

#9
post #4

Only partly related: Most websites don't get proper certificates for their FQDN -- even Google [1]. That, to me, is screwed up. [1] https://www.google.com./

That works just fine for me.

It shouldn't; if it does, it is most likely that your browser is removing the trailing dot which makes it a FQDN.

Firefox's verdict:

> www.google.com. uses an invalid security certificate. The certificate is only valid for www.google.com

The fact of the matter is that FQDNs are probably only used in three ways:

1. By accident;

2. As a curio;

3. In complaints about how they don't work properly—badly configured server configurations, invalid HTTPS certificates, &c.

Post reply on HN