Same thing happens with any shared web host that happens to listen on SSL.
Even Akamai screws up their SSL certs
11–20 of 36 posts
Re: Even Akamai screws up their SSL certs
#12This happens with almost any Akamai'zed domain, if you drop https:// in front of it you get the shared Akamai cert. Customers that pay for SSL get their own pool of IPs that respond with only their cert. Same thing happens with any shared web host that happens to listen on SSL.
Re: Even Akamai screws up their SSL certs
#13Re: Even Akamai screws up their SSL certs
#14Re: Even Akamai screws up their SSL certs
#15Earlier quoted context omitted.
> Of course it would be nice if everything were HTTPS... Nice try, Certificate Authorities!
>> Of course it would be nice if everything were HTTPS... > Nice try, Certificate Authorities! Nice try, NSA.
>> Nice try, Certificate Authorities!
> Nice try, NSA.
Nice try, HN.
Re: Even Akamai screws up their SSL certs
#16Only partly related: Most websites don't get proper certificates for their FQDN -- even Google [1]. That, to me, is screwed up. [1] https://www.google.com./
It seems to be either a problem with Firefox or with the domain name system in general.
It looks like the problem should be fixed in 2016 because then all non-FQDN certificates will have expired. Then browsers can go ahead and assume that google.com. in a url is the same as google.com in a certificate.
Re: Even Akamai screws up their SSL certs
#17Better yet, where they absolutely mean to use HTTPS they sometimes use weak keys and ciphers and get an "F" from the Qualys SSL Labs tool. Blogs.akamai.com isn't the only place this happens: https://www.ssllabs.com/ssltest/analyze.html?d=blogs.akamai....
https://www.ssllabs.com/ssltest/analyze.html?d=developer.aka...
https://www.ssllabs.com/ssltest/analyze.html?d=a248.e.akamai...
https://www.ssllabs.com/ssltest/analyze.html?d=network.akama...
The thing is, the worst part is knowing a child is capable of A's:
https://www.ssllabs.com/ssltest/analyze.html?d=control.akama...
Re: Even Akamai screws up their SSL certs
#18Better yet, where they absolutely mean to use HTTPS they sometimes use weak keys and ciphers and get an "F" from the Qualys SSL Labs tool. Blogs.akamai.com isn't the only place this happens: https://www.ssllabs.com/ssltest/analyze.html?d=blogs.akamai....
They don't have PFS, either. That's bad, though unfortunately still common. As far as I know Akamai's position is that the (small) performance cost of PFS is unacceptable. They would be delighted if it was faster (which people are working on).
I think the F is because of the 1024-bit, MD5 CA. That seems to be more of an argument for clients to disable that CA certificate, especially since there's another, good trust path, but maybe I'm missing something.
Re: Even Akamai screws up their SSL certs
#19Re: Even Akamai screws up their SSL certs
#20Earlier quoted context omitted.
>> Of course it would be nice if everything were HTTPS... > Nice try, Certificate Authorities! Nice try, NSA.
>>> Of course it would be nice if everything were HTTPS... >> Nice try, Certificate Authorities! > Nice try, NSA. Nice try, HN.