Live data from Hacker News

Expired SSL certificate

manjaro.github.io

21–30 of 71 posts

Re: Expired SSL certificate

#21
post #7

I wonder if browsers should for (say) a week after a cert has expired, show an error so alarms are raised, but allow the dialog to be dismissed with an OK instead of all the "Confirm Security Exception" that would go on for a more serious cert rejection.

I don't agree. If this happens, same rule should apply for domain name expiration.

That's actually not a bad idea.

Re: Expired SSL certificate

#22
post #5

What is shocking is that they still haven't found the way to properly fix it after 3 days. I updated some SSL certificates last week (which even required contortions such as moving to a new issuer since some legacy software requires old-style SHA-1 signed ones which our current one doesn't provide), and it didn't take more than one (long) day of work.

It's just embarrassing. I can only assume the sysop is on holiday.

Checking their about page, they have 3 web developers, one of which wrote that post. That's worrying.

Re: Expired SSL certificate

#23
post #20
post #18

Earlier quoted context omitted.

Alas, in this imperfect world, phone calls from random users are how server admins are notified of cert expiry.

In this "imperfect" world nowadays eveyone try to ship his responsability to someone else.

I'll wait for someone else to respond to your comment.

Re: Expired SSL certificate

#25
post #7

I wonder if browsers should for (say) a week after a cert has expired, show an error so alarms are raised, but allow the dialog to be dismissed with an OK instead of all the "Confirm Security Exception" that would go on for a more serious cert rejection.

I like this idea. At the moment there is nothing that differentiates a "this cert expired yesterday" warning from a "someone is MITMing your connection" warning, at least not for the casual user.

And since the former is (sadly) pretty common, this only teaches people that these warnings are not that unusual, and can safely be overridden.

It would be much better to have one "the server admin forgot to renew his certificate" type of warning and another "a totalitarian regime is trying to spy on you" type of warning...

Re: Expired SSL certificate

#26

Earlier quoted context omitted.

It's just embarrassing. I can only assume the sysop is on holiday.

Checking their about page, they have 3 web developers, one of which wrote that post. That's worrying.

The available web developers may not have access to either the SSL vendor or where the certificate is stored. None of the front-end devs I work with have access to either of those things.

Re: Expired SSL certificate

#27
post #7

I wonder if browsers should for (say) a week after a cert has expired, show an error so alarms are raised, but allow the dialog to be dismissed with an OK instead of all the "Confirm Security Exception" that would go on for a more serious cert rejection.

That shouldn't be default behaviour in any browser but rather a plugin that you can install that gives the notification. Preferably with a whitelist of websites that I want to get notifications of.

Re: Expired SSL certificate

#29
post #7

I wonder if browsers should for (say) a week after a cert has expired, show an error so alarms are raised, but allow the dialog to be dismissed with an OK instead of all the "Confirm Security Exception" that would go on for a more serious cert rejection.

I like this idea. At the moment there is nothing that differentiates a "this cert expired yesterday" warning from a "someone is MITMing your connection" warning, at least not for the casual user. And since the former is (sadly) pretty common, this only teaches people that these warnings are not that unusual, and can safely be overridden. It would be much better to have one "the server admin forgot to renew his certif…

And because of this I overheard someone say "I just click Okay because else the website won't load!".

Re: Expired SSL certificate

#30
post #8

WTF, changing your PC date is not a solution! This will cause more issues.

I guess they should have just put a notice up saying forums and wiki unavailable, that could have prevented this whole mess.
Post reply on HN