Actually, they probably don't intend for people to use www.akamai.com with HTTPS. If you add an override for the bad cert, you end up getting redirected to a non-HTTPS site anyways. I don't see anything like a login link on www.akamai.com so this is probably OK. (Of course it would be nice if everything were HTTPS...)
> Of course it would be nice if everything were HTTPS... Nice try, Certificate Authorities!
Even Akamai screws up their SSL certs
31–36 of 36 posts
Re: Even Akamai screws up their SSL certs
#32Better yet, where they absolutely mean to use HTTPS they sometimes use weak keys and ciphers and get an "F" from the Qualys SSL Labs tool. Blogs.akamai.com isn't the only place this happens: https://www.ssllabs.com/ssltest/analyze.html?d=blogs.akamai....
Not the biggest crisis. Okay, they have several awful cipher suites enabled, but no sane client would ever use them. The client report shows that almost every client uses AES; a couple crappy ones use RC4 or 3DES. They don't have PFS, either. That's bad, though unfortunately still common. As far as I know Akamai's position is that the (small) performance cost of PFS is unacceptable. They would be delighted if it was…
The Baltimore root is trusted, but also signed by the old GTE 1024-bit root. It's not clear to me what harm it does to have an appendix of old roots above a well-managed, trustworthy trusted root.
Re: Even Akamai screws up their SSL certs
#33Better yet, where they absolutely mean to use HTTPS they sometimes use weak keys and ciphers and get an "F" from the Qualys SSL Labs tool. Blogs.akamai.com isn't the only place this happens: https://www.ssllabs.com/ssltest/analyze.html?d=blogs.akamai....
Someone's parents are going to be really mad about this report card: https://www.ssllabs.com/ssltest/analyze.html?d=developer.aka... https://www.ssllabs.com/ssltest/analyze.html?d=a248.e.akamai... https://www.ssllabs.com/ssltest/analyze.html?d=network.akama... The thing is, the worst part is knowing a child is capable of A's: https://www.ssllabs.com/ssltest/analyze.html?d=control.akama...
The grades are up to Cs now and should be As within a day.
I'm glad Ivan and Qualys are helping show us where we really are.
Re: Even Akamai screws up their SSL certs
#34https://www.ssllabs.com/ssltest/analyze.html?d=control.akama...
Re: Even Akamai screws up their SSL certs
#35Earlier quoted context omitted.
Not the biggest crisis. Okay, they have several awful cipher suites enabled, but no sane client would ever use them. The client report shows that almost every client uses AES; a couple crappy ones use RC4 or 3DES. They don't have PFS, either. That's bad, though unfortunately still common. As far as I know Akamai's position is that the (small) performance cost of PFS is unacceptable. They would be delighted if it was…
Indeed, it looks like that's a bug in the SSL labs rating scheme: given two trust paths, it takes the longer one. The Baltimore root is trusted, but also signed by the old GTE 1024-bit root. It's not clear to me what harm it does to have an appendix of old roots above a well-managed, trustworthy trusted root.
Technically, the F for blogs.akamai.com was a bug (now corrected; the grade after the fix is C). I say "technically" not because I approve of export cipher suites, but because the implementation did not follow the documentation (the rating guide, linked from every report). Export suites are hopelessly weak and will be treated more harshly in the next guide revision. The new grade is certainly not something to be happy about.
Re: Even Akamai screws up their SSL certs
#36Earlier quoted context omitted.
Someone's parents are going to be really mad about this report card: https://www.ssllabs.com/ssltest/analyze.html?d=developer.aka... https://www.ssllabs.com/ssltest/analyze.html?d=a248.e.akamai... https://www.ssllabs.com/ssltest/analyze.html?d=network.akama... The thing is, the worst part is knowing a child is capable of A's: https://www.ssllabs.com/ssltest/analyze.html?d=control.akama...
That's my report card. The grades are up to Cs now and should be As within a day. I'm glad Ivan and Qualys are helping show us where we really are.