Live data from Hacker News

Expired SSL certificate

manjaro.github.io

1–10 of 71 posts

Re: Expired SSL certificate

#5
What is shocking is that they still haven't found the way to properly fix it after 3 days.

I updated some SSL certificates last week (which even required contortions such as moving to a new issuer since some legacy software requires old-style SHA-1 signed ones which our current one doesn't provide), and it didn't take more than one (long) day of work.

Re: Expired SSL certificate

#7
I wonder if browsers should for (say) a week after a cert has expired, show an error so alarms are raised, but allow the dialog to be dismissed with an OK instead of all the "Confirm Security Exception" that would go on for a more serious cert rejection.

Re: Expired SSL certificate

#9
post #7

I wonder if browsers should for (say) a week after a cert has expired, show an error so alarms are raised, but allow the dialog to be dismissed with an OK instead of all the "Confirm Security Exception" that would go on for a more serious cert rejection.

That is by far not the job of a browser to remind server administrators to renew there certs and display that message to random users.

Re: Expired SSL certificate

#10

Don't pretty much all browsers let you accept using an expired certificate?

The issue is with HSTS. If you've visited the site before you've likely cached that SSL is required and your browser will refuse to connect. Using e.g. a 'private window' will allow it to be bypassed.
Post reply on HN