11 ms·
From reddit: > This article is overly hyperbolic. Some obscure subdomains of government websites are serving expired x509 certificates. They're not down and th
by aboutruby 8y ago
From reddit:
> This article is overly hyperbolic. Some obscure subdomains of government websites are serving expired x509 certificates. They're not down and this definitely doesn't compromise the encryption that protects any login credentials. Anyway, it is embarassing to see certificate renewal is not automated - it's something any good sysadmin would have set up.
https://www.reddit.com/r/technology/comments/aeps41/government_shutdown_tls_certificates_not_renewed/ https://www.reddit.com/r/technology/comments/aeps41/governme...
- TomK32 8y agoI've dealt with expired ssl certs on api servers run by school districts and no, they don't automate this stuff, neither do i for my own servers, shamefully.
- lowercased 8y agoi did some work for my state, and I couldn't automate ssl stuff, because the dept who handled the certs didn't provide for automation to be consumed - I got emailed certs (IIRC - been a couple of years now). By contrast, for most projects, I have standard cert/le automatically updating every 2-3 months. LE was just becoming a thing a couple years ago, and they'd never heard of it. I'm not saying they should all use LE, but the initial time investment of providing an automated process to renew and update via API would pay dividends in the long run (but the people that feel that the most don't have the clout/power to lobby for such things, usually).
- theartfuldodger 8y agoI work with many large health and insurance companies, although we recommend that this be automated and are fully capable, internal IT staff at the companies seem to need to complicate the matter for job security and require they are involved although we do all the certain, often they are delayed in action due to either incompetence or other job duties. Not surprising to me to see this is the case for local and federal govt too.
- eli 8y agoThey can’t spend any money right now, it would have to be prepaid not just auto-renewed
- Xylakant 8y agoSome of these pages are on he HSTS preload list. Browsers won’t let you manually click through to accept the expired cert. Those are effectively down for all intents and purposes.
- tyingq 8y agoNothing to do with SSL, but a fair amount of US government websites are hard down, on purpose, due to the funding dilemma. Like: https://www.data.gov https://www.data.gov "Due to a lapse in government funding all Data.gov websites will be unavailable until further notice." Which is pretty odd, because putting up these blocker pages probably costs more than just letting the sites run unattended.
- baddox 8y agoGovernment departments are legally required to budget for the possibility of a shutdown, which means they have to keep the money around that they will use to shut down. https://en.wikipedia.org/wiki/Antideficiency_Act https://en.wikipedia.org/wiki/Antideficiency_Act
- rplst8 8y agoYes, but this coupled with the fact they shut down things that don't otherwise really require a human to actively working proves that it's all just a political ploy.
- lowercased 8y agoSome bits no doubt require some human intervention, and if it wasn't updated, would cause confusion. The census site seems to be a decent middle ground. Banner at the top says "NOTICE: Due to a lapse in federal funding portions of this website are not being updated." Still functional, but if something's not updated, you know why.
- baddox 8y agoI don’t dispute that shutdowns are political ploys, but I don’t think that the actual implementations of shutting down are necessarily part of that ploy. Whether a human is required to run something is not the relevant factor. What’s relevant is the cost.
- sdenton4 8y agoWell, bandwidth isn't free... Replacing a larger site for large data downloads with a simple 404 will certainly bring down costs.
- renholder 8y ago>Anyway, it is embarassing to see certificate renewal is not automated - it's something any good sysadmin would have set up. From the original article[1]: "One such example is https://ows2.usdoj.gov https://ows2.usdoj.gov, a U.S. Department of Justice website which uses a certificate that expired in the week leading up the shutdown. The certificate has been signed by a trusted certificate authority, GoDaddy, but it has not been renewed since it expired on 17 December 2018." It was probably already renewed, there's just no sysadmin to import the fresh cert. =] [1] - https://news.netcraft.com/archives/2019/01/10/gov-security-falters-during-u-s-shutdown.html https://news.netcraft.com/archives/2019/01/10/gov-security-f...
- deleted 8y ago[deleted]
- lyagushka 8y agoOne thing that the shutdown is doing is exposing were we have over dependencies on government.
- willstrafach 8y ago> They're not down and this definitely doesn't compromise the encryption that protects any login credentials That is precisely what it does. Serving an invalid certificate and requiring user click-through allows for a man in the middle attacker to inject their own certificate without further error and will therefore be able to intercept login credentials.
- panarky 8y ago> it is embarrassing to see certificate renewal is not automated It's also pretty irresponsible to let certs get this close to expiration. Why weren't they renewed 60 days ago?
- walshemj 8y agoNo these days with the way browsers handle certs its effectively down. I handed this for one of the major beverage brands recently it was flagged when GA showed a massive decline - luckily it was one of the smaller noncore brands.