5 ms·
Huawei is alerting for me. www.huawei.com 0 Actalis Authentication Root CA F373B387065A28848AF2F34ACE192BDDC78E9CAC
by BasicObject 7y ago
Huawei is alerting for me.
www.huawei.com 0 Actalis Authentication Root CA F373B387065A28848AF2F34ACE192BDDC78E9CAC
- c0nducktr 7y agoThat one is alerting for me as well. Same thumbprint.
- vxxzy 7y agosame on my end. same thumbprint.
- throwaway288383 7y agowww.huawei.com 0 Actalis Authentication Root CA F373B387065A28848AF2F34ACE192BDDC78E9CAC same for me is there reason why though?
- throwaway1777 7y agoWho’s your isp?
- tialaramex 7y agoSo what that means is that this software expected to see some other certificate but instead it saw this one. huawei has had a considerable number of wildcard (*.huawei.com) certificates issued for whatever reason (configuration screw-up, somebody press the button too many times, different teams with same job, this happens) and you can see a bunch of them here: https://crt.sh/?q=huawei.com https://crt.sh/?q=huawei.com The software's assumption is that (for some sites at least) the author can check what the "right" certificate is and if you see a different one that's wrong. That clearly won't work for some sites any of the time, they use a CDN to present different behaviour including certificates in different places, and presumably the author weeds those out. But as we see here it can't work for _any_ site all the time, it will be inconsistent.
- oefrha 7y ago> a considerable number of wildcard (*.huawei.com) certificates issued for whatever reason... Is there any downside to this? I mean, I have several wildcard certs issued for each of my personal domains mainly because it's more convenient to get separate certs on each host with certbot than trying to sync certs from one host to another. Is there any reason I shouldn't do this?
- tialaramex 7y agoYes, but the downside may be acceptable to you. A bad guy who gets any of the private keys associated with any of these certificates can use that to impersonate any service with the corresponding name, even a quite different one. So say you've got mail.oefrha.example that's a mail server using a *.oefrha.example cert, and the Dread Pirate Roberts breaks into it, they can use that when impersonating your web server www.oefrha.example or your Q&A site faq.oefrha.example even if those are on totally different hardware that Roberts wasn't able to penetrate. For older TLS (or SSL) versions there's a trick called implied authentication used with RSA. After showing the certificate, instead of your server signing something to prove it knows the corresponding private key, the client sends something across which your server decrypts. Only the real server could decrypt it with the private key to continue the conversation so authentication is implied. However, in doing this your server has to be _extremely careful_, because it's easy to give away information when things go wrong. If it's not careful enough, a bad guy doesn't learn the key but they can use your answers to work out how you'd sign RSA messages. This means if you've got old-crap.oefrha.example which does TLS 1.0 with crappy RSA implied auth enabled so as to make it work with some rotten turn of the century tech, and it has a wildcard certificate, some bad guys can maybe exploit that to pretend they are www.oefrha.example even though your actual www.oefrha.example web server only speaks TLS 1.2 or newer with elliptic curves. You say a "personal domain", and I don't recognise your name, so chances are that this just doesn't matter. We're not talking about something a bored teenager can do, but if real bad guys with resources are attacking you, then it's probably not a smart idea to have so many wildcards. Edited: Repeatedly to try to get HN's half-arsed parser to stop ruining everything. Gave up. HN use a parser that has working escapes, or remove the parser and just say the site only has text too bad.
- acdha 7y ago