15 ms·
addons.thunderbird.net SSL certificate has expired
- tialaramex 5y agoInteresting. That's an (expired) Cloudflare certificate, and those are Cloudflare IP addresses I'm being sent to. I wonder if Cloudflare broke this somehow (whoops) or if Thunderbird themselves screwed up here. I don't see a CAA record that would tell DigiCert they can't issue this either.
- xPaw 5y agoIt is indeed Cloudflare, very strange. > curl -k https://addons.thunderbird.net/cdn-cgi/trace https://addons.thunderbird.net/cdn-cgi/trace
- Namidairo 5y agoLooks like Lets Encrypt R3 to me, with a very recent issuance time. Resolved, probably?
- zinekeller 5y agoYes. Okay, is DigiCert having problems today? That's CloudFlare's primary provider, so the LE certificate might be a stop-gap applied by CF.
- tialaramex 5y agoBut that's a much bigger problem that it might appear. If Cloudflare gets right to the wire and then is like "Oh, DigiCert couldn't issue for whatever reason" then that's a process problem at Cloudflare not DigiCert. A reasonable strategy is to renew say, 30 calendar days in advance. But that would mean Cloudflare (or at least, some automated system that nobody was looking at) knew 30 days ago this would happen and nothing was done about it.
- wila 5y agoPerhaps that's why it was broken? I only see certificate issuances from Let's Encrypt. https://crt.sh/?q=addons.thunderbird.net https://crt.sh/?q=addons.thunderbird.net
- tialaramex 5y agoThe Cloudflare certificate which expired was for *.thunderbird.net which you will be able to find in crt.sh for yourself - and was issued a year ago under Cloudflare's intermediate† None of those R3 certificate expire today, and the expired cert I was originally served when this was a fresh news item was from that Cloudflare intermediate CA under DigiCert. It's possible that normally Thunderbird has Cloudflare trust their backends via the Let's Encrypt certificate rather than using Cloudflare's private "origin" CA for that purpose. That would give them the flexibility to cut Cloudflare out of the loop if necessary. But what exactly happened here I expect we'll learn in a post-mortem. † I assume but don't know for certain that in fact DigiCert operates this intermediate CA simply on behalf of Cloudflare but entirely on their own premises and with them ensuring its obeys the CA/B BRs and other trust store policies. I think the idea of letting somebody else operate unconstrained intermediates with them doing all the work died out after it sank Symantec.
- wila 5y agoAhh yes that makes perfect sense, thanks. I do indeed see the Cloudflare one from a year ago. Seems it was now renewed as a Let's Encrypt one.
- swiley 5y agoSo you're really trusting Cloudflare and not Mozilla but no one using the MUA is really told that. Why bother encrypting anything at this point of the connections are going to be terminated somewhere in the network anyway?
- tialaramex 5y agoMozilla decided to trust Cloudflare. So you're still just trusting Mozilla. Companies have lots of suppliers.
- xbenjii 5y agoSame with the main domain too www.thunderbird.net
- briffle 5y agoLooks like they have corrected it by moving to a letsEncrypt certificate for the main www.thunderbird.net domain.
- beardedwizard 5y agoMozilla seems to repeatedly suffer this[1]. I wonder what solution they use for expiry monitoring. 1: https://www.computerworld.com/article/3393446/mozilla-issues-fix-after-it-lets-cert-expire-and-firefox-add-ons-go-belly-up.html https://www.computerworld.com/article/3393446/mozilla-issues...
- thehodge 5y agoIf anyone from Mozilla is reading, I’d be happy to donation a littlewarden.com account for this very purpose. (Contact details in profile)
- stevenjohns 5y agoJust before you do, have a read through who Mozilla is in 2021[0] > "Mitchell Baker, Mozilla's top executive, was paid $2.4m in 2018, [...] Payments to Baker have more than doubled in the last five years." > "Mozilla recently announced that they would be dismissing 250 people." [0] https://calpaterson.com/mozilla.html https://calpaterson.com/mozilla.html
- seoaeu 5y agoI never understood why people were so upset at Mozilla's CEO earning a couple million per year in salary. Seems like a rather reasonable rate for running a medium size company that doesn't give out stock options/RCUs
- lowercased 5y agoI suspect it's at least partially the 'giving a raise/increase while also firing people at the same time' optics which doesn't sit well with folks. It doesn't actually strike me as 'reasonable rate' for a company which is losing market share with their main products, has a history of multiple failed product/service launches, and is having to fire people to cut costs. I (and many others) could get the same results for a mere $700k/year.
- throw37388 5y agoAny good email client alternatives?
- sdevonoes 5y agoI know little about SSL certificates. Could someone tell me why they should expire regularly? Is it for precaution? Is it just because "good practices". What's the difference (from a security point of view) between a certificate that expires in 3 months and one that expires in 3 years?
- zorr 5y agoIt's mostly to limit the damage in case of compromise and to encourage automation. Let's Encrypt explains their choice for 90day certificates here: https://letsencrypt.org/2015/11/09/why-90-days.html https://letsencrypt.org/2015/11/09/why-90-days.html edit: With 3 year certificates there is also a greater risk for certificates expiring unexpectedly because the renewal process happens so infrequently. The person with the knowledge on the renewal process might not be at the company anymore by the time the certificate expires.
- cm2187 5y agoAnd in the case of letsencrypt to encourage the automation of the renewal process.
- gchamonlive 5y agoI don't know for the rest, but for letsencrypt you don't even have an option to set the expiration date, as far as I know. You have to make sure certificates generated there are regularly refreshed (every three months). So it might well be an imposition from the Certificate Authority.
- brinox 5y agoEven if your certificate expires after 3 years, the certificate renewal process should be automated. The long validity of 3 years leads many people to not consider this necessary. If the certificate is only valid for three months however, many people will automate the renewal right away, because nobody wants to do this manually every couple weeks. From a security POV, shorter lifetimes require more periodic checks for the server's identity. E. g. a Letsencrypt-issued certificate using the ACME protocol will validate the server really belongs to the given domain more often, which is a nice property I think.
- progx 5y agoWhat can go wrong will go wrong.
- teddyh 5y agoFixed now.