4 ms·
No, the issue is not with the trust paths. The old 1024-bit root is in Mozilla's trust store, where it's a danger to everyone. SSL Labs reuses their store, whic
by ivanr 13y ago
No, the issue is not with the trust paths. The old 1024-bit root is in Mozilla's trust store, where it's a danger to everyone. SSL Labs reuses their store, which is why the weak root shows up in the trust paths.
Technically, the F for blogs.akamai.com was a bug (now corrected; the grade after the fix is C). I say "technically" not because I approve of export cipher suites, but because the implementation did not follow the documentation (the rating guide, linked from every report). Export suites are hopelessly weak and will be treated more harshly in the next guide revision. The new grade is certainly not something to be happy about.