2 ms·
After reading both blog posts, I still didn't know exactly what the heck actually happened, so I downloaded node.js 0.11.9 (released in November 2013 but not th
by rwg 13y ago
After reading both blog posts, I still didn't know exactly what the heck actually happened, so I downloaded node.js 0.11.9 (released in November 2013 but not the latest version) and ran "npm config get ca" to see what npm's default trusted certificate store used to be. There were four certificates:
• an "npm Certificate Authority" X.509v1 certificate valid from 2011-09-05 (an X.509v1 cert in 2011? srsly?)
• two of GlobalSign's Root CA certificates
• a GlobalSign subordinate CA certificate
What I'm guessing happened is that the certificate https://registry.npmjs.org https://registry.npmjs.org used a long time ago was signed by that "npm Certificate Authority" certificate. Then they switched to a signed-by-GlobalSign certificate. Then, two days ago, they switched to an EV certificate from DigiCert, and that's when all hell broke loose for people not using the latest version of npm because not-latest versions of npm would only trust certificates that chained up to GlobalSign's Root CAs or the "npm Certificate Authority."
If I'm right about what happened, then the brunt of this kerfuffle might've been avoided by making ca="" the default in npm releases as soon as the GlobalSign-signed certificate hit production and everyone was happy that it was working. Hindsight is 20/20 like that, though.
- seldo 13y agoThat is pretty much exactly correct.