8 ms·
Expired SSL certificate
- seqizz 11y agoShould we set it to 1st of April?
- bitJericho 11y agoDon't pretty much all browsers let you accept using an expired certificate?
- ins0 11y agoYes was my thought also but put glasses on this workaround is even better, as it may scrow up more ssl certs from other domains.
- jonathonf 11y agoThe issue is with HSTS. If you've visited the site before you've likely cached that SSL is required and your browser will refuse to connect. Using e.g. a 'private window' will allow it to be bypassed.
- nileshtrivedi 11y ago> Using e.g. a 'private window' will allow it to be bypassed In Firefox, yes. But not in Chrome (in my experience).
- nailer 11y agoNot if you're using HSTS. Here's what the error looks like in current Chrome: https://certsimple.com/images/blog/hsts.png https://certsimple.com/images/blog/hsts.png
- jng 11y agoWhat is shocking is that they still haven't found the way to properly fix it after 3 days. I updated some SSL certificates last week (which even required contortions such as moving to a new issuer since some legacy software requires old-style SHA-1 signed ones which our current one doesn't provide), and it didn't take more than one (long) day of work.
- jonathonf 11y agoIt's just embarrassing. I can only assume the sysop is on holiday.
- josephmx 11y agoChecking their about page, they have 3 web developers, one of which wrote that post. That's worrying.
- vacri 11y agoThe available web developers may not have access to either the SSL vendor or where the certificate is stored. None of the front-end devs I work with have access to either of those things.
- IgorPartola 11y agoThe first problem is solved by getting a new vendor. The second, well someone has to have access to that.
- IgorPartola 11y agoAt this point, changing out a cert takes me about 15 minutes (typically for multiple servers). 10 of those is figuring out the order in which to include intermediate certs. I really should script that part out.
- lauriswtf 11y agoWhy is this on the frontpage?
- bitJericho 11y agoBecause it's kind of completely ridiculous; both the problem and the proposed solution.
- tommorris 11y ago...and the fact that it kind of suggests that you might not want to trust a Linux distro to get security right on your boxes if they are unable to fix their SSL certs after 3 days.
- creshal 11y agoManjaro had a rather… iffy relationship with developing a security mindset in the past: http://allanmcrae.com/2013/10/comparison-of-security-issue-handling/ http://allanmcrae.com/2013/10/comparison-of-security-issue-h... It appears they're not learning.
- jonathonf 11y agoThe two are not really related. With regards package updates, when Arch started publishing security update announcements Manjaro could start pushing those out faster. Delayed updates of other upstream packages is not really an issue (e.g. Ubuntu and CentOS have many packages that are not in sync with upstream).
- mahouse 11y agoBecause people are forgetting that the first rule of Hacker News is that no fun is allowed.
- billpg 11y agoI wonder if browsers should for (say) a week after a cert has expired, show an error so alarms are raised, but allow the dialog to be dismissed with an OK instead of all the "Confirm Security Exception" that would go on for a more serious cert rejection.
- ins0 11y agoThat is by far not the job of a browser to remind server administrators to renew there certs and display that message to random users.
- billpg 11y agoAlas, in this imperfect world, phone calls from random users are how server admins are notified of cert expiry.
- ins0 11y agoIn this "imperfect" world nowadays eveyone try to ship his responsability to someone else.
- billpg 11y agoI'll wait for someone else to respond to your comment.
- Piskvorrr 11y ago...where a 10-line cron script would have done the same job, in advance.
- jsight 11y agoAnd then the cron job (that only needs to work every few years) breaks and you find out about it after the fact when a user complains.
- 11y ago
- thejosh 11y agoWTF, changing your PC date is not a solution! This will cause more issues.
- Yeri 11y agoIndeed, what a silly workaround.
- ikt 11y agoI guess they should have just put a notice up saying forums and wiki unavailable, that could have prevented this whole mess.
- UnoriginalGuy 11y agoA much better workaround would have been to install SuperFish as that completely disables all certificate checking on SSL.
- phyzome 11y agoYeah, doesn't that generally result in a time mismatch? I thought the server and client had to roughly agree on the time.
- agarcia-deniz 11y agoI can't help but notice the motto: Enjoy the simplicity
- deleted 11y ago[deleted]
- bastomi29 11y agohttps://storify.com/gr4kjalan/misteri-gunung-semeru https://storify.com/gr4kjalan/misteri-gunung-semeru
- andygambles 11y agoAwesome
- HendrikR 11y agoThis is really awesome. Why do certificates expire in the first place?
- billpg 11y agoBy having an expiry, revoked certs can be forgotten about once the expiry has passed. We'd need to keep a forever growing list of revocations otherwise.
- legulere 11y agoAlso certs get switched to ones with stronger algorithms and longer keylengths after expiry. You also would have to revoke old certs all the time when their crypto isn't safe anymore.
- ntoshev 11y agoOur website monitoring service https://t1mr.com https://t1mr.com will warn you before your certificate expires (in addition to warning you when your site is down, and giving you reports of inbound and outbound dead links).
- falcolas 11y agoAs does nagios' http check with the -c option. Basic monitoring helps solve so many problems.
- abofh 11y ago30 minutes, comodo reseller, seriously; You won't get SHA256, but you won't be asking your users to hurt themselves.
- deleted 11y ago[deleted]
- Karunamon 11y agoRant mode: If I understand right, getting a replacement cert doesn't result in a change of the private key anyways. It's just magically, on the expiration date, your cert is somehow insecure and we must treat it as if YOU ARE IN DANGER!! - even though it's still better than then plain HTTP that everyone uses every single goddamned day. Hell, a self signed cert is better than plain HTTP, yet for some backwards-ass reason we treat it as worse, despite the fact it makes you immune from passive eavesdropping and any injection attacks, which the average person is a lot more likely to run into than a self-signed cert being used by an attacker to MITM you. CA's are a scam and a racket. I can't wait for Mozilla's Let's Encrypt[1] to come along and put them all out of business, hopefully before the last decade or so of training users to ignore the wolf-crying cert warnings comes to fruition. Yeah, this is irresponsible on Manjaro's part, they know the rules of the game, but the game is broken! [1] http://letsencrypt.org http://letsencrypt.org
- Zikes 11y agoSelf-signed can be worse because by the same token it can be MITM'd by another self-signed cert. It would create the false illusion of security, which could lead people to provide information they otherwise would not have.
- xg15 11y agoWith all due respect, how is that worse than HTTP? Plain HTTP can be MITMed just as well, only that on HTTP - except that no one would do that because for HTTP, plain old packet sniffing is enough to eavesdrop on a connection. Which doesn't work for self-signed HTTPS connections. And there are in fact a lot of common scenarios where it is easy for an attacker to sniff packets but harder to establish an MITM.
- icebraining 11y agoWorse in the sense that you expect an HTTPS connection to be secure, while you don't (or shouldn't!) expect an HTTP connection to be.