PDA

View Full Version : Expired SSL cert or just me



asmo
10-20-2014, 10:58
From a couple of different machines I show that the sites SSL cert is expired. Is this really the case?

00tec
10-20-2014, 11:00
Same here.

hghclsswhitetrsh
10-20-2014, 11:02
Will you explain to a dummy like me what that means exactly? I googled some stuff but not a while lot of sense was made.

drift_g35
10-20-2014, 11:06
Will you explain to a dummy like me what that means exactly? I googled some stuff but not a while lot of sense was made.

An SSL certificate is basically a cryptography layer between you and a website that confirms you are actually communicating with the website you think you are. It was to help prevent someone losing sensitive information when entering it into a website that was possibly hacked by someone trying to get that information.

This is the best "Simple" explanation I can give.

hghclsswhitetrsh
10-20-2014, 11:09
Roger. Makes sense. I won't use my SSN for a password anymore.

HoneyBadger
10-20-2014, 11:21
Yep, I'm getting it too.

mcantar18c
10-20-2014, 11:55
I'm on tapatalk, not seeing any notifications.

davsel
10-20-2014, 12:06
Started getting it a few minutes ago.
[panic]

Irving
10-20-2014, 12:10
Someone just bought a Tavor with my bank card.

sellersm
10-20-2014, 12:11
Yup, same here. Chrome keeps "warning" me...

StagLefty
10-20-2014, 12:12
Yup-Chrome keeps warning me.

DeadElephant
10-20-2014, 13:50
Damn ObamaCare!

cfortune
10-20-2014, 14:30
Cert just expired at 10:00 something AM today and trot is right, no difference in the security of the site prior to 10:00.

When you do a renewal, make sure to have your certificate authority do a SHA-256 certificate. Chrome and local cert stores for Microsoft (I think anyway, haven't looked too much into this) will start throwing certificate errors sometime in November. That's what Google has ball parked for their release which will enforce this. I just got done replacing all our certificates at work because of this.

Also, SSL v3 has a vulnerability right now and TLS without v3 fallback should be configured.

J
10-20-2014, 17:16
Yeah. Will have it replaced tonight.

It will be forward compatible

J
10-20-2014, 17:34
AAAANNNNNDDDDD.... Fixed.

hghclsswhitetrsh
10-20-2014, 17:36
Sweet I will change my password back to my SSN.

Seriously though, thanks J.

cfortune
10-20-2014, 18:05
Thanks J!

J
10-20-2014, 18:15
And SSLv3 disabled now too. Not that I worry about it as much here, we are providing basic privacy security for posters, not protecting financial or ultra-sensitive information. Had already done that on all of my eCommerce sites/clients.

HoneyBadger
10-20-2014, 22:20
Damn ObamaCare!
I vote for this as the best post in the thread!

Guahan671
10-21-2014, 11:20
[Coffee]got that yesterday and figured it would go away, so here I am back on... good thing I came here first, was gonna post something like this... oh well, Good Day All.

cfortune
10-21-2014, 11:29
And SSLv3 disabled now too. Not that I worry about it as much here, we are providing basic privacy security for posters, not protecting financial or ultra-sensitive information. Had already done that on all of my eCommerce sites/clients.

Yeah, I neglected to add "not that it matters much for this site".

DeusExMachina
10-23-2014, 09:21
Cert just expired at 10:00 something AM today and trot is right, no difference in the security of the site prior to 10:00.

When you do a renewal, make sure to have your certificate authority do a SHA-256 certificate. Chrome and local cert stores for Microsoft (I think anyway, haven't looked too much into this) will start throwing certificate errors sometime in November. That's what Google has ball parked for their release which will enforce this. I just got done replacing all our certificates at work because of this.

Also, SSL v3 has a vulnerability right now and TLS without v3 fallback should be configured.

This is good advice. The new certificate is unfortunately SHA1 still. Edit: Nevermind, was looking at the thumbprint.