Web site access and Firefox 60.0b4

poppageek
poppageek
Joined: 13 Aug 10
Posts: 259
Credit: 2473733872
RAC: 0
Topic 214029

FYI

Firefox has started complaining since last update. Used Chrome to post this as cannot find a way to ignore the warning.

--------------------------------------------------------------------------------------------------------------------------------------

einsteinathome.org uses an invalid security certificate. The certificate is not trusted because the issuer certificate is unknown. The server might not be sending the appropriate intermediate certificates. An additional root certificate may need to be imported. Error code: SEC_ERROR_UNKNOWN_ISSUER

 

https://einsteinathome.org/account/dashboard

Peer’s Certificate issuer is not recognized.

HTTP Strict Transport Security: true HTTP Public Key Pinning: false 

---------------------------------------------------------------------------------------------------------------------------------------

 

Cheers!

 

poppageek
poppageek
Joined: 13 Aug 10
Posts: 259
Credit: 2473733872
RAC: 0

I reported this to

I reported this to Firefox.

 

Cheers!!

Shawn Kwang
Shawn Kwang
Joined: 3 Nov 15
Posts: 289
Credit: 3115127
RAC: 1680

poppageek wrote:FYI Firefox

poppageek wrote:

FYI

Firefox has started complaining since last update. Used Chrome to post this as cannot find a way to ignore the warning.

--------------------------------------------------------------------------------------------------------------------------------------

einsteinathome.org uses an invalid security certificate. The certificate is not trusted because the issuer certificate is unknown. The server might not be sending the appropriate intermediate certificates. An additional root certificate may need to be imported. Error code: SEC_ERROR_UNKNOWN_ISSUER

 

https://einsteinathome.org/account/dashboard

Peer’s Certificate issuer is not recognized.

HTTP Strict Transport Security: true HTTP Public Key Pinning: false 

---------------------------------------------------------------------------------------------------------------------------------------

Cheers!

 

I believe the problem is due to Google distrusting Symantec. https://security.googleblog.com/2017/09/chromes-plan-to-distrust-symantec.html. Mozilla is following Google in distrusting the same Web certificates.

We are aware of this problem and actively trying to solve it. Unfortunately it is complicated by the fact that a number of users have installed an older BOINC client, where the new certificates, which don't give this error, will not work.

PS- contacting Mozilla (Firefox) may not help. The problem is project/server-side.

Einstein@Home Project

Stef
Stef
Joined: 8 Mar 05
Posts: 206
Credit: 110568193
RAC: 0

When chrome 66 will be

When chrome 66 will be released (17. Apr) people won't be able to access einsteinathome.org anymore.

https://knowledge.rapidssl.com/support/ssl-certificate-support/index?page=content&id=ALERT2566&actp=LIST&viewlocale=en_US

 

Shawn Kwang
Shawn Kwang
Joined: 3 Nov 15
Posts: 289
Credit: 3115127
RAC: 1680

Stef_5 wrote:When chrome 66

Stef_5 wrote:

When chrome 66 will be released (17. Apr) people won't be able to access einsteinathome.org anymore.

https://knowledge.rapidssl.com/support/ssl-certificate-support/index?page=content&id=ALERT2566&actp=LIST&viewlocale=en_US

 

Thanks, we are aware of this and have posted a News item about it. We plan to update our certificate April 16.

Einstein@Home Project

Gary Roberts
Gary Roberts
Moderator
Joined: 9 Feb 05
Posts: 5874
Credit: 118445238386
RAC: 25916763

Shawn Kwang wrote:...

Shawn Kwang wrote:
... Unfortunately it is complicated by the fact that a number of users have installed an older BOINC client, where the new certificates, which don't give this error, will not work.

How old is "older BOINC client"?  I'm deploying the new bundle to a bunch of hosts with 7.2.42 clients (Linux).  Is that going to be a version that "will not work"?

Thanks for any response about this.

 

Cheers,
Gary.

Shawn Kwang
Shawn Kwang
Joined: 3 Nov 15
Posts: 289
Credit: 3115127
RAC: 1680

Gary Roberts wrote:How old

Gary Roberts wrote:

How old is "older BOINC client"?  I'm deploying the new bundle to a bunch of hosts with 7.2.42 clients (Linux).  Is that going to be a version that "will not work"?

Thanks for any response about this.

 

Gary,

I think you asked this in the News thread, but I'll answer it here too. It's my understanding that Linux clients running v 7.2 and older should still work. This is because Linux BOINC clients should use the system's CA bundle installed by the Linux distribution. I say should because there are always exceptions.

It's mainly Windows and MacOS older BOINC clients that use the CA bundle. Again this is a blanket statement and the one thing I've learned in this work is that exceptions abound.

It's like spelling in English: 'i' before 'e' except after 'c', or when the 'i' just feels like going first because it wants to: (science, laciest), or they switch positions because they can (foreign, weird).

Einstein@Home Project

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.