IWETHEY v. 0.3.0 | TODO
1,095 registered users | 1 active user | 1 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Sectigo's SHA-1 root + intermediate certs expired.
The fix will be messy as the root cert lists for the OS and each application/service that brings its own will need updating.
New I don't think that's all that happened.
The server certs we're having issues with are GlobalSign and DigiCert, not Sectigo, and the problems are intermittent.

The client OS in question has updated certs and is on OpenSSL 1.1.1.

I manually removed the AddTrust certs but that didn't help either.
Regards,
-scott
Welcome to Rivendell, Mr. Anderson.
     I'm back; this time re "Sectigo" - (Ashton) - (21)
         Sounds like an update is needed. - (static)
         Also, thanks. - (static)
         Wade is likely right + couple of things to check - (scoenye) - (3)
             Going there: - (Ashton) - (2)
                 Don't nuke the CUPS certificate - (scoenye) - (1)
                     Gracias.. - (Ashton)
         Here's a page that might help, if you can get there. - (Another Scott) - (1)
             Hm: gives important also-too CLUE! (Can't Go-->There, either) - (Ashton)
         Something happened with SSL certs yesterday - (malraux) - (11)
             Thanks.. helps out, 'the Loneliness of the Long-distance tyro-Debugger .. a bit :-) -NT - (Ashton) - (10)
                 major cert trust domain issue yesterday - (boxley) - (9)
                     CRL lookup service blowout? The only thing I can think of that would cause widespread mayhem. -NT - (scoenye) - (3)
                         Heh.. that moniker sent moi --> Belgium and a ∆ re (my) access to Sectigo. - (Ashton) - (2)
                             That is what is going on - (scoenye) - (1)
                                 Excellent--Lots of peripheral info there too; Bonus. -NT - (Ashton)
                     Still going on. - (malraux) - (4)
                         we use a gummint cert internal to ourselves - (boxley) - (3)
                             We didn't have browser issues - (malraux) - (2)
                                 Sectigo's SHA-1 root + intermediate certs expired. - (scoenye) - (1)
                                     I don't think that's all that happened. - (malraux)
         Teapot; Tempest-in: Thanks all! stuff works. The post-mortem amusement awaits.. -NT - (Ashton)

Powered by zeptotechnology!
80 ms