Hacker News new | past | comments | ask | show | jobs | submit login

I can proceed if I add an exception. But I don't know if I want to add an exception.

Edit: Clock is automatically set via OSX. Not a problem with other sites.

Firefox says

tails.boum.org uses an invalid security certificate. The certificate is not trusted because the issuer certificate is unknown. The server might not be sending the appropriate intermediate certificates. An additional root certificate may need to be imported. (Error code: sec_error_unknown_issuer)

Sooooo..... I need a root certificate of some sort then? See, this is what we get to contend with - I can't read this site because reasons. And it's up to me to find out what the reasons are I guess. Wait till this hits the masses when certs get revoked, expire, etc. :)




And you shouldn't - this page uses a valid certificate for me. Either your clock is set wrong, you're missing CAs or you're being MITM'd. Verify your time, check the certificate chain on the site (should be UserTrust -> Gandi -> site) and try to check fingerprints against https://www.grc.com/fingerprints.htm if you can.


Yeah.. That's suspicious.. Firefox uses it's own CA list, so if your install of firefox is up to date, and your system clock is correct then you are potentially being MITM'd...

If that is the case then your browser is exhibiting correct behavior.

For me, I can see that the root CA is USERTrust (SHA-384 sig, interestingly), and the server is presenting a valid intermediate (Gandi - also using a SHA-384 signature), then the site certificate (SHA-256 sig).

There is a secondary certification path though, coming from a old SHA1 AddTrust Root (but this is also in my trust store for Firefox).


Same results on Chrome. I am not on a corporate network - I am at home.

Are there tools I can use to work my way through this?


Odd. Chrome also uses it's own trust store, distinct from system and Firefox..

OpenSSL is a good starting point:

openssl s_client -connect tails.boum.org:443


type 'danger' on the warning page


Did you resolve this? Make sure the root that shows up on the certificate details page is UserTrust - if it's not, it's possible someone is performing MITM on you.

SHA-256 Fingerprint for tails.boum.org should be:

F8:DC:67:21:96:77:46:F5:9D:77:BD:7B:87:C1:39:42:C8:4E:4B:25:97:34:AC:E2:80:24:99:35:D9:81:9C:B6

If that doesn't match the value you see in the Firefox or Chrome certificate details page, please, send as many details about the chain as you can back, I'm very interested to see what's happening here considering you're not on a corp network and seeing this and even moreso because this is the Tails site, something that might very much interest some attackers...


I had a bunch of work to get to today, so I just didn't have time to mess with this.

But the problems seem to have gone away.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: