invalid cert for https://us.metamath.org/

55 views
Skip to first unread message

Glauco

unread,
Dec 11, 2021, 10:38:33 AM12/11/21
to Metamath
Am I the only one getting an invalid cert error?

This is not new, but I've never written about it before.

I've tried Chrome and Edge on Win10 and Firefox on Linux. Similar errors.

I can go beyond the warning messages, selecting kind of "go on anyway (go back recommended)" options.

The timespan is valid, I've not investigated if the root CA or the intermediate cert is the "invalid" one.

Below, the details from Firefox under Linux ("requested domain name does not match the server’s certificate")

Glauco

*** detailed error message from Firefox under Linux ***

https://us.metamath.org/mpeuni/supxrleub.html



Unable to communicate securely with peer: requested domain name does not match the server’s certificate.



HTTP Strict Transport Security: false

HTTP Public Key Pinning: false



Certificate chain:



-----BEGIN CERTIFICATE-----

MIIFJjCCBA6gAwIBAgISBFunoJW6i3kKnjubLKCE0TeeMA0GCSqGSIb3DQEBCwUA

MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD

EwJSMzAeFw0yMTExMDIyMjA1NDBaFw0yMjAxMzEyMjA1MzlaMBsxGTAXBgNVBAMT

EHNzbC5tZXRhbWF0aC5vcmcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB

AQCzqmnOVn7t//By9YhUHSfcZv+PrLs+46go7VhkwzJnpW0/9w5FCxRcJlpZUSsW

U+XzL+ZRR1C0z3Y77ONzJVyo0BMu7Fnd+nvdovOP5/vfx5EmGWndaEMQcLK3Vk0X

5e4VNIYNYNTZEOIMgmZQupcN88MwXClcJB32bPr1oA/Fl1rImG7mS9c4nrgsGQON

LWGOF2Me1lsBYVGN4BaNvVqDf8ko+Kc6CHyahsnFqJhLqtJbhypvCZqz9MxQKU2w

+pgWDVHjVR96LKnAq8XytYloF157JQ/gngcA6Jyy8zdNxOL/ghnb8oC17E9xolYT

QtDW7k8AJk/vRxzUAR2ko52fAgMBAAGjggJLMIICRzAOBgNVHQ8BAf8EBAMCBaAw

HQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwHQYD

VR0OBBYEFGwFrmA15j77JwB1agAOwKylf5WOMB8GA1UdIwQYMBaAFBQusxe3WFbL

rlAJQOYfr52LFMLGMFUGCCsGAQUFBwEBBEkwRzAhBggrBgEFBQcwAYYVaHR0cDov

L3IzLm8ubGVuY3Iub3JnMCIGCCsGAQUFBzAChhZodHRwOi8vcjMuaS5sZW5jci5v

cmcvMBsGA1UdEQQUMBKCEHNzbC5tZXRhbWF0aC5vcmcwTAYDVR0gBEUwQzAIBgZn

gQwBAgEwNwYLKwYBBAGC3xMBAQEwKDAmBggrBgEFBQcCARYaaHR0cDovL2Nwcy5s

ZXRzZW5jcnlwdC5vcmcwggEEBgorBgEEAdZ5AgQCBIH1BIHyAPAAdgDfpV6raIJP

H2yt7rhfTj5a6s2iEqRqXo47EsAgRFwqcwAAAXzi5qrcAAAEAwBHMEUCIAOWXG4I

mm1d+bbnNOQpyAP+Yq3KZU/5g83sjg4+XYjGAiEAmyGwFx35yghJF4EUWX+1wJBj

wy3XUlmIRUvjnZVfZ3sAdgApeb7wnjk5IfBWc59jpXflvld9nGAK+PlNXSZcJV3H

hAAAAXzi5qrRAAAEAwBHMEUCIAyloDw8nKS2A6HmTs+DJSBpEmWSwKnPMHyE1aC+

kBLAAiEAgNSzsmYUEfqippC8FYamOzpQH9BGFSrWYf9BwgXCFrUwDQYJKoZIhvcN

AQELBQADggEBAKFXGRKFZQ3WXch1xUXpaHHUa/lPfA2TEcy2zxgnEp3cbs+9AH11

XOmoeMJFJpJMH9IL+UU7zyRNK1wSc4MgMNNd0hQ3EAis+2YORjfgfbl/gous4Qod

ocBNVI30KJP9us9Hy3Z0HmozoJXPN6nxWXw2GCPe9FL9WsBTGfDaspAc/e9QkjPd

MfIIMJVX9eAfgjQhDvxt6A37W6PWQIjJPrOW049cUtKIes3GOGlw8GPKLQ/e3eul

Y5vNLANLg7/hr/BtUYoNLxvN2oo9SxASWXQHL608xiflfBB9rhlTOexZok7IWLz1

KXfIVqR53bdETuqZC8riOxQPk0M8hppDY3U=

-----END CERTIFICATE-----

-----BEGIN CERTIFICATE-----

MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw

TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh

cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw

WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg

RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK

AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP

R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx

sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm

NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg

Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG

/kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC

AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB

Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA

FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw

AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw

Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB

gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W

PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl

ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz

CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm

lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4

avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2

yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O

yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids

hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+

HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv

MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX

nLRbwHOoq7hHwg==

-----END CERTIFICATE-----

-----BEGIN CERTIFICATE-----

MIIFYDCCBEigAwIBAgIQQAF3ITfU6UK47naqPGQKtzANBgkqhkiG9w0BAQsFADA/

MSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMT

DkRTVCBSb290IENBIFgzMB4XDTIxMDEyMDE5MTQwM1oXDTI0MDkzMDE4MTQwM1ow

TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh

cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwggIiMA0GCSqGSIb3DQEB

AQUAA4ICDwAwggIKAoICAQCt6CRz9BQ385ueK1coHIe+3LffOJCMbjzmV6B493XC

ov71am72AE8o295ohmxEk7axY/0UEmu/H9LqMZshftEzPLpI9d1537O4/xLxIZpL

wYqGcWlKZmZsj348cL+tKSIG8+TA5oCu4kuPt5l+lAOf00eXfJlII1PoOK5PCm+D

LtFJV4yAdLbaL9A4jXsDcCEbdfIwPPqPrt3aY6vrFk/CjhFLfs8L6P+1dy70sntK

4EwSJQxwjQMpoOFTJOwT2e4ZvxCzSow/iaNhUd6shweU9GNx7C7ib1uYgeGJXDR5

bHbvO5BieebbpJovJsXQEOEO3tkQjhb7t/eo98flAgeYjzYIlefiN5YNNnWe+w5y

sR2bvAP5SQXYgd0FtCrWQemsAXaVCg/Y39W9Eh81LygXbNKYwagJZHduRze6zqxZ

Xmidf3LWicUGQSk+WT7dJvUkyRGnWqNMQB9GoZm1pzpRboY7nn1ypxIFeFntPlF4

FQsDj43QLwWyPntKHEtzBRL8xurgUBN8Q5N0s8p0544fAQjQMNRbcTa0B7rBMDBc

SLeCO5imfWCKoqMpgsy6vYMEG6KDA0Gh1gXxG8K28Kh8hjtGqEgqiNx2mna/H2ql

PRmP6zjzZN7IKw0KKP/32+IVQtQi0Cdd4Xn+GOdwiK1O5tmLOsbdJ1Fu/7xk9TND

TwIDAQABo4IBRjCCAUIwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYw

SwYIKwYBBQUHAQEEPzA9MDsGCCsGAQUFBzAChi9odHRwOi8vYXBwcy5pZGVudHJ1

c3QuY29tL3Jvb3RzL2RzdHJvb3RjYXgzLnA3YzAfBgNVHSMEGDAWgBTEp7Gkeyxx

+tvhS5B1/8QVYIWJEDBUBgNVHSAETTBLMAgGBmeBDAECATA/BgsrBgEEAYLfEwEB

ATAwMC4GCCsGAQUFBwIBFiJodHRwOi8vY3BzLnJvb3QteDEubGV0c2VuY3J5cHQu

b3JnMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly9jcmwuaWRlbnRydXN0LmNvbS9E

U1RST09UQ0FYM0NSTC5jcmwwHQYDVR0OBBYEFHm0WeZ7tuXkAXOACIjIGlj26Ztu

MA0GCSqGSIb3DQEBCwUAA4IBAQAKcwBslm7/DlLQrt2M51oGrS+o44+/yQoDFVDC

5WxCu2+b9LRPwkSICHXM6webFGJueN7sJ7o5XPWioW5WlHAQU7G75K/QosMrAdSW

9MUgNTP52GE24HGNtLi1qoJFlcDyqSMo59ahy2cI2qBDLKobkx/J3vWraV0T9VuG

WCLKTVXkcGdtwlfFRjlBz4pYg1htmf5X6DYO8A4jqv2Il9DjXA6USbW1FzXSLr9O

he8Y4IWS6wY7bCkjCWDcRQJMEhg76fsO3txE+FiYruq9RUWhiF1myv4Q6W+CyBFC

Dfvp7OOGAN6dEOM4+qR9sdjoSYKEBpsr6GtPAQw4dy753ec5

-----END CERTIFICATE-----





Ken Kubota

unread,
Dec 11, 2021, 10:49:49 AM12/11/21
to meta...@googlegroups.com
The certificate is issued for ssl.metamath.org only.

You should add us.metamath.org (and possible other domains) as alternative DNS extension.

____________________________________________________

Ken Kubota
https://doi.org/10.4444/100



--
You received this message because you are subscribed to the Google Groups "Metamath" group.
To unsubscribe from this group and stop receiving emails from it, send an email to metamath+u...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/metamath/80c1a912-38fc-4f7c-9da1-9efd2ffb9b70n%40googlegroups.com.

Glauco

unread,
Dec 11, 2021, 11:08:07 AM12/11/21
to Metamath
Thank you, Ken

I can live with that warning message, the problem is that the newcomer would not be positively impressed (I guess).

Is there a reason why Let's encrypt cannot be used to get a cert for us.metamath.org ? (it looks like it's the most common result from Google).

And, if I'm not mistaken, Let's encrypt allows for wildcard certs, now:


Thanks again
Glauco

David A. Wheeler

unread,
Dec 13, 2021, 1:22:55 PM12/13/21
to Metamath Mailing List


> On Dec 11, 2021, at 11:08 AM, Glauco <glaform...@gmail.com> wrote:
>
> Thank you, Ken
>
> I can live with that warning message, the problem is that the newcomer would not be positively impressed (I guess).
>
> Is there a reason why Let's encrypt cannot be used to get a cert for us.metamath.org ? (it looks like it's the most common result from Google).
>
> And, if I'm not mistaken, Let's encrypt allows for wildcard certs, now:
>
> https://community.letsencrypt.org/t/acme-v2-production-environment-wildcards/55578

We definitely need to fix up our HTTPS story. Really, we should serve everything from HTTPS,
and the only plausible use for HTTP should be redirecting to HTTPS.
There are malicious actors who inject nasty content in HTTP nowadays as man-in-the-middle attacks :-(.

However, I expect complicates due to Norman Megille's recent death. Please be patient :-).

--- David A. Wheeler

Reply all
Reply to author
Forward
0 new messages