IMPORTANT: Certificate for www.vim.org has expired.

153 views
Skip to first unread message

Paul

unread,
Sep 9, 2023, 10:33:59 AM9/9/23
to vim...@googlegroups.com
PLEASE DO NOT CLICK ON ANYTHING IN THIS EMAIL THAT RENDERS AS A LINK.

That said, this is nothing to panic about. However, the www.vim.org
certificate appears to have expired at Fri, 08 Sep 2023 04:38:42 GMT.

I am posting this to alert to the community and those in a position to
work on fixing the problem.

It is unlikely, but possible that the certificate is OK and I am a
victim, hence do not trust any link in this email and do not hit your
client's replay button.

--

Paul

Christian Brabandt

unread,
Sep 10, 2023, 12:49:37 PM9/10/23
to vim...@googlegroups.com
Hi,
thanks. I wasn't aware of this. I need to find out who used to manage
the SSL Certs. I am afraid this was done by Bram. May take a while until
this get's resolved :(

Thanks,
Chris
Mit freundlichen Grüßen
Christian
--
The mosquito exists to keep the mighty humble.

Marvin Renich

unread,
Sep 10, 2023, 1:05:45 PM9/10/23
to vim...@googlegroups.com
* Christian Brabandt <cbl...@256bit.org> [230910 12:49]:
> Hi,
> thanks. I wasn't aware of this. I need to find out who used to manage
> the SSL Certs. I am afraid this was done by Bram. May take a while until
> this get's resolved :(
>
> Thanks,
> Chris
>
> On Sa, 09 Sep 2023, Paul wrote:
>
> > PLEASE DO NOT CLICK ON ANYTHING IN THIS EMAIL THAT RENDERS AS A LINK.
> >
> > That said, this is nothing to panic about. However, the www.vim.org
> > certificate appears to have expired at Fri, 08 Sep 2023 04:38:42 GMT.
> >
> > I am posting this to alert to the community and those in a position to work
> > on fixing the problem.
> >
> > It is unlikely, but possible that the certificate is OK and I am a victim,
> > hence do not trust any link in this email and do not hit your client's
> > replay button.

This is very odd. Is www.vim.org served by multiple hosts behind a load
balancer?

When this was first reported yesterday, I went there and didn't have a
problem. I looked at the certificate, and it was issued 2023-08-26,
valid until 2023-11-24.

When I went there just now, I received the security warning due to an
expired certificate. I refreshed the page (without accepting the
security exception), and I didn't have any trouble, and got the same
new certificate that I saw yesterday.

The certificate is issued by Let's Encrypt, so the update is likely
handled automatically. If a load balancer is being used, perhaps the
updated certificate is not being propagated to all hosts.

...Marvin

Christian Brabandt

unread,
Sep 10, 2023, 1:12:18 PM9/10/23
to vim...@googlegroups.com

On So, 10 Sep 2023, Marvin Renich wrote:

> This is very odd. Is www.vim.org served by multiple hosts behind a load
> balancer?
>
> When this was first reported yesterday, I went there and didn't have a
> problem. I looked at the certificate, and it was issued 2023-08-26,
> valid until 2023-11-24.
>
> When I went there just now, I received the security warning due to an
> expired certificate. I refreshed the page (without accepting the
> security exception), and I didn't have any trouble, and got the same
> new certificate that I saw yesterday.
>
> The certificate is issued by Let's Encrypt, so the update is likely
> handled automatically. If a load balancer is being used, perhaps the
> updated certificate is not being propagated to all hosts.

Oh that is true, I remember I checked the cert some time ago.

It might be caused by OSDN. Yet another reason to migrate away :)

I am currently in the process to plan the move, we should have a better
hosting provider soon. I have already tested the vim php homepage with
PHP 9 and it works. We just need to migrate the database and perform the
switch once the server is ready (and I need to sync with the DNS admins
to plan this).

I hope to have news on this more during the week.

Thanks,
Christian
--
Some men are so interested in their wives' continued happiness that they
hire detectives to find out the reason for it.
Reply all
Reply to author
Forward
0 new messages