Still problems with svn.wxwidgets.org certificate

16 views
Skip to first unread message

Vadim Zeitlin

unread,
Jul 10, 2014, 7:45:41 AM7/10/14
to wx-dev, Robin Dunn
Hello,

Unfortunately the new certificate used for svn.wxwidgets.org uses the new
(~2011) Go Daddy root certificate which is not recognized as trusted one by
quite a few systems, including old Debian/Ubuntu and (even new) iOS. The
latter is arguably not a problem in practice, and the former will die out
with time, of course, but in the meanwhile review.wxwidgets.org is still
down because it still can't connect to the svn server.

Additionally, Vaclav tells me that StartSSL free certificates are accepted
more widely -- and free, of course. So perhaps it would make sense to get
one of those instead?

TIA,
VZ

Bryan Petty

unread,
Jul 10, 2014, 10:09:55 AM7/10/14
to wxWidgets Development, Robin Dunn
On Thu, Jul 10, 2014 at 5:45 AM, Vadim Zeitlin <va...@wxwidgets.org> wrote:
> Unfortunately the new certificate used for svn.wxwidgets.org uses the new
> (~2011) Go Daddy root certificate which is not recognized as trusted one by
> quite a few systems, including old Debian/Ubuntu and (even new) iOS.

Ah, this explains why the SVN->Git mirrors were still complaining
about the new certificate, weird.

--
Regards,
Bryan Petty

Hans Mackowiak

unread,
Jul 10, 2014, 10:13:42 AM7/10/14
to wx-...@googlegroups.com, Robin Dunn
sorry if i dont know 100% correctly, but wasnt GoDaddy one of the CAs
that has massive problems where the domains got hjacked or similar, and
got kicked out of the trusted CA list?

Hanmac

Václav Slavík

unread,
Jul 13, 2014, 6:26:06 AM7/13/14
to wx-...@googlegroups.com, Robin Dunn

On 10 Jul 2014, at 16:09, Bryan Petty <br...@ibaku.net> wrote:
>> Unfortunately the new certificate used for svn.wxwidgets.org uses the new
>> (~2011) Go Daddy root certificate which is not recognized as trusted one by
>> quite a few systems, including old Debian/Ubuntu and (even new) iOS.
>
> Ah, this explains why the SVN->Git mirrors were still complaining
> about the new certificate, weird.

I think there’s more to it: the certificate chain sent by the server is incomplete and doesn’t contain the “Go Daddy Secure Certificate Authority - G2” intermediate CA, so the client has no way of validating up to a trusted root (without performing additional download from the CA to get the missing certificate): https://www.ssllabs.com/ssltest/analyze.html?d=svn.wxwidgets.org

Vaclav
Reply all
Reply to author
Forward
0 new messages