Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Some other people are saying they've seen Chrome complain, but I can't reproduce it. Please send email (support@pinboard.in) if you can figure out what's up.


Incorrect certificate chain. When you moved to SHA2 certs, you failed to change the intermediates to the "Gandi Standard SSL CA 2" ones.


1 s:/C=FR/ST=Paris/L=Paris/O=Gandi/CN=Gandi Standard SSL CA 2 i:/C=US/ST=New Jersey/L=Jersey City/O=The USERTRUST Network/CN=USERTrust RSA Certification Authority

Nope...?


Yes, this is the correct intermediate.


Ah, his blog.pinboard.in and pinboard.in configs are different.

@idlewords: http://charlieharvey.org.uk/page/gandi_sha2_intermediate_cer...

Are you putting the chain certs in the SSLCertificateChainFile file, and not concating them to the SSLCertificateFile?


https://www.ssllabs.com/ssltest/analyze.html?d=blog.pinboard... Google Chrome on Android ERR_CERT_AUTHORITY_INVALID You are using obsolute chiper.


The actual problem resulting in untrusted cert is the "extra download" certificates.


Cert chain is incorrect basically and the browser is fetching intermediate certs to try to make it work.

Most of the issues Qualys points out on blog.pinboard.in are not present on pinboard.in itself, so I presume there's a difference in config there that would be a good place to start. They're also running on different versions of Debian (squeeze v. wheezy, which ship different OpenSSLs) which accounts for some of the variance.

Also, as Qualys notes, disable RC4 ciphers on pinboard.in and you're in pretty good shape.


It only happens on Android Chrome. SSLLabs reports a bunch of stuff, but it seems like the issue matches http://stackoverflow.com/questions/27892873/ssl-cert-err-cer.... Hopefully a quick fix.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: