Settings

Theme

The Guardian also open-sourced a test SSL cert

github.com

33 points by boyander 13 years ago · 15 comments

Reader

ctz 13 years ago

  Issuer: C=GB, ST=London, L=London, O=GU, OU=tech, CN=*.int.gnl/emailAddress=martyn.inglis@guardian.co.uk  
  Subject: C=GB, ST=London, L=London, O=GU, OU=tech, CN=*.int.gnl/emailAddress=martyn.inglis@guardian.co.uk
This isn't the Guardian's certificate. It's self-signed, for starters.
vxxzy 13 years ago

This is just a self-signed cert.

quasse 13 years ago

HTTPS does not seem to be properly configured on their servers anyway, I get an "You attempted to reach www.theguardian.com, but instead you actually reached a server identifying itself as *.a.ssl.fastly.net." error when trying to connect over HTTPS.

That's interesting because they do have content protected by a sign in system. Are they just not using HTTPS for that? I kind of expected more from the Guardian.

clone1018 13 years ago

Wouldn't this allow someone to do a full man in the middle attack with a compromised server/dns server?

anilshanbhag 13 years ago

So now anyone snooping on visitors to Guardian's site can decrypt the communication. Don't see why anyone would waste time on this given that there is no 'money' involved.

boyanderOP 13 years ago

Yes, just checked now.

samuel1604 13 years ago

it's not the real one it's a test SSL cert

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection