howartp Posted April 7, 2014 Posted April 7, 2014 Hi everyone, I renewed our website/exchange/etc SSL certificate last week and updated it on most servers. However I missed one, and GoDaddy have now revoked the old one. Unfortunately the server it covers is Linux-based and the interface for updating settings is web-based - but I can't get at it cos the certificate expired! Is there a temporary way of allowing myself access to my own site whilst I swap the certificate, or am I stuck? (I've emailed support for the company, but waiting for a reply) I tried adding it to my Trusted Sites, but that still doesn't let me in. I searched Google, but all responses are quite rightly 'no' to the non-techie people who don't understand the risks and are fed up of cert warnings on sites. Hence trying here for a techie answer, if one exists? Peter
SYNACK Posted April 7, 2014 Posted April 7, 2014 Can you find out the crl site for the cert and block that through a hosts file or something on just the one station to mask the revocation, what browser as you can wind the settings right down on some, Firefox seems to be the least cautious about certs by default. 1
featured_spectre Posted April 7, 2014 Posted April 7, 2014 Have a word with godaddy. They should be able to get a temp cert up for you.
AMLinington Posted April 7, 2014 Posted April 7, 2014 Hi everyone, I renewed our website/exchange/etc SSL certificate last week and updated it on most servers. However I missed one, and GoDaddy have now revoked the old one. Unfortunately the server it covers is Linux-based and the interface for updating settings is web-based - but I can't get at it cos the certificate expired! Is there a temporary way of allowing myself access to my own site whilst I swap the certificate, or am I stuck? (I've emailed support for the company, but waiting for a reply) I tried adding it to my Trusted Sites, but that still doesn't let me in. I searched Google, but all responses are quite rightly 'no' to the non-techie people who don't understand the risks and are fed up of cert warnings on sites. Hence trying here for a techie answer, if one exists? Peter Isn't this just a browser issue? Usually if a certificate is untrusted you can select to go through anyway. Is there a command line alternative?
howartp Posted April 7, 2014 Author Posted April 7, 2014 Can you find out the crl site for the cert and block that through a hosts file or something on just the one station to mask the revocation, what browser as you can wind the settings right down on some, Firefox seems to be the least cautious about certs by default. Thanks Synack, that was a good idea that I would have followed through if support hadn't rung back. Have a word with godaddy. They should be able to get a temp cert up for you. Unfortunately that wouldn't have helped because I still couldn't get into the web interface to add the temp cert - I already have the new one ready to go, I just couldn't get in to install it. Isn't this just a browser issue? Usually if a certificate is untrusted you can select to go through anyway. Is there a command line alternative? If a certificate is untrusted or expired, you can generally click through. If it's been revoked (which is different to simply expiring) then most browsers seem to stop you. I have however had a reply from Support. In IE, you can go to Tools > Internet Options > Advanced > Security and untick 'Check for publishers certificate revocation' and 'Check for servers certificate revocation' and reboot your PC. This has the same effect as Synack's suggestion, and lets you click through as AMLightfoot thought. Worth noting (as pointed out by Support) that iOS and OSX don't seem to have this setting ticked by default so if I was onsite I could have used my iPhone or iPad to do this reasonably easily. Peter
glennda Posted April 7, 2014 Posted April 7, 2014 What AV are you using? I had this issue with a client and Vipre AV blocking in (rebadged GFI it was but vipre at the core). If it is disable the services.
AMLinington Posted April 7, 2014 Posted April 7, 2014 If a certificate is untrusted or expired, you can generally click through. If it's been revoked (which is different to simply expiring) then most browsers seem to stop you. I have however had a reply from Support. In IE, you can go to Tools > Internet Options > Advanced > Security and untick 'Check for publishers certificate revocation' and 'Check for servers certificate revocation' and reboot your PC. This has the same effect as Synack's suggestion, and lets you click through as AMLightfoot thought. Worth noting (as pointed out by Support) that iOS and OSX don't seem to have this setting ticked by default so if I was onsite I could have used my iPhone or iPad to do this reasonably easily. Peter This was the feature to which I was referring - I have a feeling (unconfirmed) that Firefox might be able to do this without a reboot - Under the Advanced settings in the Certificates tab you can play about with the validation rules. Depends on whether this is broken by your GP or not.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now