Jump to content

Recommended Posts

Posted

Hi everyone,

 

I renewed our website/exchange/etc SSL certificate last week and updated it on most servers.

 

However I missed one, and GoDaddy have now revoked the old one. Unfortunately the server it covers is Linux-based and the interface for updating settings is web-based - but I can't get at it cos the certificate expired!

 

Is there a temporary way of allowing myself access to my own site whilst I swap the certificate, or am I stuck? (I've emailed support for the company, but waiting for a reply) I tried adding it to my Trusted Sites, but that still doesn't let me in.

 

I searched Google, but all responses are quite rightly 'no' to the non-techie people who don't understand the risks and are fed up of cert warnings on sites. Hence trying here for a techie answer, if one exists?

 

Peter

Posted
Can you find out the crl site for the cert and block that through a hosts file or something on just the one station to mask the revocation, what browser as you can wind the settings right down on some, Firefox seems to be the least cautious about certs by default.
  • Thanks 1
Posted
Hi everyone,

 

I renewed our website/exchange/etc SSL certificate last week and updated it on most servers.

 

However I missed one, and GoDaddy have now revoked the old one. Unfortunately the server it covers is Linux-based and the interface for updating settings is web-based - but I can't get at it cos the certificate expired!

 

Is there a temporary way of allowing myself access to my own site whilst I swap the certificate, or am I stuck? (I've emailed support for the company, but waiting for a reply) I tried adding it to my Trusted Sites, but that still doesn't let me in.

 

I searched Google, but all responses are quite rightly 'no' to the non-techie people who don't understand the risks and are fed up of cert warnings on sites. Hence trying here for a techie answer, if one exists?

 

Peter

 

Isn't this just a browser issue? Usually if a certificate is untrusted you can select to go through anyway. Is there a command line alternative?

Posted
Can you find out the crl site for the cert and block that through a hosts file or something on just the one station to mask the revocation, what browser as you can wind the settings right down on some, Firefox seems to be the least cautious about certs by default.

Thanks Synack, that was a good idea that I would have followed through if support hadn't rung back.

 

Have a word with godaddy. They should be able to get a temp cert up for you.

Unfortunately that wouldn't have helped because I still couldn't get into the web interface to add the temp cert - I already have the new one ready to go, I just couldn't get in to install it.

 

Isn't this just a browser issue? Usually if a certificate is untrusted you can select to go through anyway. Is there a command line alternative?

If a certificate is untrusted or expired, you can generally click through. If it's been revoked (which is different to simply expiring) then most browsers seem to stop you.

 

I have however had a reply from Support. In IE, you can go to Tools > Internet Options > Advanced > Security and untick 'Check for publishers certificate revocation' and 'Check for servers certificate revocation' and reboot your PC. This has the same effect as Synack's suggestion, and lets you click through as AMLightfoot thought.

 

Worth noting (as pointed out by Support) that iOS and OSX don't seem to have this setting ticked by default so if I was onsite I could have used my iPhone or iPad to do this reasonably easily.

 

Peter

Posted
What AV are you using? I had this issue with a client and Vipre AV blocking in (rebadged GFI it was but vipre at the core). If it is disable the services.
Posted

If a certificate is untrusted or expired, you can generally click through. If it's been revoked (which is different to simply expiring) then most browsers seem to stop you.

 

I have however had a reply from Support. In IE, you can go to Tools > Internet Options > Advanced > Security and untick 'Check for publishers certificate revocation' and 'Check for servers certificate revocation' and reboot your PC. This has the same effect as Synack's suggestion, and lets you click through as AMLightfoot thought.

 

Worth noting (as pointed out by Support) that iOS and OSX don't seem to have this setting ticked by default so if I was onsite I could have used my iPhone or iPad to do this reasonably easily.

 

Peter

 

This was the feature to which I was referring - I have a feeling (unconfirmed) that Firefox might be able to do this without a reboot - Under the Advanced settings in the Certificates tab you can play about with the validation rules. Depends on whether this is broken by your GP or not.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...