Jump to content

Recommended Posts

Posted
Has anyone heard anything about the root Certificate from Add Trust expiring? Several of the websites we access are coming up as blocked by the firewall. On further checking it was found the Add trust root certificate had expired a few days ago. Sites like exampro, and doublestuck.EU are getting blocked.
Posted

The issue is with your computers, filtering or application as oppose to the sites.

 

We have had issues with the older Citrix Receiver having the trusted certificates included in the program, so couldn't of staff unable to login. That was fun to diagnose why 3 of 300 staff were getting the SSL issue and no one else was.

 

I read quite a lot about this, here is the base article from Sectigo (Comodo came from these guys) https://support.sectigo.com/Com_KnowledgeDetailPage?Id=kA03l00000117LT

Posted
We use Fortinet. Any ideas in how to do this on Fortinet? Thanks.

 

Sorry, I know nothing about the fortinet software.

 

Maybe a post on Spiceworks might help or someone on here might pop up. Have you tried the fortinet forums - if they are available?

Posted
Sorry, I know nothing about the fortinet software.

 

Maybe a post on Spiceworks might help or someone on here might pop up. Have you tried the fortinet forums - if they are available?

No problem and thanks for the info. Fortinet forum just suggests to either disable SSL Inspection, or wait for the websites to replace the expired certificate. Not really helpful from them.
Posted

We used to use one of these affected certificates and got reports of this issue from some schools - this is the announcement covering it, https://support.sectigo.com/articles/Knowledge/Sectigo-AddTrust-External-CA-Root-Expiring-May-30-2020

In the end I just swapped out the old certificates for Amazon-issued certificates to resolve the issue.

In our case we made no changes due to the indication that the old certificates should still function correctly, however that was based on faulty assumptions hence us updating our certificates. Hopefully these other services do likewise as it seems that this being an issue is certainly not isolated.

Posted

The Impending Doom of Expiring Root CAs and Legacy Clients

 

Some CAs have now been around for a very long time, we're talking 20-25 years! That also just so happens to mean that some of the original Root CAs out there are also coming towards the end of their natural life, their time is almost up. For most of us this won't be a problem at all because CAs have created new root certificates and those have been distributed across the World in OS and browser updates for years. For some of us though, those who haven't installed OS or browser updates for years, well there's kind of a problem...

 

This problem was perfectly demonstrated recently, at May 30 10:48:38 2020 GMT to be exact. That exact time was then the AddTrust External CA Root expired and brought with it the first signs of trouble that I've been expecting for some time.

 

There is a whole load of stuff that broke because of this Root CA expiring and Andy Ayer has a good list tracking quite a few more here. The point is, the affected clients only have the old (now expired) AddTrust Root CA Certificate installed and because they've not been updated they haven't received the new version that replaces it. Without that new version, things simply don't work and Server Certificates that should be valid, that are valid, will rightly be seen as invalid and rejected by the client.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...