Jump to content

Recommended Posts

Posted

In relation to Talk Straights new web filtering certificate, and in a bid to prevent some of you from wasting their week updating policies and devices etc, like I just have across all our schools, the below has been posted on Talk Straights hub this afternoon:

 

"It has been brought to our attention that the certificate linked in the previous update was deployed with outdated and potentially insecure encryption. In this case SHA1. Unfortunately, this means that we have had to issue a new certificate with the correct SHA256 encryption and any customers that have proactively deployed the certificate will need to replace it."

Posted

The existing one expires 24th May 2022. A new certificate was released start of April which lasts until some point in the year 2072. Or rather, did.

 

The new, new one is less that that. I didn't save it anywhere useful earlier but I think it was good for ten years.

  • Thanks 1
Posted
Well, thats made my afternoon of productivity an afternoon of drinking coffee and sitting around... I should have checked the hub before I deployed it to all of my schools!
  • 4 weeks later...
Posted

Latest Update from SBB - Third certificate to deploy!

 

URGENT UPDATE - 16/5/33

 

Good Evening All,

 

We can only apologise but unfortunately, we have had to reissue the replacement Netsweeper certificate due to issues getting unmanaged Apple iOS devices to trust the new certificate. It seems like Apple don’t allow users to trust certificates over a certain validity period, we deliberately set the validity period to 10 years to reduce work in the future but have had to reduce it to 5 years to get the certificate to deploy.

 

With the Netsweeper platform, we can only have a single certificate at any one time so with the number of schools using Apple products we took the difficult decision to reissue the certificate.

 

As you may have already done the work required (multiple times) we want to apologise and stress that we are looking at solutions for the future where each customer/MAT will be able to share their certificate.

 

The certificate has been replaced at the original link for you to download again,

 

https://hub.talk-straight.com/dl.php?type=d&id=135

 

As before, this work will need to be completed before Tuesday 24th May 2022.

 

If there is anything we can do to help please let us know.

 

Thanks,

 

Talk Straight Technical Department

Posted

Yep. A week to update all those things that have already been update well in advance, twice.

 

P*ss up and brewery comes to mind as well as many expletives.

Posted (edited)

If they read this and are re-issuing...you can just set the datetime to 2019 and manually make a 10/20/30yr cert, they trust them before a certain period.

Works fine from this end with random unmanaged Apple devices, does mean the cert looks a lot older, but works so easy win.

 

Does seem weird though as it shouldn't affect admin-added root CAs...

Edited by PaddyNewman
Posted (edited)

SBB at it again. This is absolutely embarrassing, again. Right in the middle of exam season too, where we are running AEN accessibility in the middle of it all.

Almost as embarrasing as their website being listed as unsafe by Google last week too.

 

I'm looking forward to our contract ending with them.

Edited by paulkerton
Posted
I don't know if anyone is having issues this morning but we are, new certificate is rolled out but https browsing is inconsistent. Some sites just error.
Posted
If you don't use the certificate then you don't need to worry.

 

Seems I missed one of the updates because I was on annual leave, you don't really expect so many mistakes.

 

Original cert was called "Root Certificate Authority" with an expiry of 24/05/2022

 

They provided a new one called Network Operations which later turned out to be wrong so they issued a new one called:

 

Web Filtering with an expiry of 2032 which is the one I preloaded.

 

On the 16th they issued yet another one:

 

"Schools Broadband Web Filtering" with an expiry of 2028 and that works absolutely fine when on its own with the others deleted.

Posted

Lots of pupils in this morning already asking for new cert to be installed, even though I've sent out 2 emails in the past week and a reminder along with guides...

 

Strong RTFM vibes atm

Posted
Lots of pupils in this morning already asking for new cert to be installed, even though I've sent out 2 emails in the past week and a reminder along with guides...

 

Strong RTFM vibes atm

 

I can see that, the first lot of comms that was sent by email from SBB was visible then they started asking for you to click the link to login to check the most recent status. The problem is they were spamming these emails so very often there were no updates. The most recent change to the cert went out on the 16th of May at 21:43 and that was the one I missed. Fortunately the previous one they asked me to preload wasn't completely broken so it could have been a lot worse. In terms of mobile devices I gave up providing instructions to the students because they didn't follow them and as a result our wireless network doesn't get much use.

Posted

Most people have taken notice of the comms which is good news. Our call desk has been busier than normal this morning but this hasn't been the doomsday event some people had said it would have been, far from it.

 

Thank you for everyone that took notice and proactively made the changes to ensure your service continued as normal.

 

Dave

Posted

Hi Dave,

 

I don't think that our school had any notification of this so it caused a large headache for us at an already busy time.

  • Thanks 2
Posted (edited)
Our call desk has been busier than normal this morning but this hasn't been the doomsday event some people had said it would have been, far from it.

Because your customers have been pushed to do the work in triplicate, including being given a week's notice of the third issue of a certificate - right in the middle of exams season - then sure, job well done by your customers inspite of all of the mess they've been presented with.

Edited by paulkerton
Posted

I'd be more concerned that a company with responsibilities for safety and security within technology:

 

a) made numerous basic mistakes relating to a certificate

b) ignored the numerous schools in this thread who have been given the runaround after these mistakes

c) Refused to apologise for their mess

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...