MrEprise Posted October 3, 2024 Posted October 3, 2024 I know it's generally not a good idea to do this, however when a user gets a block page with the reason: "The server's certificate did not match the domain name", is there any way to bypass this? Science receive vouchers they can spend on equipment and the site that they use to receive these uses a URL which throws up this error. I'd love nothing more than to get them to fix their error but in the meantime, is there a way to bypass this for just this one site for one user only? If not, I'll have to keep telling them that there's nothing I can do to fix the issue (beyond moaning to the site owner(s).)
synaesthesia Posted October 3, 2024 Posted October 3, 2024 I say no out of principal and ask them to contact the site they're having trouble with. Otherwise precedents get set and you're doing it for every tom dick and harry We have one site I have been shouting at for months about the same - to make it worse, its Northants Safeguarding Board... 1
MrEprise Posted October 3, 2024 Author Posted October 3, 2024 That's not good especially given it's resolving to http as well! Yeah, that's fine, I'll continue saying no and offering to get the voucher code for them as I can bypass it for myself.
3s-gtech Posted October 3, 2024 Posted October 3, 2024 Currently about to have the same battle with Pearson (their mail shots to exams officers have this issue). Their reply? "You have filtering. It needs to be taken off." Pearson need to be taken off. The planet. 3
pete Posted October 3, 2024 Posted October 3, 2024 If it's truly mission-critical (your HT would agree) and the site otherwise gets a clean bill of health (virustotal and google check), they get a temporary allow with a deadline to fix their broken stuff. If it's "Bob's interesting penguin facts" that they need for a biology lesson? No. 1
Bumhug360 Posted October 3, 2024 Posted October 3, 2024 Browsers now try and push everything through HTTPS but not all sites have security certificates set up. Guessing (as every time it happens here) the link they have been sent is a redirect link and removing the S so its just http://HTTP://URL will allow the redirect to work and point in the right place. Removing the S is of course dodgy if the site then asks for personal details but we get this a lot and just tell the users to edit the URL 1
synaesthesia Posted October 3, 2024 Posted October 3, 2024 Most of the ones we get including the aforementioned safeguarding site, the front page is fine but there's logins and pages beyond which is where HTTPS naturally kicks in (or tries to, of course!)
msi_school Posted October 3, 2024 Posted October 3, 2024 But why would anyone want to fix their web site or email, when they can just say "it works at other schools" and get someone to shout down the IT department?
3s-gtech Posted October 3, 2024 Posted October 3, 2024 Indeed, that was another line from Pearson - "well we haven't had any issues from any other schools!" Right, well either their filtering doesn't catch cert errors or they haven't bothered to read your poxy mailshots. Fix your stuff, dumb*****.
pete Posted October 3, 2024 Posted October 3, 2024 Indeed, that was another line from Pearson - "well we haven't had any issues from any other schools!" Right, well either their filtering doesn't catch cert errors or they haven't bothered to read your poxy mailshots. Fix your stuff, dumb*****. If you're feeling mean you could reply "That kind of attitude is how you got your last* $1 million fine from the SEC, are you trying for another from ICO?" *https://www.sec.gov/newsroom/press-releases/2021-154 1
tom_newton Posted October 4, 2024 Posted October 4, 2024 You can definitely bypass - but concur with others, give the site owners hell while you do. What I would do is create a new custom list (and review it every few months) and then apply a "do not inspect" policy (guardian/https inspection/manage policy) 2
MrEprise Posted October 8, 2024 Author Posted October 8, 2024 ...but concur with others, give the site owners hell while you do. Oh I certainly will do. Some of the site owners don't seem to budge though. My latest fight is with Zenergi, whose meter reading portal has a certificate that expired on the 4th and they've not done anything about it despite my support query asking them to. These site owners should be renewing before the certificates expire, not after! 1
rossibIT Posted October 8, 2024 Posted October 8, 2024 Its normally a case that these websites are hosted so the company themselves deny all knowledge it being an issue. If you show screenshots from your personal device showing the 'Connection Not Secure' and ask if the website is hosted, have found that the company then starts giving you more answers. Good Luck
3s-gtech Posted October 9, 2024 Posted October 9, 2024 Still battling with Pearson on this “We don’t use Smoothwall. Smoothwall is a safeguarding device that some schools use.” Yes, that’s correct you absolute drain blockage. Schools also use our eyes to read words, such as “the server’s certificate does not match the domain name” which is in the email sent to you.
PotNoodleTech Posted October 9, 2024 Posted October 9, 2024 Out of date/malconfigured certificates is often a sign that a website has been hacked. If they won't fix their certificate, consider them hacked, block them and report them to the ICO. If you bodge it your end then their website could actually get hacked and you wouldnt know which breeches data protecion and cyber security guidance.
3s-gtech Posted October 9, 2024 Posted October 9, 2024 I have no intention of unblocking it. They're as competent as Boris Johnson's government was, and have consistently been at the very bottom of the pile. Our exams officer hasn't got a clue and is starting to get upset that I won't unblock it. She thinks a first-line tech at Pearson must know better.
Olliedawg Posted October 9, 2024 Posted October 9, 2024 We've been having a few issues with Pearson too. Causing our EO multiple headaches.
pete Posted October 9, 2024 Posted October 9, 2024 (edited) I assume you've run the URL through SSLLabs (https://www.ssllabs.com/ssltest/) so you've got something that the L1 tech can hand to someone more capable? Edited October 9, 2024 by pete
3s-gtech Posted October 9, 2024 Posted October 9, 2024 They’ve now admitted it’s their problem and passed it up the line. Here’s a tip for all first line techs - don’t assume you’re dealing with an idiot or novice. Make that judgment based on the information available - which may be from the moment the user opens their mouth of course. Jumping straight to the old “it can’t be us, must be you” mantra makes you look like a chump when dealing with someone who has a clue what they’re talking about. Patronising me about what Smoothwall is makes me want to drive to your office and give you a ruddy good telling off. 1
tom_newton Posted October 10, 2024 Posted October 10, 2024 My favourite thing about this thread was @3s-gtech calling someone a "drain blockage". I will use that.
3s-gtech Posted October 10, 2024 Posted October 10, 2024 Why I'm trying not to swear, I tend to get...creative. 1
Disease Posted December 10, 2024 Posted December 10, 2024 They’ve now admitted it’s their problem and passed it up the line. Here’s a tip for all first line techs - don’t assume you’re dealing with an idiot or novice. Make that judgment based on the information available - which may be from the moment the user opens their mouth of course. Jumping straight to the old “it can’t be us, must be you” mantra makes you look like a chump when dealing with someone who has a clue what they’re talking about. Patronising me about what Smoothwall is makes me want to drive to your office and give you a ruddy good telling off. We have the same issue with Pearsons and our Exams Officer, I am not unblocking it either, in fact when I spoke to CoConnect who co manage the Smoothwall with us they advised against unblocking it and said it would not be good practice for security. So I have just left it as Pearsons admitted the problem was on their end.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now