[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Scripts that run insecurely-downloaded code

Davide Prina wrote:
Not all the software that implement HTTPS verify the validity of the certificate and the validity of all the certification chain.
These scripts are using wget or curl, which both say they do verify certificates. If they do not do so correctly, please report this.

For example where I work has been invalidated a certificate, but for mistake the new valid one was not loaded on a https site. With Debian and Firefox I cannot access that site (I get "the certificate is not valid" or something similar), but other people, that use another OS, can access it with internet explorer and chrome, but not with Firefox.

Since this involved a revoked certificate, possibly https://en.wikipedia.org/wiki/Online_Certificate_Status_Protocol#Browser_support

Reply to: