Hacker News new | past | comments | ask | show | jobs | submit login

The SSL cert chain is broken for me.



We wanted to switch long time ago to Let's Encrypt, unfortunately it isn't that simple when you have 10ths of domains and subdomains, distributed among 5-10 servers.


What client and error? Works here and ssllabs.com has always turned up good results.

Maybe it's the fact it's (still) a StartSSL cert?



startcom CA, i've noticed this seems broken more often. Maybe not included in all CA-Cert collections for some operating systems.


startcom and wosign (startcom is now owned by wosign) certificates signed after a certain date are not trusted by some browsers by default due to the back-dating issue last year.

Because of the same trust issues some organisations have their OS and browser installations configured to not trust any certificate signed by startcom or wosign (or a certificate that chains to one of theirs).


Gentoo is one of distributions that distrusted startcom and wosign certs completely not following any depreciation paths.


Nope.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: