IBM uses self signed SSL certificates?

by Volker Weber

ibmselfsigned

Start using Firefox 3 and you get new insights.

Comments

openssl s_client -connect www-949.ibm.com:443

Tells me the same :-)

Sascha Reissner, 2008-06-18 12:29

FF2 tells you the same thing. Using self signed certs in and of itself is not necessarily a bad thing. Is this a customer facing site?

Kerr Rainey, 2008-06-18 13:18

i thought that Mozilla and Opera and Microsoft agreed on the color scheme for certificate error so users would have the same noticiation.

does it turn red if you continue after the warning ?

Flemming Riis, 2008-06-18 15:31

There is no need to use Firefox 3 to get this not always helpful message. The major problem is that hardly anybody sees and uses the offered hotspot "exception" ! That is the same situation with IE or Opera.....
And that is why companies like Verisign and Thawte have a rather simple and very successful business modell: They just sell the evidence of conformity with certificates stored in browser software.

Claus Bäumler, 2008-06-18 16:16

@Claus: You're correct. In fact, the dialog is technically incorrect - a certificate is not "invalid" simply because it is self-signed. This message is needlessly alarmist.

David Richardson, 2008-06-18 21:08

@David,
its properly considered invalid, because the connection may have been infiltrated by a man-in-the-middle attack.

Only if you would be able to verify the authenticity, it would even provide the higher level of integrity over an official certificate.

Roland Leißl, 2008-06-18 21:35

I agree with David - that the connection may have been infiltrated does not mean that the certificate is invalid. It's good that FF show's its suspicion, but to say the certificate is invalid is just not correct.

Martin Hiegl, 2008-06-18 22:02

From a client perspective, the trustworthiness of certificates rely solely on some bunch of chaining mumbo-jumbo. As roots of some authorities are stored on your system already, only these are considered valid, and so their descendants.

Unlike self-signed certs. They are considered invalid, because no reference is found, unless added to the trust-store manually. This dialog-phrase sure makes sense to users.

Much more important to me: I Heart the new look!

Roland Leißl, 2008-06-18 22:45

Recent comments

Fotios Nisiropoulos on Listen to podcasts on Sonos at 22:13
Bill Kron on Listen to podcasts on Sonos at 18:43
Volker Weber on Listen to podcasts on Sonos at 18:34
Bill Kron on Listen to podcasts on Sonos at 18:32
Johannes Matzke on Listen to podcasts on Sonos at 17:32
Fotios Nisiropoulos on Listen to podcasts on Sonos at 17:24
Volker Weber on Listen to podcasts on Sonos at 17:01
Johannes Matzke on Listen to podcasts on Sonos at 16:58
Ragnar Schierholz on Windows 10 on iPad Pro? at 21:25
Craig Wiseman on Verkehrte Welt :: Lenovo Soft Keyboard vs BlackBerry Hard Keyboard at 15:52
Volker Weber on Verkehrte Welt :: Lenovo Soft Keyboard vs BlackBerry Hard Keyboard at 15:09
Karl Heindel on Verkehrte Welt :: Lenovo Soft Keyboard vs BlackBerry Hard Keyboard at 14:57
Volker Weber on Windows 10 on iPad Pro? at 09:58
Wolfram Votteler on Windows 10 on iPad Pro? at 09:39
Volker Jürgensen on Windows 10 on iPad Pro? at 21:42
Volker Weber on Moto Z2 Play :: Let's talk about the phone at 14:13
Tobias Müller on Moto Z2 Play :: Let's talk about the phone at 13:40
Fredrik Malmborg on Moto Z2 Play :: A modular smartphone at 10:29
Peter Meuser on Earn the National Park Challenge award today at 07:49
Bodo Menke on Closing the Sonos chapter at 09:43
Boudewijn Kiljan on Closing the Sonos chapter at 08:40
Martin Hiegl on Moto Z2 Play :: A modular smartphone at 12:24
Frank Quednau on Moto Z2 Play :: A modular smartphone at 11:33
Hubert Stettner on Moto Z2 Play :: A modular smartphone at 11:01
Hauke Fink on Closing the Sonos chapter at 22:17

Ceci n'est pas un blog

I explain difficult concepts in simple ways. For free, and for money. Clue procurement and bullshit detection.

vowe

Contact
Publications
Amazon Wish List
Frequently Asked Questions

rss feed  twitter

Local time is 14:49

visitors.gif