Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Interesting note about Firefox there.

I've certainly expirenced the missing "missing intermediate cert" problem before. It is a bit of a nightmare to debug.

1. Had issue, raise support ticket: TLS not working

2. Ticket closed as can't reproduce

3. Try myself again locally, also can't reproduce. Hmpf!

4. 2 months goes by..

5. Experience same issue. Debug more carefully locally, use openssl go get proof of missing intermediate

6. Raise support ticket with platform team, then try to convince them that just because most people are not affected, it still needs to be fixed!



You can often engage people, especially technical people who enjoy things being gameified - by showing them that Qualys gives them a lousy score for what they've done.

https://www.ssllabs.com/ssltest/

Also this lets you out-source the decisions about what's important versus what really doesn't matter to somebody else, and unless you've got (or can hire someone who has got) hours per week to read and digest work in this area that's likely going to mean better security in practice.


ssllabs is great and only works for publicly accessibly websites.

The challenge in my experience is to resolve the issue for internal sites, the thousands of internal tools and test domains from every department. None of the public tools can reach them.


If you like ssllabs, you will love https://www.hardenize.com

Much more intel, better performance and a better UI.

No affiliation, just a fan since day one.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: