Does anyone else find this funny?

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Do I think it's funny that you don't have the DOD Root CA 2 public key in your browser? No. Do I think it's funny you don't understand certificates at all, kinda of.
 

destrekor

Lifer
Nov 18, 2005
28,799
359
126
It's kind of ironic.

But the government in general seems to be iffy when it comes to providing quality security certificates. I used to have a lot of issues with us.army.mil in FF3. I think I just went and added an exception and that is why I don't have problems anymore.
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Originally posted by: destrekor
It's kind of ironic.

But the government in general seems to be iffy when it comes to providing quality security certificates. I used to have a lot of issues with us.army.mil in FF3. I think I just went and added an exception and that is why I don't have problems anymore.

Its not ironic at all, you guys are just clueless. You really think the DOD has Verisign issue it's public keys?

 

her209

No Lifer
Oct 11, 2000
56,336
11
0
Originally posted by: bsobel
Do I think it's funny that you don't have the DOD Root CA 2 public key in your browser? No. Do I think it's funny you don't understand certificates at all, kinda of.
I understand why I got the error. I just thought it was funny that I got the error.
 

Fayd

Diamond Member
Jun 28, 2001
7,970
2
76
www.manwhoring.com
Originally posted by: her209
<a target=_blank class=ftalternatingbarlinklarge href="https://www.dss.mil/"><a target=_blank class=ftalternatingbarlinklarge href="https://www.dss.mil/"><a target=_blank class=ftalternatingbarlinklarge href="https://www.dss.mil/">https://www.dss.mil/</a></a></a>

Using FF3, I get:

Secure Connection Failed

www.dss.mil uses an invalid security certificate.

The certificate is not trusted because the issuer certificate is unknown.

(Error code: sec_error_unknown_issuer)

the government sucks at mantaining security certificates on their websites. pretty much every one i go to i have to make a special exception in firefox.

edit: oh now i see why.

is there any way to force firefox to recognize DOD as a certificate issuing authority? or do i have to register an exception with every site?
 

MrChad

Lifer
Aug 22, 2001
13,507
3
81
Originally posted by: Fayd
Originally posted by: her209
<a target=_blank class=ftalternatingbarlinklarge href="https://www.dss.mil/"><a target=_blank class=ftalternatingbarlinklarge href="https://www.dss.mil/"><a target=_blank class=ftalternatingbarlinklarge href="https://www.dss.mil/">https://www.dss.mil/</a></a></a>

Using FF3, I get:

Secure Connection Failed

www.dss.mil uses an invalid security certificate.

The certificate is not trusted because the issuer certificate is unknown.

(Error code: sec_error_unknown_issuer)

the government sucks at mantaining security certificates on their websites. pretty much every one i go to i have to make a special exception in firefox.

/facepalm
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Originally posted by: her209
Originally posted by: bsobel
Do I think it's funny that you don't have the DOD Root CA 2 public key in your browser? No. Do I think it's funny you don't understand certificates at all, kinda of.
I understand why I got the error. I just thought it was funny that I got the error.

If you understood why you got the error you wouldnt have thought it was funny.
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Originally posted by: Fayd
Originally posted by: her209
<a target=_blank class=ftalternatingbarlinklarge href="https://www.dss.mil/"><a target=_blank class=ftalternatingbarlinklarge href="https://www.dss.mil/"><a target=_blank class=ftalternatingbarlinklarge href="https://www.dss.mil/">https://www.dss.mil/</a></a></a>

Using FF3, I get:

Secure Connection Failed

www.dss.mil uses an invalid security certificate.

The certificate is not trusted because the issuer certificate is unknown.

(Error code: sec_error_unknown_issuer)

the government sucks at mantaining security certificates on their websites. pretty much every one i go to i have to make a special exception in firefox.

Another clueless poster.
 

Fayd

Diamond Member
Jun 28, 2001
7,970
2
76
www.manwhoring.com
Originally posted by: MrChad
Originally posted by: Fayd

the government sucks at mantaining security certificates on their websites. pretty much every one i go to i have to make a special exception in firefox.

/facepalm

see edit. you all too fast for me :/

and fwiw, i dont understand security certificates. i'm not an IT guy...
 

Fayd

Diamond Member
Jun 28, 2001
7,970
2
76
www.manwhoring.com
Originally posted by: MrChad
Originally posted by: Fayd
the government sucks at mantaining security certificates on their websites. pretty much every one i go to i have to make a special exception in firefox.

edit: oh now i see why.

is there any way to force firefox to recognize DOD as a certificate issuing authority? or do i have to register an exception with every site?

http://dodpki.c3pki.chamb.disa.mil/rootca.html

thanks.
 

destrekor

Lifer
Nov 18, 2005
28,799
359
126
Originally posted by: bsobel
Originally posted by: Fayd

the government sucks at mantaining security certificates on their websites. pretty much every one i go to i have to make a special exception in firefox.

Another clueless poster.

yeah, we're clueless. :disgust:

Maybe it's because we don't follow every thing there is to know about security certificates. Granted, the issue makes perfect sense, but I don't think I have ever cared to even think about the issue. I follow IT stuff, and used to train for network communications (and an option I am still entertaining as one of my top choices for my Army career), but website security certificates have never phased me as something I'll ever care about.

I say that because I just don't understand your attitude/methods in this thread.
 

her209

No Lifer
Oct 11, 2000
56,336
11
0
Originally posted by: bsobel
Originally posted by: her209
Originally posted by: bsobel
Do I think it's funny that you don't have the DOD Root CA 2 public key in your browser? No. Do I think it's funny you don't understand certificates at all, kinda of.
I understand why I got the error. I just thought it was funny that I got the error.
If you understood why you got the error you wouldnt have thought it was funny.
:roll:
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
yeah, we're clueless. :disgust:

You don't see the irony of coming into a thread and stating that the government/DOD sucks at maintaining security certificates then exclaim you don't know about certificates when it's pointed out your wrong?. Yea, you come off as a bit clueless.
 

Miklebud

Platinum Member
Nov 20, 2002
2,459
1
81
I'm clueless...
I've been getting those for damn near everything. Comcast. Chase.com. Amazon...
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Originally posted by: Flammable
explain please

The site is a DOD site secured with the DOD's public key. IE, Firefox, Opera, Chrome (etc) don't ship the public root key for the DOD (they ship root keys for Verisign, Thawt, GE and dozens more). So if you go to the site you get an SSL error. Posters in the thread think this shows the DOD's security is bad when in fact thats exactly what is supposed to happen since you don't have the root key...

No, the browser (not the DOD) could do a better job of explaining this to users, but then again most users aren't knowledgeable to install the right root cert unless someone ships it to them as part of their browser. Then again, most users aren't going to a DOD site either...
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Originally posted by: Miklebud
I'm clueless...
I've been getting those for damn near everything. Comcast. Chase.com. Amazon...

Ok, you have a completely different and BAD problem you need to fix. Either your root certs are missing/corrupt or your getting traffic proxied to bad sites and your ignoring your browser trying to tell you that...

There are other explanations (like your clock being off), I've seen a person who's machine was a year back, caused all kinds of grieve until they finally figured it out... But the most likely is one of the two above and I urge you to figure out whats going on...