NREL / developer.nrel.gov

An issue tracker for NREL's APIs available at https://developer.nrel.gov
43 stars 39 forks source link

Unsecure Certificate of developer.nrel.gov #351

Open ostermannBernd opened 2 months ago

ostermannBernd commented 2 months ago

I have developed an Android App accessing your site for getting data of Cng and Lpg filling stations. Devices with Android version < 10.0 cannot access your web site any more. This is caused by your certificate which allows only computers and not mobile devices to access your web site. Please change your certificate to allow mobile devices to access your web site. Testing your certificate results in: Server sent invalid HSTS policy. See below for further information. This site works only in browsers with SNI support. Regards Bernd Ostermann

ostermannBernd commented 2 months ago

This issue affects devices with Android Version <=6.0. It is not caused by an unsecure certificate. Such devices do not contain the certificate of Internet Security Research Group ISRG X1 in Trusted Certificates. This certificate is used by the site developer.nrel.gov. By Installing this certificate on the device the web site developer-nrel.gov is accessible again. One can get the certificate by openeing developer.nrel.gov in a browser and clicking on the key symbol left of the address bar.