chromium / badssl.com

:lock: Memorable site for testing clients against bad SSL configs.
https://badssl.com
Apache License 2.0
2.81k stars 190 forks source link

revoked.badssl.com is about to expire #404

Closed sfionov closed 4 years ago

sfionov commented 4 years ago

It is about to expire at 2019-09-11

sfionov commented 4 years ago

Also it seems to be missing from Chrome CRLSets now. So the test is unusable.

rohitratri commented 4 years ago

Hey folks! When do you plan to update the cert? This is a very useful resource - hope to see it back in action again soon...

christhompson commented 4 years ago

Yep, we'll work on getting this back up. We need to get a new cert and then revoke it, which is a little more involved than normal.

mikhail-chebakov commented 4 years ago

Hello, guys! Is there any progress on this?

We really appreciate this resource. Hoping it will come back.

naumanshah03 commented 4 years ago

Any update on this issue?

B3nac commented 4 years ago

Looking forward to this cert hopefully getting renewed. For anyone looking for a site to test certs revoked by a CRL https://revoked.grc.com/ works.

cr commented 4 years ago

This is breaking non-critical automated OCSP-based testing at Mozilla. We can work around for now, but getting away from the broken fallback certificate that's currently being delivered by the server and restoring the original behavior would be highly preferable.

Thanks @B3nac for the alternate! This will definitely be our temporary workaround.

christhompson commented 4 years ago

This is now deployed. The Chrome CRLSet update is in-progress and should reach Chrome clients in ~1 day. I'll leave this open until we've handled other revocation list followup.

naumanshah03 commented 4 years ago

SSL Labs now reports it correctly as revoked. Thank you

https://www.ssllabs.com/ssltest/analyze.html?d=revoked.badssl.com&hideResults=on

christhompson commented 4 years ago

Closing as it looks like everything has propagated in at least Chrome and Firefox.