moxie0 / Convergence

An agile, distributed, and secure alternative to the Certificate Authority system.
http://convergence.io
623 stars 127 forks source link

Yahoo mail domain fails cert UCC match #159

Open psypete opened 11 years ago

psypete commented 11 years ago

When trying to log into Yahoo! Mail (https://mail.yahoo.com/) you are redirected to http://us.mg4.mail.yahoo.com/neo/launch?.rand= . Using HTTPS Everywhere this usually works, even though it is listed as 'buggy'. But now with Convergence, the certificate is consistently rejected, saying that the hostname ('us.mg4.mail.yahoo.com') does not match a hostname in the cert's list.

That list, for reference, is: mail.yahoo.com, .mail.yahoo.net, .ymail.com, .msg.yahoo.com, .flickr.com, .flic.kr, .fantasysports.yahoo.com, .secure.yahoo.com, help.yahoo.com, yep.video.yahoo.com, .mail.yahoo.com

Even after attempting to manually add a permanent security exception, the exception page keeps popping up. I have to disable HTTPS for Yahoo! Mail to be able to log in, when Convergence is enabled.

guns commented 11 years ago

us.mg4.mail.yahoo.com doesn't match the cert's Common Name or the subjectAltName list, so this is a problem with Yahoo's certificate.