Skip to content
This repository has been archived by the owner on Jul 30, 2024. It is now read-only.

Bad server certificate #1158

Open
Fabsfabsfabs opened this issue May 19, 2023 · 6 comments
Open

Bad server certificate #1158

Fabsfabsfabs opened this issue May 19, 2023 · 6 comments

Comments

@Fabsfabsfabs
Copy link

Description

Hi,
Recently I have been unable to access the qgis website. I am using zscaler for Internet security.
Zscaler is blocking the website as it says it has a bad certificate. I wonder if it has expired or needs to be updated.
This is preventing me from downloading plugins into qgis.

The qgis plugins repo says its unavailable, but I think it's that the whole website is blocked.

I am asking zscaler to try and fix too.. But they said that qgis should update the certificate

Thanks!

Page URL: https://qgis.org/en/site/index.html

@rduivenvoorde
Copy link
Contributor

Can you show the certificate that is been shown to you? With me it show a Google cert (probably because the sites are behind cloudflare)... Our own servers use 'letsencrypt' certificates.

Below is cert for plugins.qgis.org

Screenshot from 2023-05-19 16-51-43

@Fabsfabsfabs
Copy link
Author

Thanks,
Im not sure if this is what you need, but when I view the certificate it looks like this:
image

@jef-n
Copy link
Member

jef-n commented May 22, 2023

That's obviously not the certificate of our site. What does zscaler actually complain about?

@morgenstern72
Copy link

I have the same problem with ESET, using Edge and Firefox latest versions. Also https://www.sslchecker.com/sslchecker reports the Certificate as untrusted:
image

@morgenstern72
Copy link

morgenstern72 commented May 24, 2023

ESETs Error (tanslated from german): "This error was caused by an invalid OCSP response. This response must be valid because OCSP stapling is used."

In the ESET forum I find https://forum.eset.com/topic/29951-website-certificate-revoked/
"This will be due to the Let's Encrypt "DST Root CA X3 DST" certificate authority expiring on the 30th September. We have the same issue with 1 of our customers who use ESET Endpoint Security. None of our other customers have issues. Even though our certificate is valid ESET gives the same error and prevents access because one of the 2 paths has now expired. "

@morgenstern72
Copy link

Maybe thats the problem: https://www.ssllabs.com/ssltest/analyze.html?d=www.qgis.org&s=172.67.143.23

OCSP stapling: Yes
OCSP Must Staple: No

Revocation information
CRL, OCSPCRL: http://crls.pki.goog/gts2p2/veX2kUr15RQ.crl -> WORKS
OCSP: http://ocsp.pki.goog/s/gts2p2/seHKaOqDXks -> DOES NOT WORK

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants