nanog mailing list archives

Re: McAfee's certificate on akamai seems to be invalid


From: Brandon Martin <lists.nanog () monmotha net>
Date: Thu, 7 May 2020 13:14:00 -0400

On 5/7/20 12:16 PM, Niels Bakker wrote:
It looks like you shouldn't attempt to access that site over HTTPS, just via plain HTTP.  Do you have any official bit of documentation that links to the HTTPS version?

Given the prevalence of opportunistic upgrades to TLS these days, I'd argue that having a misbehaving server listing on 443 (and accepting SNI for a name that works on plain HTTP, if applicable) at the same domain as a well-known, public HTTP server, especially from a "security" company, is a poor idea.
--
Brandon Martin


Current thread: