SSL error prevents access to LP-hosted mailing list archives

Bug #412471 reported by Fabián Rodríguez
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Launchpad itself
Won't Fix
Undecided
Unassigned

Bug Description

When trying to access a mailing list post via Launchpad, I get this error:

lists.edge.launchpad.net uses an invalid security certificate.

The certificate is only valid for the following names:
  *.launchpad.net , launchpad.net

(Error code: ssl_error_bad_cert_domain)

One such example is from the results page of this search:
https://edge.launchpad.net/+search?field.text=golden+cheetah

From my distant knowledge of SSL, it seems there is a wildcard SSL certificate assigned to *.launchpad.net, however this does not cover uses in 4 level domains (list.edge.launchpad.net). Granted this is not high priority as edge is beta, but perhaps worth fixing.

"A Wildcard Certificate conveniently allows you to secure multiple sub domains on one domain on the same server using *.domain.com pattern for the common name." (ref: https://www.thawte.com/ssl-digital-certificates/wildcardssl/index.html, also see http://wiki.cacert.org/wiki/WildcardCertificates).

I am using Shiretoko from Universe (Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.1.2) Gecko/20090803 Ubuntu/9.04 (jaunty) Shiretoko/3.5.2), but I can reproduce the same with the Firefox version (3.0.13) provided in Jaunty (Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.0.13) Gecko/2009080315 Ubuntu/9.04 (jaunty) Firefox/3.0.13).

This dialog does not provide an easy way to create a security exception for this error. This workaround works:

For Firefox 3.5.2 or 3.0.13:
1) Right-click on the link that doesn't work, choose "Copy Link Location"
2) Go to Edit > Preferences, "Advanced" tab, click on "View certificates"
3) Paste the link copied in 1) in the "Location" field, click on "Get certificate"
4) Check that the certificate serial number matches 54:CF:D7:48
5) Click "Confirm exception", then "Ok" in remaining dialogs

Firefox won't need a restart, you should be able to click on archive links normally now.

I'll mark this as security knowing it may be mostly cosmetic, so feel free to unmark it as such.

Christian Reis (kiko)
visibility: private → public
affects: launchpad → launchpad-registry
tags: added: mailing-lists
Curtis Hovey (sinzui)
affects: launchpad-registry → launchpad-foundations
Changed in launchpad-foundations:
status: New → Triaged
Revision history for this message
Martin Albisetti (beuno) wrote :

Wow, I just ran into this again, and it feels like a lot of bang per buck.

Revision history for this message
Robert Collins (lifeless) wrote :

We are removing the edge domain (partly because of issues like this) and so the problem is irrelevant. Right now the domain still exists, but the redirect to it for beta users has been removed.

Changed in launchpad-foundations:
status: Triaged → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.