Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Expired Certs Cause Headaches » Note on firewalling... parenthetical...
Search Topic:
Uniqs:
21
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« I haven't noticed anything ...  
AuthorAll Replies


gwion
wild colonial boy
Premium,ExMod 2001-08
join:2000-12-28
Pittsburgh, PA

Note on firewalling... parenthetical...

Verisign appears to have brought up the same two servers some people were blocking because of the DNS-redirection issue of a few months back as revocation list servers. If you're blocking any Verisign servers as an artifact of those discussions, I strongly suggest you check the IP's you're blocking, by simply making a browser connection to them. If you retreive a list of certificates, then you're blocking a server that's been redelegated to act as a revocation list server. If you have those servers blocked, and you don't have the block set to prompt you when it's triggered, you might be getting messages that IE is unable to verify that the certificate hasn't expired/been revoked when you visit a secure site. I ran into this issue yesterday, while playing with some old rulesets I have archived for Kerio...

This might be more of a sidelong issue, but I thought it was worth mentioning, since some people may have certain Verisign servers blocked without a log or prompt, and have all but forgotten doing it. The two servers I traced are:

12.158.80.10 -- crl.verisign.com
and
64.94.110.11 -- crl.verisign.com

If either of these two servers is blocked, you stand a very good chance of being unable to verify certificates for revocation and expiry status, slowing down SSL connections, and creating error messages and a potential security vulnerability for yourself at a "phished" or fraudulant site... just an FYI...
--
I read Shakespeare and the Bible, and I can shoot dice. That's what I call a liberal education.
Forums » Expired Certs Cause Headaches« I haven't noticed anything ...  


Sunday, 22-Nov 20:42:17 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [210] Weekend Open Thread
· [117] Verizon Again Hints At Metered Billing
· [97] There's Still No Evidence That Metered Billing Is Necessary
· [94] Will AOL's Implosion Ever End?
· [85] Spain Declares Broadband A Legal Right
· [75] Deploying FTTH Without Digging Things Up
· [74] Verizon To Be Tested By Unofficial Droid Tethering
· [73] Femtocells Are A No Show
· [67] Verizon To AT&T: The Truth Hurts
· [60] Chicago Tribune Visits 'Comcast University'
Most people now reading
· [NFL] Week 11 Games Thread [Sports Chat]
· Smoker's Applecare warranties may not be worth anything [All Things Macintosh]
· Windows 7 boot manager editing questions [Microsoft Help]
· Hacking.....seriously, how easy is it to get hacked? [Security]
· Best Bluray player [General Questions]
· 3.2 Mage PVE [World of Warcraft]
· Extra charge to use Master Card instead of Visa? [General Questions]
· TekSavvy Price Increase? [TekSavvy]
· Why do cats... [General Questions]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]