<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Certificate Error greeted me this AM . . . (copied here)</title>
	<atom:link href="http://habitablezone.com/2014/05/05/certificate-error-greeted-me-this-am-copied-here/feed/" rel="self" type="application/rss+xml" />
	<link>https://habitablezone.com/2014/05/05/certificate-error-greeted-me-this-am-copied-here/</link>
	<description></description>
	<lastBuildDate>Fri, 22 May 2026 23:33:52 -0700</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: DanS</title>
		<link>https://habitablezone.com/2014/05/05/certificate-error-greeted-me-this-am-copied-here/#comment-30604</link>
		<dc:creator>DanS</dc:creator>
		<pubDate>Tue, 06 May 2014 19:10:20 +0000</pubDate>
		<guid isPermaLink="false">https://www.habitablezone.com/?p=44815#comment-30604</guid>
		<description>Redemtech has been taken into Arrow Electronics -- &#039;bout a year, now -- so I expect someday to get a real system under me.

...someday...

To &quot;cut costs,&quot; they even went so far as to take away our MS Office Suite and give us LibraSuite.

As always, hoping for better days.
Cheers.</description>
		<content:encoded><![CDATA[<p>Redemtech has been taken into Arrow Electronics &#8212; &#8217;bout a year, now &#8212; so I expect someday to get a real system under me.</p>
<p>&#8230;someday&#8230;</p>
<p>To &#8220;cut costs,&#8221; they even went so far as to take away our MS Office Suite and give us LibraSuite.</p>
<p>As always, hoping for better days.<br />
Cheers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>https://habitablezone.com/2014/05/05/certificate-error-greeted-me-this-am-copied-here/#comment-30603</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Tue, 06 May 2014 18:15:00 +0000</pubDate>
		<guid isPermaLink="false">https://www.habitablezone.com/?p=44815#comment-30603</guid>
		<description>Thanks for copying the messages. They&#039;re illuminating: It looks like IE8 is refusing to connect using all the high-grade encryption on offer, forcing the server to skip the new certificate entirely and fall back on a generic cert (that&#039;s what &quot;omU-12-31-39-07-85-C7&quot; is telling me). The generic cert isn&#039;t issued by an official Certificate Authority, so it&#039;ll get flagged as &quot;self-signed&quot;.

An important thing to remember is that these digital certificates serve two purposes: encryption, and identification. Any digital certificate, no matter who created it, will work for encryption. Your connection to a web site after seeing all those warnings is still encrypted (albeit using weaker cyphers). It&#039;s the other function, identification, that&#039;s causing the warnings. The owner of a self-signed cert, one not issued by a formal authority, can&#039;t be determined, and the browser is warning you of the danger that you&#039;re connected to a fake phishing web site.

When things work correctly, the certificate information would say that the cert was issued to &quot;Robert Shepherd&quot;, and you could trust that, because the Certificate Authority verified my identity. I can issue what are called &quot;class 2&quot; certs because I&#039;m verified; class 1 certs only verify that the name on a domain registration matches the name of whoever&#039;s generated the cert, and that&#039;s pretty easily faked. Class 2 verifies both the domain ownership and the identity of the purported owner.

And, in the grand scheme of things, little of this really matters. It&#039;s kind of a joke, really, that most parts of the Zone that are wide open to be read by anybody, without registration, are nevertheless encrypted. I&#039;m making a statement about privacy, and I wish it weren&#039;t inconveniencing you, but I think on balance it&#039;s worth it.

Thanks for going along with it.</description>
		<content:encoded><![CDATA[<p>Thanks for copying the messages. They&#8217;re illuminating: It looks like IE8 is refusing to connect using all the high-grade encryption on offer, forcing the server to skip the new certificate entirely and fall back on a generic cert (that&#8217;s what &#8220;omU-12-31-39-07-85-C7&#8243; is telling me). The generic cert isn&#8217;t issued by an official Certificate Authority, so it&#8217;ll get flagged as &#8220;self-signed&#8221;.</p>
<p>An important thing to remember is that these digital certificates serve two purposes: encryption, and identification. Any digital certificate, no matter who created it, will work for encryption. Your connection to a web site after seeing all those warnings is still encrypted (albeit using weaker cyphers). It&#8217;s the other function, identification, that&#8217;s causing the warnings. The owner of a self-signed cert, one not issued by a formal authority, can&#8217;t be determined, and the browser is warning you of the danger that you&#8217;re connected to a fake phishing web site.</p>
<p>When things work correctly, the certificate information would say that the cert was issued to &#8220;Robert Shepherd&#8221;, and you could trust that, because the Certificate Authority verified my identity. I can issue what are called &#8220;class 2&#8243; certs because I&#8217;m verified; class 1 certs only verify that the name on a domain registration matches the name of whoever&#8217;s generated the cert, and that&#8217;s pretty easily faked. Class 2 verifies both the domain ownership and the identity of the purported owner.</p>
<p>And, in the grand scheme of things, little of this really matters. It&#8217;s kind of a joke, really, that most parts of the Zone that are wide open to be read by anybody, without registration, are nevertheless encrypted. I&#8217;m making a statement about privacy, and I wish it weren&#8217;t inconveniencing you, but I think on balance it&#8217;s worth it.</p>
<p>Thanks for going along with it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DanS</title>
		<link>https://habitablezone.com/2014/05/05/certificate-error-greeted-me-this-am-copied-here/#comment-30600</link>
		<dc:creator>DanS</dc:creator>
		<pubDate>Tue, 06 May 2014 11:12:41 +0000</pubDate>
		<guid isPermaLink="false">https://www.habitablezone.com/?p=44815#comment-30600</guid>
		<description>https://www.google.com/ comes in clean on IE8.  https://www.habitablezone.com/ &amp; .net both insist upon the Certificate Error, which warns with the Error page, and paints my URL Address Field pink, while at the same time displaying an error icon and blocking certain nefarious bits from my screen.  Clicking the icon gets this info:

A small dialogue box with two options:


&lt;blockquote&gt;1. &quot;About Certificate Errors&quot;
2. &quot;View certificates&quot;&lt;/blockquote&gt;


In &quot;View certificates&quot; I get a dialogue box with 3 tabs -- &quot;General,&quot; &quot;Details&quot; and &quot;Certification Path&quot;.  Under the &quot;General&quot; tab is found &quot;Certificate Information.&quot;

Certificate Information displays:


&lt;blockquote&gt;Issued to: domU-12-31-39-07-85-C7
Issued by: domU-12-31-39-07-85-C7
Valid from: 4/24/2014 to 4/24/2015&lt;/blockquote&gt;


This tab includes 2 options:


&lt;blockquote&gt;1. &quot;Install Certificate&quot;
2. &quot;Issue Statement&quot;&lt;/blockquote&gt;


&quot;Issue Statement&quot; is disabled, so I &quot;Installed&quot;.
A few clicks, and I return to the tabbed dialogue box.

There appears to be no change.  I closed the browser and reopened, again with no change.  I warm-booted the PC, again with no change.  I did a cold-restart, pretty sure it would change nothing.  It changed nothing.

------

Anyway...

The second tab is &quot;Details,&quot; with a selection field displaying the following:


&lt;blockquote&gt;Version: V3
Serial number: 60 2b
Signature algorithm: sha256RSA
Issuer: root@domU-12-31-39-07-85...
Valid from: Thursday, April 24, 2014 8:34...
Valid to: Friday, April 24, 2015 8:34:37...
Subject: root@domU-12-31-39-07-85...
Public key: RSA (2048 bits)
Basic Constraints: Subject Type=CA, Path Lengt...
Subject Alternative Name:  DNS Name=localhost, DNS Na...
Key Usage: Digital Signature, Non-Repudia...
Thumbprint algorithm: sha1
Thumbprint: 42 8b f6 1c c8 3b 91 ae ff 8a c...&lt;/blockquote&gt;

&quot;...&quot; indicates a continuation with off-field/undisplayed data.

------

The &quot;Certification Path&quot; tab has 2 fields.


&lt;blockquote&gt;Field #1 displays &quot;Certification path&quot;:
domU-12-31-39-07-85-C7
Field #2 displays &quot;Certificate status&quot;:
This certificate is OK.&lt;/blockquote&gt;

The alarm remains.</description>
		<content:encoded><![CDATA[<p><a href="https://www.google.com/" rel="nofollow">https://www.google.com/</a> comes in clean on IE8.  <a href="https://www.habitablezone.com/" rel="nofollow">https://www.habitablezone.com/</a> &amp; .net both insist upon the Certificate Error, which warns with the Error page, and paints my URL Address Field pink, while at the same time displaying an error icon and blocking certain nefarious bits from my screen.  Clicking the icon gets this info:</p>
<p>A small dialogue box with two options:</p>
<blockquote><p>1. &#8220;About Certificate Errors&#8221;<br />
2. &#8220;View certificates&#8221;</p></blockquote>
<p>In &#8220;View certificates&#8221; I get a dialogue box with 3 tabs &#8212; &#8220;General,&#8221; &#8220;Details&#8221; and &#8220;Certification Path&#8221;.  Under the &#8220;General&#8221; tab is found &#8220;Certificate Information.&#8221;</p>
<p>Certificate Information displays:</p>
<blockquote><p>Issued to: domU-12-31-39-07-85-C7<br />
Issued by: domU-12-31-39-07-85-C7<br />
Valid from: 4/24/2014 to 4/24/2015</p></blockquote>
<p>This tab includes 2 options:</p>
<blockquote><p>1. &#8220;Install Certificate&#8221;<br />
2. &#8220;Issue Statement&#8221;</p></blockquote>
<p>&#8220;Issue Statement&#8221; is disabled, so I &#8220;Installed&#8221;.<br />
A few clicks, and I return to the tabbed dialogue box.</p>
<p>There appears to be no change.  I closed the browser and reopened, again with no change.  I warm-booted the PC, again with no change.  I did a cold-restart, pretty sure it would change nothing.  It changed nothing.</p>
<p>&#8212;&#8212;</p>
<p>Anyway&#8230;</p>
<p>The second tab is &#8220;Details,&#8221; with a selection field displaying the following:</p>
<blockquote><p>Version: V3<br />
Serial number: 60 2b<br />
Signature algorithm: sha256RSA<br />
Issuer: root@domU-12-31-39-07-85&#8230;<br />
Valid from: Thursday, April 24, 2014 8:34&#8230;<br />
Valid to: Friday, April 24, 2015 8:34:37&#8230;<br />
Subject: root@domU-12-31-39-07-85&#8230;<br />
Public key: RSA (2048 bits)<br />
Basic Constraints: Subject Type=CA, Path Lengt&#8230;<br />
Subject Alternative Name:  DNS Name=localhost, DNS Na&#8230;<br />
Key Usage: Digital Signature, Non-Repudia&#8230;<br />
Thumbprint algorithm: sha1<br />
Thumbprint: 42 8b f6 1c c8 3b 91 ae ff 8a c&#8230;</p></blockquote>
<p>&#8220;&#8230;&#8221; indicates a continuation with off-field/undisplayed data.</p>
<p>&#8212;&#8212;</p>
<p>The &#8220;Certification Path&#8221; tab has 2 fields.</p>
<blockquote><p>Field #1 displays &#8220;Certification path&#8221;:<br />
domU-12-31-39-07-85-C7<br />
Field #2 displays &#8220;Certificate status&#8221;:<br />
This certificate is OK.</p></blockquote>
<p>The alarm remains.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>https://habitablezone.com/2014/05/05/certificate-error-greeted-me-this-am-copied-here/#comment-30598</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Tue, 06 May 2014 01:00:35 +0000</pubDate>
		<guid isPermaLink="false">https://www.habitablezone.com/?p=44815#comment-30598</guid>
		<description>Thanks</description>
		<content:encoded><![CDATA[<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DanS</title>
		<link>https://habitablezone.com/2014/05/05/certificate-error-greeted-me-this-am-copied-here/#comment-30597</link>
		<dc:creator>DanS</dc:creator>
		<pubDate>Tue, 06 May 2014 00:30:27 +0000</pubDate>
		<guid isPermaLink="false">https://www.habitablezone.com/?p=44815#comment-30597</guid>
		<description>I&#039;ll check with Google tomorrow and follow-up then.

Cheers to all here.</description>
		<content:encoded><![CDATA[<p>I&#8217;ll check with Google tomorrow and follow-up then.</p>
<p>Cheers to all here.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>https://habitablezone.com/2014/05/05/certificate-error-greeted-me-this-am-copied-here/#comment-30596</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Mon, 05 May 2014 19:47:15 +0000</pubDate>
		<guid isPermaLink="false">https://www.habitablezone.com/?p=44815#comment-30596</guid>
		<description>on multiple levels. Sounds like your company&#039;s IT department is seriously defective; keeping IE8 around is tantamount to professional malpractice.

I&#039;m very curious: What happens when you connect to encrypted Google? (&lt;a href=&quot;https://www.google.com&quot; rel=&quot;nofollow&quot;&gt;https://www.google.com&lt;/a&gt;). What I did is modeled after recommendations from Google and the Mozilla Foundation, and Google gets exactly the same test results the Zone gets (https://www.ssllabs.com/ssltest/analyze.html?d=google.com&amp;s=74.125.239.113). Including not supporting IE8. Do you get the same error message at Google?

None of which will help you, I guess. I looked at Google hoping that they&#039;d found a way to support IE8, and that I could copy it, but no such luck. Google gave up on IE8 too.

Sorry man. I suppose we&#039;re straining at gnats, since you can power through the scary warning to view the Zone anyway. Mostly it&#039;s my technical pride at stake: I don&#039;t want my Web site generating scary warning messages.

Thanks for checking and reporting, Dan.</description>
		<content:encoded><![CDATA[<p>on multiple levels. Sounds like your company&#8217;s IT department is seriously defective; keeping IE8 around is tantamount to professional malpractice.</p>
<p>I&#8217;m very curious: What happens when you connect to encrypted Google? (<a href="https://www.google.com" rel="nofollow">https://www.google.com</a>). What I did is modeled after recommendations from Google and the Mozilla Foundation, and Google gets exactly the same test results the Zone gets (<a href="https://www.ssllabs.com/ssltest/analyze.html?d=google.com&#038;s=74.125.239.113" rel="nofollow">https://www.ssllabs.com/ssltest/analyze.html?d=google.com&#038;s=74.125.239.113</a>). Including not supporting IE8. Do you get the same error message at Google?</p>
<p>None of which will help you, I guess. I looked at Google hoping that they&#8217;d found a way to support IE8, and that I could copy it, but no such luck. Google gave up on IE8 too.</p>
<p>Sorry man. I suppose we&#8217;re straining at gnats, since you can power through the scary warning to view the Zone anyway. Mostly it&#8217;s my technical pride at stake: I don&#8217;t want my Web site generating scary warning messages.</p>
<p>Thanks for checking and reporting, Dan.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DanS</title>
		<link>https://habitablezone.com/2014/05/05/certificate-error-greeted-me-this-am-copied-here/#comment-30595</link>
		<dc:creator>DanS</dc:creator>
		<pubDate>Mon, 05 May 2014 18:48:10 +0000</pubDate>
		<guid isPermaLink="false">https://www.habitablezone.com/?p=44815#comment-30595</guid>
		<description>...Since you can.

Cheers, Jody.</description>
		<content:encoded><![CDATA[<p>&#8230;Since you can.</p>
<p>Cheers, Jody.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DanS</title>
		<link>https://habitablezone.com/2014/05/05/certificate-error-greeted-me-this-am-copied-here/#comment-30594</link>
		<dc:creator>DanS</dc:creator>
		<pubDate>Mon, 05 May 2014 18:46:49 +0000</pubDate>
		<guid isPermaLink="false">https://www.habitablezone.com/?p=44815#comment-30594</guid>
		<description>Unfortunately, this is a company machine, so my options are limited to -- dare i say it? -- none.

Well, thx anyway.</description>
		<content:encoded><![CDATA[<p>Unfortunately, this is a company machine, so my options are limited to &#8212; dare i say it? &#8212; none.</p>
<p>Well, thx anyway.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DanS</title>
		<link>https://habitablezone.com/2014/05/05/certificate-error-greeted-me-this-am-copied-here/#comment-30593</link>
		<dc:creator>DanS</dc:creator>
		<pubDate>Mon, 05 May 2014 18:43:56 +0000</pubDate>
		<guid isPermaLink="false">https://www.habitablezone.com/?p=44815#comment-30593</guid>
		<description>http://www.habitablezone.com/ &amp; http://www.habitablezone.net/</description>
		<content:encoded><![CDATA[<p><a href="http://www.habitablezone.com/" rel="nofollow">http://www.habitablezone.com/</a> &amp; <a href="http://www.habitablezone.net/" rel="nofollow">http://www.habitablezone.net/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jody</title>
		<link>https://habitablezone.com/2014/05/05/certificate-error-greeted-me-this-am-copied-here/#comment-30592</link>
		<dc:creator>Jody</dc:creator>
		<pubDate>Mon, 05 May 2014 18:21:08 +0000</pubDate>
		<guid isPermaLink="false">https://www.habitablezone.com/?p=44815#comment-30592</guid>
		<description>Cat doody greeted me this morning.</description>
		<content:encoded><![CDATA[<p>Cat doody greeted me this morning.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
