logoalt Hacker News

dmitrygryesterday at 3:54 PM2 repliesview on HN

Which would make sense if they were valid for 10 years and somebody forgot about them. Not when they’re valid for, what is it now, 40 days?


Replies

smashedyesterday at 4:01 PM

An official government source is teaching users to ignore security warnings about expired certificates.

Mistakes happen, some automation failed and the certs did not renew on time, whatever. Does not inspire confidence but we all know it happens.

But then to just instruct users to click through the warning is very poor judgement on top of poor execution.

show 1 reply
lynndotpyyesterday at 4:28 PM

The certificate they failed to renew was valid for 365 days. You can check this in any modern desktop browser.