logoalt Hacker News

anademtoday at 1:02 AM2 repliesview on HN

Firefox says "Error Code: SEC_ERROR_UNKNOWN_ISSUER" for that CFTC link (untrusted certificate issued by Avast in Prague) and won't open the site


Replies

akerl_today at 1:05 AM

Not seeing that here; is your connection being MITM'd?

Issuer I'm seeing is Sectigo Public Server Authentication CA OV R36.

Avast is nominally an AV/VPN company; are you running their tooling on your machine?

Bendertoday at 1:16 AM

The cert I am seeing:

    Testing via IPv4:
    IPv4 (2 address(es)):
    104.18.25.94
    104.18.24.94
      subject   : C=US, ST=District of Columbia, O=Commodity Futures Trading Commission, CN=www.cftc.gov
      issuer    : C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA OV R36
      SAN       : DNS:www.cftc.gov, DNS:accountcreation.cftc.gov, DNS:cftc.gov, DNS:smartcheck.gov, DNS:whistleblower.gov, DNS:www.smartcheck.gov, DNS:www.whistleblower.gov
      sha1      : 42:AC:E2:34:10:93:10:9B:0E:45:6E:BC:A9:D5:B8:7D:C4:8B:BE:A5
      sha256    : E5:C9:F2:9F:4E:6C:30:51:AA:6B:63:AD:AD:F9:58:A4:E0:3E:7A:32:E9:2C:AB:8D:ED:4F:24:4D:D6:F0:DE:E8
      validity  : Oct 23 00:00:00 2025 GMT -> Nov  1 23:59:59 2026 GMT (81 days left)
      tls       : TLSv1.3 / 
      Verify return code: 0 (ok)
Are you seeing that too? This [1] is the function I am using. Claude's Improved version over my old chicken scratch.

Qualys Results [2] for www.cftc.gov Cloudflare in front of Drupal 11

[1] - https://nochan.net/b/Text-Crap/function_fingerprint2.sh

[2] - https://www.ssllabs.com/ssltest/analyze.html?d=www.cftc.gov&...