{"id":207,"date":"2012-09-20T20:40:40","date_gmt":"2012-09-21T04:40:40","guid":{"rendered":"http:\/\/unmitigatedrisk.com\/?p=207"},"modified":"2012-09-20T20:40:40","modified_gmt":"2012-09-21T04:40:40","slug":"a-look-at-expired-certificates","status":"publish","type":"post","link":"https:\/\/unmitigatedrisk.com\/?p=207","title":{"rendered":"A look at expired certificates"},"content":{"rendered":"<p>Today I was on a mail thread where the topic of how browsers handle expired certificates; this is particularly relevant for a few reasons.<\/p>\n<p>The first of which is that there is a large number of sites operating with expired certificates out on the Internet today, the other is that the adoption of short lived certificates (which I am a fan of) is at least in part dependent on how browsers deal with certificates that are expired.<\/p>\n<p>In any event I was not sure how the most recent versions of browsers were handling these cases so I dug up an example site where an expired certificate was in use (https:\/\/www.appliancetherapy.com \u2013 it uses a certificate that expired a few weeks ago and has not as of yet been replaced).<\/p>\n<p>So what did I want to find? In a perfect world I believe that the following should be true:<\/p>\n<ol>\n<li>Users are warned or prohibited from going to the site in question.<\/li>\n<li>The warning language used is easy to understand and explains the risks.<\/li>\n<li>The warning language used is related to the fact that the certificate is expired.<\/li>\n<li>The trust indicator does not show or is marked to indicate that there is a problem.<\/li>\n<\/ol>\n<p>The good news is that for the most part browsers behaved fairly close to this, they all could have improved language but I believe Internet Explorers was the best.<\/p>\n<p>The worst behaving client was Mozilla, as it doesn\u2019t report the certificate as expired but instead indicates that it tried to make an OCSP request but got a response it was not expecting. This has two problems \u2013 the first of which being it should not have made an OCSP request for the status of an expired request.<\/p>\n<p><a href=\"http:\/\/www.ietf.org\/rfc\/rfc5280.txt\">RFC 5280<\/a>\u00a0Section 5 states that:<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 30px;\">\u00a0\u00a0 A complete CRL lists all unexpired certificates, within its scope,<\/p>\n<p style=\"padding-left: 30px;\">\u00a0 \u00a0that have been revoked for one of the revocation reasons covered by<\/p>\n<p style=\"padding-left: 30px;\">\u00a0\u00a0 the CRL scope.\u00a0 A full and complete CRL lists all unexpired<\/p>\n<p style=\"padding-left: 30px;\">\u00a0\u00a0 certificates issued by a CA that have been revoked for any reason.<\/p>\n<p>&nbsp;<\/p>\n<p>And\u00a0<a href=\"http:\/\/www.ietf.org\/rfc\/rfc2560.txt\">RFC 2560<\/a>\u00a0is written largely based on OCSP responses being fed from CRLs. What this means is that it is not appropriate to ask the revocation status of a certificate that is expired.<\/p>\n<p>The next problem is that Mozilla also doesn\u2019t handle the unauthorized response in a usable way.\u00a0<a href=\"http:\/\/www.rfc-editor.org\/rfc\/rfc5019.txt\">RFC 5019<\/a>\u00a0Section 2.2.3 states:<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 30px;\">\u00a0\u00a0\u00a0The response &#8220;unauthorized&#8221; is returned in cases where the client<\/p>\n<p style=\"padding-left: 30px;\">\u00a0\u00a0\u00a0is not authorized to make this query to this server or the server<\/p>\n<p style=\"padding-left: 30px;\">\u00a0\u00a0\u00a0is not capable of responding authoritatively.<\/p>\n<p>&nbsp;<\/p>\n<p>A user who receives this message would believe the issue is related to their permissions but based on the true reason for the error the failure as really that the responder in question doesn\u2019t have the information that\u2019s needed.<\/p>\n<p>This lack of information on the server is likely due to the fact that it isn\u2019t required to maintain information for expired certificates and the message Mozilla delivered should have been about the certificate being expired.<\/p>\n<p>In any event the browsers behaved much better than I expected, IE and Chrome did the best (I really like Chromes red \/ over the https as a visual queue there is a problem).<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2><\/h2>\n<h2>Chrome<\/h2>\n<p><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/chrome-expired.png\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"158\" class=\"alignnone size-medium wp-image-208\" title=\"chrome-expired\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/chrome-expired-300x158.png\" alt=\"\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/chrome-expired-300x158.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/chrome-expired-1024x539.png 1024w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/chrome-expired-284x150.png 284w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/chrome-expired.png 1356w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<h2>Internet Explorer<\/h2>\n<p><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/IE-expired.png\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"158\" class=\"alignnone size-medium wp-image-209\" title=\"IE-expired\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/IE-expired-300x158.png\" alt=\"\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/IE-expired-300x158.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/IE-expired-1024x542.png 1024w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/IE-expired-283x150.png 283w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/IE-expired.png 1360w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<h2>Mozilla<\/h2>\n<p><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Mozilla-expired.png\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"157\" class=\"alignnone size-medium wp-image-210\" title=\"Mozilla-expired\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Mozilla-expired-300x157.png\" alt=\"\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Mozilla-expired-300x157.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Mozilla-expired-1024x537.png 1024w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Mozilla-expired-285x150.png 285w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Mozilla-expired.png 1352w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<h2>Opera<\/h2>\n<p><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Opera-expired.png\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"155\" class=\"alignnone size-medium wp-image-211\" title=\"Opera-expired\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Opera-expired-300x155.png\" alt=\"\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Opera-expired-300x155.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Opera-expired-1024x532.png 1024w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Opera-expired-288x150.png 288w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Opera-expired.png 1345w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<h2>Safari<\/h2>\n<p><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Safari-expired.png\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"157\" class=\"alignnone size-medium wp-image-212\" title=\"Safari-expired\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Safari-expired-300x157.png\" alt=\"\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Safari-expired-300x157.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Safari-expired-1024x539.png 1024w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Safari-expired-284x150.png 284w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2012\/09\/Safari-expired.png 1352w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today I was on a mail thread where the topic of how browsers handle expired certificates; this is particularly relevant for a few reasons. The first of which is that there is a large number of sites operating with expired certificates out on the Internet today, the other is that the adoption of short lived [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3,4],"tags":[57,56,53,54,55],"class_list":["post-207","post","type-post","status-publish","format-standard","hentry","category-security","category-thoughts","tag-expired-certificate","tag-internet-explorer","tag-mozilla","tag-opera","tag-safari"],"_links":{"self":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/207","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=207"}],"version-history":[{"count":0,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/207\/revisions"}],"wp:attachment":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=207"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=207"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=207"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}