Bug 414291 - https://valgrind.org has an invalid certificate
Summary: https://valgrind.org has an invalid certificate
Status: RESOLVED FIXED
Alias: None
Product: valgrind
Classification: Developer tools
Component: general (show other bugs)
Version: unspecified
Platform: Other Linux
: NOR normal
Target Milestone: ---
Assignee: Julian Seward
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-11-19 10:05 UTC by Per Mildner
Modified: 2019-11-19 11:53 UTC (History)
1 user (show)

See Also:
Latest Commit:
Version Fixed In:
Sentry Crash Report:


Attachments
Firefox warning and information (179.09 KB, image/png)
2019-11-19 10:05 UTC, Per Mildner
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Per Mildner 2019-11-19 10:05:59 UTC
Created attachment 124008 [details]
Firefox warning and information

The certificate for https://valgrind.org is for another site, so browesers (Firefox, Chrome) refuse to enter.
Comment 1 Tom Hughes 2019-11-19 10:09:46 UTC
Where did you see that URL advertised?
Comment 2 Julian Seward 2019-11-19 10:55:05 UTC
It should be fixed now.  Per, can you try again?
Comment 3 Per Mildner 2019-11-19 11:02:00 UTC
It works now. Thanks.

(I did not see that URL advertised but I use https for everything, if at all possible.)
Comment 4 Tom Hughes 2019-11-19 11:47:15 UTC
Well that is what I suspect and was kind of my point - it is not valid to assume that you can just replace http with https.

When a site has not been https enabled and you try that you are going to get an error, whether a mismatch like this because you get a certificate for a different site on the same machine or a self signed certificate or just a connection failure.

It's fixed now anyway, and valgrind.org is improved by being https enabled which is a good outcome.
Comment 5 Per Mildner 2019-11-19 11:53:19 UTC
It is indeed a good outcome. Plain http is obsolete and Google Chrome, for instance, shows such sites as "Not Secure", which is not a good first impression.

So, perhaps the https version of the URL should be what is advertised henceforth?