Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Certificate https://revoked.badssl.com/ has expired #515

Closed
mjeffrey opened this issue Oct 28, 2022 · 7 comments
Closed

Certificate https://revoked.badssl.com/ has expired #515

mjeffrey opened this issue Oct 28, 2022 · 7 comments

Comments

@mjeffrey
Copy link

The certificate above has now expired. Could it be replaced? Thanks!

@natluqwerty
Copy link

please!!! 🙏

@drauch
Copy link

drauch commented Jul 18, 2023

Also the CRL for this certificate is empty? So it is not really revoked anymore?!

@szhu25
Copy link

szhu25 commented Jul 24, 2023

Also the CRL for this certificate is empty? So it is not really revoked anymore?!

Because the issuer certificate (intermediate certificate by RapidSSL/Digicert) also expired on May 31st, 2023...

@popeanga94
Copy link

Any updates on this issue? It would be very helpful if the certificate for https://revoked.badssl.com/ would be replaced with one that is not expired. Thx!

@levon-vardevanyan-solarwinds
Copy link

levon-vardevanyan-solarwinds commented Jan 9, 2024

Happy New Year! It's 2024 already - no plans to bring it back to life? This resource was actually tremendously helpful, looks like back in 2021 some amazing folks managed to fix it #477 maybe @BenWilson-Mozilla and @christhompson still have some knowledge/connection to resurrect it?

Meanwhile if anyone's wondering you can try using https://www.digicert.com/kb/digicert-root-certificates.htm

@gamer191
Copy link

I understand that this issue might not be worth fixing. However, please at least remove that domain, because currently it's misleading, since it suggests that every tested program that blocks expired certificates is capable of checking certificate revokation status

@christhompson
Copy link
Collaborator

Apologies for the long-expired cert here. The revoked test case was particularly painful to renew because we previously were manually issuing and revoking it, and then manually adding it to Chrome's certificate blocklist. I've switched this test case over to be included in our automated certificate renewal system using Lets Encrypt + ACME -- this means that it will just be marked as revoked in the CRLs, which may have different behavior across browsers, but it does mean it will automatically be kept renewed along with the other main certs for the site.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

8 participants