Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Nvd.nist.gov cert expired yesterday and uses HSTS (nist.gov)
15 points by SuperSandro2000 on Sept 2, 2024 | hide | past | favorite | 8 comments


Fails to load on my end right now. Firefox says:

"nvd.nist.gov has a security policy called HTTP Strict Transport Security (HSTS), which means that Firefox can only connect to it securely. You can't add an exception to visit this site.

(...) there is nothing you can do to resolve it."


for chrome users, to bypass this: just type "thisisunsafe" while focused on the error page. not very helpful in this scenario, but for other HSTS issues it might be! 2c


The fact that certificates for .gov's can still (due to procedural laziness) expire on a federal holiday without even a third party automated tweet to even notify the responsible or affected parties is a pure Kafka-eqsue tragedy when considered of the statistical inevitability that someone, somewhere, will lose their life to the coincidental crossroads of technical and bureaucratic err.


Some of the site's infrastructure is using an expired cert referencing letsencrypt R3 and other bits are serving a working cert at letsencrypt R10. Broken ACME updates maybe.

This can be so hard to get right! But I guess an automation oopsie is a step up from the need for spreadsheets, NMS checks, calendar reminders, and still having things expire once turnover erodes institutional knowledge.


Seems to be valid now.


Replying again, the inconsistency seems to be because their cert is fine over IPv6 but IPv4 is still showing expired. That’s a very strange setup y’all have there NIST.

https://www.ssllabs.com/ssltest/analyze.html?d=nvd.nist.gov


Bizarre, ssllabs test says IPv4 "A+", IPv6 "T" (whatever that means, Qualys).

I see the TLS error on direct connection, with Brave (Chromium), but have only IPv4 connectivity.


Still showing as expire cert on on my iPhone at 2024-09-02T15:54:30Z.

Do they have a cached OCSP staple response or something?




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: