|
|
|
|
|
by dingaling
1 day ago
|
|
> I wish Firefox would just give a mild warning for a recently expired certificate Nope, if the SSL industry continues to insist on increasingly short cert lifetimes then I want Firefox to give no quarter when a cert expires. Play by their rules and fall by their rules too. |
|
The former is most likely an administrative error (ie: someone forgot to renew, or the auto-renew is failing). The latter is more likely to be an MTM attack.
I'm not sure how you would use an expired cert as an attack vector. By loading in an old cert into an expired domain so you could spoof older content?