Hacker News new | ask | show | jobs
SSL certificate at https://www.cnn.com/ bad?
4 points by vocatan 4135 days ago
Testing SSL certificates and found that the SSL certificate that presents itself at https://www.cnn.com doesn't allow that hostname?

www.cnn.com uses an invalid security certificate. The certificate is only valid for the following names: a.ssl.fastly.net, .a.ssl.fastly.net, fast.wistia.com, purge.fastly.net, mirrors.fastly.net, .imgix.net, .parsecdn.com, .fastssl.net, voxer.com, www.voxer.com, .firebase.com, sites.yammer.com, sites.staging.yammer.com, .skimlinks.com, .skimresources.com, cdn.thinglink.me, .fitbit.com, .hosts.fastly.net, control.fastly.net, .wikia-inc.com, .perfectaudience.com, .wikia.com, f.cloud.github.com, .digitalscirocco.net, .etsy.com, .etsystatic.com, .addthis.com, .addthiscdn.com, fast.wistia.net, raw.github.com, www.userfox.com, .assets-yammer.com, .staging.assets-yammer.com, assets.huggies-cdn.net, api.kinja.com, orbit.shazamid.com, about.jstor.org, .global.ssl.fastly.net, web.voxer.com, pypi.python.org, .12wbt.com, www.holderdeord.no, secured.indn.infolinks.com, play.vidyard.com, play-staging.vidyard.com, secure.img.wfrcdn.com, secure.img.josscdn.com, .gocardless.com, widgets.pinterest.com, .7digital.com, .7static.com, p.datadoghq.com, .plan3.se, new.mulberry.com, www.safariflow.com, cdn.contentful.com, tools.fastly.net, .huevosbuenos.com, .goodeggs.com, .fastly.picmonkey.com, .cdn.whipplehill.net, .whipplehill.net, cdn.media34.whipplehill.net, cdn.media56.whipplehill.net, cdn.media78.whipplehill.net, cdn.media910.whipplehill.net, .modcloth.com, .disquscdn.com, .jstor.org, .dreamhost.com, www.flinto.com, .chartbeat.com, .hipmunk.com, content.beaverbrooks.co.uk, secure.common.csnstores.com, *.vsco.co,

full list at http://pastebin.com/raw.php?i=kwCzM5z0

2 comments

Interesting. I just visited the site and received a warning from firefox – the same invalid cert error was given, with the same domains.

The cert was issued to:

  a.ssl.fastly.net
  Fastly, Inc.
And issued by:

  DigiCert SHA2 High Assurance Server CA
  DigiCert Inc
Perhaps this is just a CDN error/issue?
Probably just a CDN issue (https://cnn.com not found, www. shows an error, etc.), but fyi...

Cert Subject Alt Names:

Not Critical DNS Name: a.ssl.fastly.net DNS Name: .a.ssl.fastly.net DNS Name: fast.wistia.com DNS Name: purge.fastly.net DNS Name: mirrors.fastly.net DNS Name: .imgix.net DNS Name: .parsecdn.com DNS Name: .fastssl.net DNS Name: voxer.com DNS Name: www.voxer.com DNS Name: .firebase.com DNS Name: sites.yammer.com DNS Name: sites.staging.yammer.com DNS Name: .skimlinks.com DNS Name: .skimresources.com DNS Name: cdn.thinglink.me DNS Name: .fitbit.com DNS Name: .hosts.fastly.net DNS Name: control.fastly.net DNS Name: .wikia-inc.com DNS Name: .perfectaudience.com DNS Name: .wikia.com DNS Name: f.cloud.github.com DNS Name: .digitalscirocco.net DNS Name: .etsy.com DNS Name: .etsystatic.com DNS Name: .addthis.com DNS Name: .addthiscdn.com DNS Name: fast.wistia.net DNS Name: raw.github.com DNS Name: www.userfox.com DNS Name: .assets-yammer.com DNS Name: .staging.assets-yammer.com DNS Name: assets.huggies-cdn.net DNS Name: api.kinja.com DNS Name: orbit.shazamid.com DNS Name: about.jstor.org DNS Name: .global.ssl.fastly.net DNS Name: web.voxer.com DNS Name: pypi.python.org DNS Name: .12wbt.com DNS Name: www.holderdeord.no DNS Name: secured.indn.infolinks.com DNS Name: play.vidyard.com DNS Name: play-staging.vidyard.com DNS Name: secure.img.wfrcdn.com DNS Name: secure.img.josscdn.com DNS Name: .gocardless.com DNS Name: widgets.pinterest.com DNS Name: .7digital.com DNS Name: .7static.com DNS Name: p.datadoghq.com DNS Name: .plan3.se DNS Name: new.mulberry.com DNS Name: www.safariflow.com DNS Name: cdn.contentful.com DNS Name: tools.fastly.net DNS Name: .huevosbuenos.com DNS Name: .goodeggs.com DNS Name: .fastly.picmonkey.com DNS Name: .cdn.whipplehill.net DNS Name: .whipplehill.net DNS Name: cdn.media34.whipplehill.net DNS Name: cdn.media56.whipplehill.net DNS Name: cdn.media78.whipplehill.net DNS Name: cdn.media910.whipplehill.net DNS Name: .modcloth.com DNS Name: .disquscdn.com DNS Name: .jstor.org DNS Name: .dreamhost.com DNS Name: www.flinto.com DNS Name: .chartbeat.com DNS Name: .hipmunk.com DNS Name: content.beaverbrooks.co.uk DNS Name: secure.common.csnstores.com DNS Name: .vsco.co DNS Name: www.joinos.com DNS Name: staging-mobile-collector.newrelic.com DNS Name: .modcloth.net DNS Name: .foursquare.com DNS Name: .shazam.com DNS Name: .4sqi.net DNS Name: .metacpan.org DNS Name: .fastly.com DNS Name: wikia.com DNS Name: fastly.com DNS Name: kinja.com DNS Name: .gadventures.com DNS Name: www.gadventures.com.au DNS Name: www.gadventures.co.uk DNS Name: kredo.com DNS Name: cdn-tags.brainient.com DNS Name: my.billspringapp.com DNS Name: rvm.io

serial: 01:E8:7D:87:DA:D5:21:F0:05:72:28:EE:85:7A:0A:E6 sha1 fingerprint: 01:E8:7D:87:DA:D5:21:F0:05:72:28:EE:85:7A:0A:E6