astaro.org certificate

The current astaro.org wildcard certificate will expire in a few hours.

SSL Server Test: astaro.org (Powered by Qualys SSL Labs)


Server Key and Certificate #1
Common names *.astaro.org
Alternative names *.astaro.org astaro.org
Prefix handling Both (with and without WWW)
Valid from Mon Mar 24 21:38:38 PDT 2014
Valid until Fri Mar 27 19:55:08 PDT 2015 (expires in 10 hours and 31 minutes)
Key RSA 2048 bits (e 65537)
Weak key (Debian) No
Issuer RapidSSL CA


Also, administrator(s) please include any intermediate CA certificates required by a newer certificate.
  • I reinstalled windows 7 and when using the lastest version of Firefox it said the connection to astaro.org couldn't be trusted and I accepted the certificate anyway.  Now in Firefox the site is not showing correctly and can't be navigated.  I also installed Ubuntu and Firefox wouldn't load the site correctly.  However with Google Chrome everything works fine.  Also in a Windows 8.1 installation updated to the latest version of Firefox the site loads fine.
  • I have been having the same thing, also using Firefox.  It is not trusted in Chrome either for me though.
  • I reinstalled windows 7 and when using the lastest version of Firefox it said the connection to astaro.org couldn't be trusted and I accepted the certificate anyway.  Now in Firefox the site is not showing correctly and can't be navigated.  I also installed Ubuntu and Firefox wouldn't load the site correctly.  However with Google Chrome everything works fine.  Also in a Windows 8.1 installation updated to the latest version of Firefox the site loads fine.


    I had the same Problems on one of my PCs, after i accepted the expired certificate from last year (2014 were the same Problem).
    After that some layers of the Website were above others and i couldn't navigate on the Website... (with Firefox)

    I hadn't that Problem with Internet-Explorer or another PC, after a trusted certificate was implemented. 

    I removed the invalid certificate from Firefox and the certification store on my pc, without luck. I also uninstalled Firefox and deleted the Profile - again no luck.

    So i recommend not to accept the certificate until it is not valid and trusted ^^.

    greetz
  • The security certificate expiring isn't a big deal for this site.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • Embarrassing though, and might dissuade newbies from joining/participating.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • not really frankly https on this site is really unnecessary.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • I've emailed someone at Sophos that is involved in the blog/public forum projects they are working on and have notified them of the issue.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Sophos Platinum Partner

    --------------------------------------

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • Seems to be done, i see a cert valid till 30.04.2016.
  • With the new cert I get "Unable to get local issuer certificate" with SSL scanning enabled:


    What's wrong here?

    Webfilter log entries:
    2015:03:31-12:11:35 vpn-1 httpproxy[5935]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="" dstip="85.115.22.9" user="" ad_domain="" statuscode="302" cached="0" profile="REF_HttProInternalde (Internal_Default)" filteraction="REF_HttCffInterConteFilte (Internal content filter action)" size="235" request="0xabb8000" url="www.astaro.org/.../html"
    
    2015:03:31-12:11:35 vpn-1 httpproxy[5935]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="GET" srcip="" dstip="85.115.22.9" user="" ad_domain="" statuscode="403" cached="0" profile="REF_HttProInternalde (Internal_Default)" filteraction="REF_HttCffInterConteFilte (Internal content filter action)" size="3903" request="0xe0a22000" url="www.astaro.org/.../Business Forums"

    ----------
    Sophos user, admin and reseller.
    Private Setup:

    • XG: HPE DL20 Gen9 (Core i3-7300, 8GB RAM, 120GB SSD) | XG 18.0 (Home License) with: Web Protection, Site-to-Site-VPN (IPSec, RED-Tunnel), Remote Access (SSL, HTML5)
    • UTM: 2 vCPUs, 2GB RAM, 50GB vHDD, 2 vNICs on vServer (KVM) | UTM 9.7 (Home License) with: Email Protection, Webserver Protection, RED-Tunnel (server)