Last modified: 2010-04-09 11:56:54 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T25107, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 23107 - X.509 certificate for Bugzilla server(s) has expired
X.509 certificate for Bugzilla server(s) has expired
Status: RESOLVED INVALID
Product: Wikimedia
Classification: Unclassified
Bugzilla (Other open bugs)
unspecified
All All
: Normal normal (vote)
: ---
Assigned To: Priyanka Dhanda
https://bugzilla.wikimedia.org/
: shell
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2010-04-09 10:21 UTC by Nico R.
Modified: 2010-04-09 11:56 UTC (History)
3 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Nico R. 2010-04-09 10:21:13 UTC
The X.509 certificate for bugzilla.wikimedia.org has expired: it is not valid after 2011-01-31T21:36:50+00:00. It should be replaced.


Side notes:

It also uses the MD5 algorithm for hashing, which is not considered secure anymore. This should be changed to a more secure algorithm like one from the SHA-2 family.

The certificate is also used for bugs.wikimedia.org, but does not contain that host name in the certificate (should be included in subjectAlternativeName as a dNSName). bugs.wikimedia.org uses a HTTP 302 Moved to redirect users to bugzilla.wikimedia.org, but this does not mean that the certificate does not have to include the host name as well. (Or a second certificate has to be used.)

Furthermore, I recommend restricting keyUsage to critical:(digitalSignature,keyEncipherment) (this will limit the usable algorithms to the ones with ephemeral keys, which should not be a problem, but considered a good thing) and extendedKeyUsage to (serverAuth). Client authentication is probably unnecessary for the certificate.
Comment 1 Jan Luca 2010-04-09 10:31:24 UTC
Hi,

the current year is 2010 and not 2011. 

Is this a error from your browser? If yes, control your date settings.

Viele Grüße
Jan
Comment 2 Roan Kattouw 2010-04-09 11:56:54 UTC
Certificate is valid for another 9 months, closing.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links