SOLVED ixsystems certificate error

Joined
Jun 2, 2019
Messages
591
Trying to download the nightly SCALE update file and receive the following error. I have cleared my browser cache and cookies.

https://update.freenas.org/scale/TrueNAS-SCALE-Angelfish-Nightlies/TrueNAS-SCALE.update

Not sure if it's related, but my SCALE testing platform stopped picking up new nightly updates since updating to nightly TrueNAS-SCALE-22.02-MASTER-20211124-112925


Screen Shot 2021-11-28 at 4.04.58 AM.png


Screen Shot 2021-11-28 at 3.45.48 AM.png
 
Last edited:
Joined
Jun 2, 2019
Messages
591
Go Daddy certificate, has this been revoked in response to the Go Daddy hacks?
Seems plausible



Now how do we get ixsystems to acknowledge and fix it?
 
Last edited:

morganL

Captain Morgan
Administrator
Moderator
iXsystems
Joined
Mar 10, 2018
Messages
2,694
Can we confirm if anyone else is seeing the same issue?
 

danb35

Hall of Famer
Joined
Aug 16, 2011
Messages
15,504
ssllabs.com is giving an F for update.freenas.org as well:

1638399681447.png

The issue is, again, that the cert is revoked:
1638399718590.png

SSLLabs shows the same F grade for each of eight IP addresses (four each IPv4 and IPv6 addresses), but I haven't looked at each report to confirm that each is for the same reason (though that seems likely).
 
Joined
Jun 2, 2019
Messages
591
With all that evidence, seems like an open and shut case. No plea bargin.

@morganL
 
Last edited:
Joined
Jun 2, 2019
Messages
591
Hopefully this lands in someone's inbox who can do something about it

Screen Shot 2021-12-01 at 6.34.48 PM.png
 

jgreco

Resident Grinch
Joined
May 29, 2011
Messages
18,680
And, of course, if they used Let's Encrypt, this would be a non-issue.

Well, not really. LetsEncrypt is its own ball of sh!+, with a need to run certbot or acme.sh or whatever, to maintain the certificates, and this isn't universally compatible with what could be a CDN or other traditional high volume distribution system. LetsEncrypt hasn't even managed to provide stability to the point where the stuff they originally released will still work today, and those of us who are actually responsible for maintaining at-scale infrastructure find it to be rather frustrating to design and redesign things as time passes. This compares poorly to the relatively simple act of simply renewing, downloading, and installing a new 2 year certificate. I certainly would have spent much less time doing three such renewals than I've spent fighting insipid, idiotic, and/or arbitrary changes in LetsEncrypt-based systems, some of which have broken with zero warning or notice.
 

morganL

Captain Morgan
Administrator
Moderator
iXsystems
Joined
Mar 10, 2018
Messages
2,694
It has an internal ticket to resolve.... I don't know what the cause was.
 

Jaron

iX IT Mgr
Administrator
Moderator
iXsystems
Joined
Oct 10, 2018
Messages
25
This has been resolved. There was a certificate change which wasnt updated at the CDN. All should be working now.
 
Joined
Jun 2, 2019
Messages
591
Confirmed

Screen Shot 2021-12-02 at 10.02.42 AM.png
 
Top