Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

Like punning, programming is a play on words.


computers / microsoft.public.windowsxp.general / Invalid certificate

SubjectAuthor
* Invalid certificateG.F.
+* Re: Invalid certificateAoli
|`- Re: Invalid certificateG.F.
+* Re: Invalid certificateShadow
|`* Re: Invalid certificateG.F.
| +* Re: Invalid certificateShadow
| |`- Re: Invalid certificateShadow
| `* Re: Invalid certificatePaul
|  `* Re: Invalid certificateShadow
|   `- Re: Invalid certificatePaul
+- Re: Invalid certificateMayayana
+* Re: Invalid certificateSteve Hayes
|+* Re: Invalid certificatePaul
||`* Re: Invalid certificateJJ
|| `- Re: Invalid certificateShadow
|`- Re: Invalid certificatepyotr filipivich
`* Re: Invalid certificateLu Wei
 +- Re: Invalid certificateJJ
 `* Re: Invalid certificatePamela
  `- Re: Invalid certificateJ. P. Gilliver (John)

1
Invalid certificate

<sj74e2$15s4$1@gioia.aioe.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1209&group=microsoft.public.windowsxp.general#1209

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!LtoP2/5dIpHK+cdGEfLg4g.user.46.165.242.75.POSTED!not-for-mail
From: nospam@grazie.it (G.F.)
Newsgroups: microsoft.public.windowsxp.general
Subject: Invalid certificate
Date: Fri, 1 Oct 2021 16:02:46 +0200
Organization: Aioe.org NNTP Server
Lines: 10
Message-ID: <sj74e2$15s4$1@gioia.aioe.org>
Injection-Info: gioia.aioe.org; logging-data="38788"; posting-host="LtoP2/5dIpHK+cdGEfLg4g.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-Newsreader: Microsoft Outlook Express 6.00.2900.5931
X-Notice: Filtered by postfilter v. 0.9.2
X-MSMail-Priority: Normal
X-RFC2646: Format=Flowed; Original
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.6157
X-Priority: 3
 by: G.F. - Fri, 1 Oct 2021 14:02 UTC

Hi all.
The number of websites unusable with XP is increasing, due to the "invalid
certificate".
1) is there an easy way to install other certificates on XP?.
2) even if the certificate is invalid, the browser offers the option to
continue. What may be the risk of continuing?

GF

Re: Invalid certificate

<sj7fc0$egr$1@gioia.aioe.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1210&group=microsoft.public.windowsxp.general#1210

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!8ER4TMW3TSRnvS06aECo6g.user.46.165.242.91.POSTED!not-for-mail
From: Aoli@Aoli.com (Aoli)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Fri, 1 Oct 2021 10:09:25 -0700
Organization: Aioe.org NNTP Server
Message-ID: <sj7fc0$egr$1@gioia.aioe.org>
References: <sj74e2$15s4$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="14875"; posting-host="8ER4TMW3TSRnvS06aECo6g.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:52.0) Gecko/20100101 Firefox/52.0
SeaMonkey/2.49.5
X-Notice: Filtered by postfilter v. 0.9.2
 by: Aoli - Fri, 1 Oct 2021 17:09 UTC

Try MyPal browser.

G.F. wrote:
> Hi all.
> The number of websites unusable with XP is increasing, due to the "invalid
> certificate".
> 1) is there an easy way to install other certificates on XP?.
> 2) even if the certificate is invalid, the browser offers the option to
> continue. What may be the risk of continuing?
>
> GF
>
>

Re: Invalid certificate

<99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1211&group=microsoft.public.windowsxp.general#1211

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!FggddZiATW67Rfmh6dtpdg.user.46.165.242.75.POSTED!not-for-mail
From: Sh@dow.br (Shadow)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Fri, 01 Oct 2021 16:58:25 -0300
Organization: A noiseless patient Shadow
Message-ID: <99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com>
References: <sj74e2$15s4$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
Injection-Info: gioia.aioe.org; logging-data="27462"; posting-host="FggddZiATW67Rfmh6dtpdg.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-Notice: Filtered by postfilter v. 0.9.2
X-Newsreader: Forte Agent 3.3/32.846
 by: Shadow - Fri, 1 Oct 2021 19:58 UTC

On Fri, 1 Oct 2021 16:02:46 +0200, "G.F." <nospam@grazie.it> wrote:

>Hi all.
>The number of websites unusable with XP is increasing, due to the "invalid
>certificate".
>1) is there an easy way to install other certificates on XP?.
>2) even if the certificate is invalid, the browser offers the option to
>continue. What may be the risk of continuing?

Let's Encrypt went bonkers this week.

Download the certificates from

https://letsencrypt.org/certificates/

You'll need ISRG Root X1, ISRG Root X2, Let’s Encrypt R3 and
Let’s Encrypt E1.

Download them using the links (right click, save as).

You can add them to your XP store by double clicking on them.

To add them to Firefox/whatever by go to tools --> options -->
advanced --> certificates --> View Certificates.
Click on import certificate. After you've imported them all,
go to "Internet Security Research Group" and "edit trust". Check they
are trusted for web pages or whatever.
HTH

PS Can't remember which are best for what. *.PEM worked for
Firefox. Can't remember if I used *.PEM or *.DER for XP.
[]'s
--
Don't be evil - Google 2004
We have a new policy - Google 2012
Google Fuchsia - 2021

Re: Invalid certificate

<sj7rcl$1m9u$1@gioia.aioe.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1212&group=microsoft.public.windowsxp.general#1212

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!LtoP2/5dIpHK+cdGEfLg4g.user.46.165.242.75.POSTED!not-for-mail
From: nospam@grazie.it (G.F.)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Fri, 1 Oct 2021 22:34:35 +0200
Organization: Aioe.org NNTP Server
Lines: 14
Message-ID: <sj7rcl$1m9u$1@gioia.aioe.org>
References: <sj74e2$15s4$1@gioia.aioe.org> <sj7fc0$egr$1@gioia.aioe.org>
Injection-Info: gioia.aioe.org; logging-data="55614"; posting-host="LtoP2/5dIpHK+cdGEfLg4g.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-RFC2646: Format=Flowed; Response
X-Newsreader: Microsoft Outlook Express 6.00.2900.5931
X-Priority: 3
X-MSMail-Priority: Normal
X-Notice: Filtered by postfilter v. 0.9.2
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.6157
 by: G.F. - Fri, 1 Oct 2021 20:34 UTC

"Aoli" <Aoli@Aoli.com> ha scritto nel messaggio
news:sj7fc0$egr$1@gioia.aioe.org...
>
> Try MyPal browser.

The official website doesn't work because of... invalid certificate. :-)
Majorgeeks doesn't work because of... invalid certificate. :-)
Softpedia doesn't work because of... 404 page not found :-)

I'm at the end of my rope. :-)

GF

Re: Invalid certificate

<sj7rg0$1naf$1@gioia.aioe.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1213&group=microsoft.public.windowsxp.general#1213

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!LtoP2/5dIpHK+cdGEfLg4g.user.46.165.242.75.POSTED!not-for-mail
From: nospam@grazie.it (G.F.)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Fri, 1 Oct 2021 22:36:22 +0200
Organization: Aioe.org NNTP Server
Lines: 15
Message-ID: <sj7rg0$1naf$1@gioia.aioe.org>
References: <sj74e2$15s4$1@gioia.aioe.org> <99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com>
Injection-Info: gioia.aioe.org; logging-data="56655"; posting-host="LtoP2/5dIpHK+cdGEfLg4g.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.6157
X-MSMail-Priority: Normal
X-Notice: Filtered by postfilter v. 0.9.2
X-Newsreader: Microsoft Outlook Express 6.00.2900.5931
X-RFC2646: Format=Flowed; Original
X-Priority: 3
 by: G.F. - Fri, 1 Oct 2021 20:36 UTC

"Shadow" <Sh@dow.br> ha scritto nel messaggio
news:99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com...
> On Fri, 1 Oct 2021 16:02:46 +0200, "G.F." <nospam@grazie.it> wrote:

> Download the certificates from
>
> https://letsencrypt.org/certificates/

I get "Invalid certificate" :-)

I'm at the end of my rope. :-)

GF

Re: Invalid certificate

<5o0flg5tt4de1jne3vjrdjgb11nct3lel9@4ax.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1214&group=microsoft.public.windowsxp.general#1214

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!FggddZiATW67Rfmh6dtpdg.user.46.165.242.75.POSTED!not-for-mail
From: Sh@dow.br (Shadow)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Fri, 01 Oct 2021 18:57:50 -0300
Organization: A noiseless patient Shadow
Message-ID: <5o0flg5tt4de1jne3vjrdjgb11nct3lel9@4ax.com>
References: <sj74e2$15s4$1@gioia.aioe.org> <99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com> <sj7rg0$1naf$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="50609"; posting-host="FggddZiATW67Rfmh6dtpdg.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-Notice: Filtered by postfilter v. 0.9.2
X-Newsreader: Forte Agent 3.3/32.846
 by: Shadow - Fri, 1 Oct 2021 21:57 UTC

On Fri, 1 Oct 2021 22:36:22 +0200, "G.F." <nospam@grazie.it> wrote:

>"Shadow" <Sh@dow.br> ha scritto nel messaggio
>news:99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com...
>> On Fri, 1 Oct 2021 16:02:46 +0200, "G.F." <nospam@grazie.it> wrote:
>
>> Download the certificates from
>>
>> https://letsencrypt.org/certificates/
>
>I get "Invalid certificate" :-)
>
>I'm at the end of my rope. :-)
>
>GF

LOL. Allow an "Exception"(assuming Firefox). Then you can open
the certs page. Double clicking on the "*.der" download link will
install the certificate to the browser. Close the browser, open it and
you should be good to go.
As I said, you'll have to right-click and save them if you
want to install to your XP cache.
HTH
[]'s
--
Don't be evil - Google 2004
We have a new policy - Google 2012
Google Fuchsia - 2021

Re: Invalid certificate

<2v1flgh58smag5b9ioebuqbjl7qevov5sb@4ax.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1215&group=microsoft.public.windowsxp.general#1215

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!rocksolid2!i2pn.org!aioe.org!FggddZiATW67Rfmh6dtpdg.user.46.165.242.75.POSTED!not-for-mail
From: Sh@dow.br (Shadow)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Fri, 01 Oct 2021 19:15:06 -0300
Organization: A noiseless patient Shadow
Message-ID: <2v1flgh58smag5b9ioebuqbjl7qevov5sb@4ax.com>
References: <sj74e2$15s4$1@gioia.aioe.org> <99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com> <sj7rg0$1naf$1@gioia.aioe.org> <5o0flg5tt4de1jne3vjrdjgb11nct3lel9@4ax.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
Injection-Info: gioia.aioe.org; logging-data="62508"; posting-host="FggddZiATW67Rfmh6dtpdg.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-Newsreader: Forte Agent 3.3/32.846
X-Notice: Filtered by postfilter v. 0.9.2
 by: Shadow - Fri, 1 Oct 2021 22:15 UTC

On Fri, 01 Oct 2021 18:57:50 -0300, Shadow <Sh@dow.br> wrote:

>On Fri, 1 Oct 2021 22:36:22 +0200, "G.F." <nospam@grazie.it> wrote:
>
>>"Shadow" <Sh@dow.br> ha scritto nel messaggio
>>news:99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com...
>>> On Fri, 1 Oct 2021 16:02:46 +0200, "G.F." <nospam@grazie.it> wrote:
>>
>>> Download the certificates from
>>>
>>> https://letsencrypt.org/certificates/
>>
>>I get "Invalid certificate" :-)
>>
>>I'm at the end of my rope. :-)
>>
>>GF

Correction:
>
> LOL. Allow an "Exception"(assuming Firefox). Then you can open
>the certs page. Double clicking on the "*.der" download link will
>install the

certificateS. Just one is not enough.

(You'll need ISRG Root X1, ISRG Root X2, Let’s Encrypt R3 and
Let’s Encrypt E1)

> to the browser. Close the browser, open it and
>you should be good to go.
> As I said, you'll have to right-click and save them if you
>want to install to your XP cache.
> HTH
> []'s
--
Don't be evil - Google 2004
We have a new policy - Google 2012
Google Fuchsia - 2021

Re: Invalid certificate

<sj8e3m$vrm$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1216&group=microsoft.public.windowsxp.general#1216

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Fri, 1 Oct 2021 21:53:50 -0400
Organization: A noiseless patient Spider
Lines: 139
Message-ID: <sj8e3m$vrm$1@dont-email.me>
References: <sj74e2$15s4$1@gioia.aioe.org>
<99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com> <sj7rg0$1naf$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Sat, 2 Oct 2021 01:53:58 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="9fd781c9625a580f06eba02695724a87";
logging-data="32630"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/8bTtL2w/SaLExRfp5PrI3IoP1LenxZSw="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:QVRGTMAFIyuMBEbdKRD8ipczxi8=
In-Reply-To: <sj7rg0$1naf$1@gioia.aioe.org>
Content-Language: en-US
 by: Paul - Sat, 2 Oct 2021 01:53 UTC

On 10/1/2021 4:36 PM, G.F. wrote:
> "Shadow" <Sh@dow.br> ha scritto nel messaggio
> news:99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com...
>> On Fri, 1 Oct 2021 16:02:46 +0200, "G.F." <nospam@grazie.it> wrote:
>
>> Download the certificates from
>>
>> https://letsencrypt.org/certificates/
>
> I get "Invalid certificate" :-)
>
> I'm at the end of my rope. :-)
>
> GF

This is to give you some idea how hard it will be to
bootstrap. Apparently Firefox has its own certificate store.
But (of course), a modern Firefox, like a Firefox 91 won't
run on Windows XP.

I picked this post, the one at the end right now, to
show there are "hand tools" that are not browsers.

https://borncity.com/win/2021/09/30/sept-30-2021-will-we-see-trouble-with-old-lets-encrypt-certificates/

"Ubuntu 16.04 doesnt recognizes at all.
Tried to update the /etc/ssl/certs/ca-certificates.crt but no effect.

The only thing that made it work was to update openssl package and
then update curl pointing to the new openssl (all done by compiling method)
to get the curl to work.

wget still not working as its as pre-compiled with old openssl…
Still wondering if it has something to do with this topic or just a coincidence."

What we'd need then, is a curl which is updated today, and
available on an http (not https) site.

https://curl.se/download.html # Yeah, I know, https

curl version: 7.79.1
Build: 7.79.1
Date: 2021-09-22 # Not today...

https://curl.se/windows/dl-7.79.1/curl-7.79.1-win32-mingw.zip <=== advertised as...

http://curl.se/windows/dl-7.79.1/curl-7.79.1-win32-mingw.zip <=== seems to work...

WGET would be the better tool, because the description reads as this,
but as far as I know, it doesn't have internal certificates.

"wget is a fantastic tool for downloading content and files. It can download files,
web pages, and directories. It contains intelligent routines to traverse links in
web pages and recursively download content across an entire website. It is
unsurpassed as a command-line download manager."

Now CURL is supposed to have certificates, as part of pulling stuff
into its library.

"curl satisfies an altogether different need. Yes, it can retrieve files, but it
cannot recursively navigate a website looking for content to retrieve."

This usage of CURL is silly. Don't do this. The problem would be,
with binary or ISOs or the like. You want something that won't screw up,
if doing big downloads.

cd /d C:\Downloads\CurlDir # Point at the dir with the EXE in it

curl https://www.bbc.com > bbc.html

Whereas this one, puts content into a file. The log should still
be dumped into Command Prompt.

curl -o bbc.html https://www.bbc.com

My WinXP computer broke two days ago (would freeze in memtest).
All the hardware is pulled from the computer case, the case is
just sitting near my shoulder, EMPTY!!! No hardwares. Can't test
diddly now. I'm running off Win7 at the moment, haven't moved
my email over, the usual mess.

Now, we need any emergency OS with Firefox in it, on the
assumption it has certificates. I picked the Lite version,
for lower RAM consumption.

https://mirror.clarkson.edu/zorinos/isos/15/Zorin-OS-15.3-Lite-32-bit.iso

curl -o zorin153x86.iso https://mirror.clarkson.edu/zorinos/isos/15/Zorin-OS-15.3-Lite-32-bit.iso

That's around 2GB, so should work in FAT32 for storage, and you
can burn a DVD of that for boot purposes.

I tested in a VM, and that will boot on 512MB, but you can't
start Firefox unless the computer has about 1GB of RAM for "comfort".
Running a LiveDVD, RAM is used for scratch file space, which is
why these things jam up so easily.

I can put that on a USB stick. I used rufus.ie to do a USB stick,
and it offered me a 26GB casper-rw persistent partition. This is
on a 32GB USB stick. This is an EXT partition and not just a loopback
mount as might be more normal (lots of persistent sticks have
just 4GB of storage on a bitmap file sitting on a FAT32 partition,
which is why they have the 4GB limit). This happens to be a Ubuntu at
the moment, and I can see a file stamping the stick as being
made by Rufus.

--- /dev/sde
Block device, size 29.22 GiB (31376707072 bytes)
DOS/MBR partition map
Partition 1: 3.221 GiB (3458359296 bytes, 6754608 sectors from 2048, bootable)
Type 0x0C (Win95 FAT32 (LBA))
SYSLINUX boot loader
FAT32 file system (hints score 4 of 5)
Volume size 3.217 GiB (3454156800 bytes, 210825 clusters of 16 KiB)
Partition 2: 26.00 GiB (27917277696 bytes, 54525933 sectors from 6756656)
Type 0x83 (Linux)
Ext3 file system
Volume name "casper-rw"
UUID 69FD8B2A-C16A-8B42-9C60-6DDC9C4FE0E9 (DCE, v8)
Last mounted at "/"
Volume size 26.00 GiB (27917275136 bytes, 6815741 blocks of 4 KiB)

The USB would be useful, if you've done these before, and your
machine has a USB boot capability. Otherwise, it's a DVD thing.
A DVD won't work on my first PC (1.1GHz Tualatin), and there
I need a CD instead (the BIOS does not grok DVD type as a hardware).

This might not work due to github web code. But if it does, you can
play with using a USB stick instead of a DVD blank.

curl.exe -o rufus315.exe https://github.com/pbatard/rufus/releases/download/v3.15/rufus-3.15p.exe

Once you're booted into Zorin Live Lite, you can follow Shadows suggestions
and look at various web sites for certificate downloads.

I don't know how far you'll get, but that's an idea of
how I'd try to escape the Houdini box you're in.

Paul

Re: Invalid certificate

<eobglgh43igpnoqhp8sj1ihfq5lnnd554l@4ax.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1217&group=microsoft.public.windowsxp.general#1217

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!Sk+LPk95o70GpI7WA2i4KA.user.46.165.242.75.POSTED!not-for-mail
From: Sh@dow.br (Shadow)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Sat, 02 Oct 2021 07:36:46 -0300
Organization: A noiseless patient Shadow
Message-ID: <eobglgh43igpnoqhp8sj1ihfq5lnnd554l@4ax.com>
References: <sj74e2$15s4$1@gioia.aioe.org> <99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com> <sj7rg0$1naf$1@gioia.aioe.org> <sj8e3m$vrm$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
Injection-Info: gioia.aioe.org; logging-data="14185"; posting-host="Sk+LPk95o70GpI7WA2i4KA.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-Newsreader: Forte Agent 3.3/32.846
X-Notice: Filtered by postfilter v. 0.9.2
 by: Shadow - Sat, 2 Oct 2021 10:36 UTC

On Fri, 1 Oct 2021 21:53:50 -0400, Paul <nospam@needed.invalid> wrote:

>On 10/1/2021 4:36 PM, G.F. wrote:
>> "Shadow" <Sh@dow.br> ha scritto nel messaggio
>> news:99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com...
>>> On Fri, 1 Oct 2021 16:02:46 +0200, "G.F." <nospam@grazie.it> wrote:
>>
>>> Download the certificates from
>>>
>>> https://letsencrypt.org/certificates/
>>
>> I get "Invalid certificate" :-)
>>
>> I'm at the end of my rope. :-)
>>
>> GF
>
>This is to give you some idea how hard it will be to
>bootstrap. Apparently Firefox has its own certificate store.
>But (of course), a modern Firefox, like a Firefox 91 won't
>run on Windows XP.
>
>I picked this post, the one at the end right now, to
>show there are "hand tools" that are not browsers.
>
>https://borncity.com/win/2021/09/30/sept-30-2021-will-we-see-trouble-with-old-lets-encrypt-certificates/
>
> "Ubuntu 16.04 doesnt recognizes at all.
> Tried to update the /etc/ssl/certs/ca-certificates.crt but no effect.
>
> The only thing that made it work was to update openssl package and
> then update curl pointing to the new openssl (all done by compiling method)
> to get the curl to work.
>
> wget still not working as its as pre-compiled with old openssl…
> Still wondering if it has something to do with this topic or just a coincidence."
>
>What we'd need then, is a curl which is updated today, and
>available on an http (not https) site.
>
>https://curl.se/download.html # Yeah, I know, https
>
> curl version: 7.79.1
> Build: 7.79.1
> Date: 2021-09-22 # Not today...
>
> https://curl.se/windows/dl-7.79.1/curl-7.79.1-win32-mingw.zip <=== advertised as...
>
> http://curl.se/windows/dl-7.79.1/curl-7.79.1-win32-mingw.zip <=== seems to work...
>
>WGET would be the better tool, because the description reads as this,
>but as far as I know, it doesn't have internal certificates.
>
> "wget is a fantastic tool for downloading content and files. It can download files,
> web pages, and directories. It contains intelligent routines to traverse links in
> web pages and recursively download content across an entire website. It is
> unsurpassed as a command-line download manager."
>
>Now CURL is supposed to have certificates, as part of pulling stuff
>into its library.
>
> "curl satisfies an altogether different need. Yes, it can retrieve files, but it
> cannot recursively navigate a website looking for content to retrieve."
>
>This usage of CURL is silly. Don't do this. The problem would be,
>with binary or ISOs or the like. You want something that won't screw up,
>if doing big downloads.
>
> cd /d C:\Downloads\CurlDir # Point at the dir with the EXE in it
>
> curl https://www.bbc.com > bbc.html
>
>Whereas this one, puts content into a file. The log should still
>be dumped into Command Prompt.
>
> curl -o bbc.html https://www.bbc.com
>
>My WinXP computer broke two days ago (would freeze in memtest).
>All the hardware is pulled from the computer case, the case is
>just sitting near my shoulder, EMPTY!!! No hardwares. Can't test
>diddly now. I'm running off Win7 at the moment, haven't moved
>my email over, the usual mess.
>
>Now, we need any emergency OS with Firefox in it, on the
>assumption it has certificates. I picked the Lite version,
>for lower RAM consumption.
>
>https://mirror.clarkson.edu/zorinos/isos/15/Zorin-OS-15.3-Lite-32-bit.iso
>
> curl -o zorin153x86.iso https://mirror.clarkson.edu/zorinos/isos/15/Zorin-OS-15.3-Lite-32-bit.iso
>
>That's around 2GB, so should work in FAT32 for storage, and you
>can burn a DVD of that for boot purposes.
>
>I tested in a VM, and that will boot on 512MB, but you can't
>start Firefox unless the computer has about 1GB of RAM for "comfort".
>Running a LiveDVD, RAM is used for scratch file space, which is
>why these things jam up so easily.
>
>I can put that on a USB stick. I used rufus.ie to do a USB stick,
>and it offered me a 26GB casper-rw persistent partition. This is
>on a 32GB USB stick. This is an EXT partition and not just a loopback
>mount as might be more normal (lots of persistent sticks have
>just 4GB of storage on a bitmap file sitting on a FAT32 partition,
>which is why they have the 4GB limit). This happens to be a Ubuntu at
>the moment, and I can see a file stamping the stick as being
>made by Rufus.
>
>--- /dev/sde
>Block device, size 29.22 GiB (31376707072 bytes)
>DOS/MBR partition map
>Partition 1: 3.221 GiB (3458359296 bytes, 6754608 sectors from 2048, bootable)
> Type 0x0C (Win95 FAT32 (LBA))
> SYSLINUX boot loader
> FAT32 file system (hints score 4 of 5)
> Volume size 3.217 GiB (3454156800 bytes, 210825 clusters of 16 KiB)
>Partition 2: 26.00 GiB (27917277696 bytes, 54525933 sectors from 6756656)
> Type 0x83 (Linux)
> Ext3 file system
> Volume name "casper-rw"
> UUID 69FD8B2A-C16A-8B42-9C60-6DDC9C4FE0E9 (DCE, v8)
> Last mounted at "/"
> Volume size 26.00 GiB (27917275136 bytes, 6815741 blocks of 4 KiB)
>
>The USB would be useful, if you've done these before, and your
>machine has a USB boot capability. Otherwise, it's a DVD thing.
>A DVD won't work on my first PC (1.1GHz Tualatin), and there
>I need a CD instead (the BIOS does not grok DVD type as a hardware).
>
>This might not work due to github web code. But if it does, you can
>play with using a USB stick instead of a DVD blank.
>
> curl.exe -o rufus315.exe https://github.com/pbatard/rufus/releases/download/v3.15/rufus-3.15p.exe
>
>Once you're booted into Zorin Live Lite, you can follow Shadows suggestions
>and look at various web sites for certificate downloads.
>
>I don't know how far you'll get, but that's an idea of
>how I'd try to escape the Houdini box you're in.
>
> Paul

I understand what you did, but it's a bit of an overkill for a
XP-only user.

I just loaded the page(Palemoon - same dialogs as an old
Firefox), got the invalid certificate warning, chose the "exception"
(or whatever it's called)

"Are you sure, you are playing with fire, you naughty person"

I clicked "I LIKE playing with fire"

The page opened, I downloaded the certs (pem, der AND txt -
wasn't sure which ones I needed), then manually installed them both to
XP and the browser.

https://postimg.cc/QVbV07cG

(yes, you need the certs to access Postimg)

Of course, once they were working I checked the fingerprints
at

https://www.grc.com/fingerprints.htm

(that uses a Digicert certificate)

When you allow an exception, for all practical purposes you
are using http ..... which can be tampered with. Best to be sure you
got valid certs.

My wget is v1.19.4, it's the last version that works with XP
and apparently it uses the XP store of certs. It's working fine now.

Incredible how many of my favorite sites broke because of the
Let's Encrypt fsckup. Didn't realize how popular it was.

PS I removed ALL references to Let'sEncrypt in my cert store
before installing the new ones. Didn't want any conflicts.
[]'s
--
Don't be evil - Google 2004
We have a new policy - Google 2012
Google Fuchsia - 2021

Re: Invalid certificate

<sj9f7k$5ot$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1218&group=microsoft.public.windowsxp.general#1218

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Sat, 2 Oct 2021 07:19:06 -0400
Organization: A noiseless patient Spider
Lines: 199
Message-ID: <sj9f7k$5ot$1@dont-email.me>
References: <sj74e2$15s4$1@gioia.aioe.org>
<99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com> <sj7rg0$1naf$1@gioia.aioe.org>
<sj8e3m$vrm$1@dont-email.me> <eobglgh43igpnoqhp8sj1ihfq5lnnd554l@4ax.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Sat, 2 Oct 2021 11:19:16 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="9fd781c9625a580f06eba02695724a87";
logging-data="5917"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19TC9YMpGV+2GhQrUXfWknQcbWppntdYuY="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:sg7qxzFvUJsiwg+HsIcajdppLEc=
In-Reply-To: <eobglgh43igpnoqhp8sj1ihfq5lnnd554l@4ax.com>
Content-Language: en-US
 by: Paul - Sat, 2 Oct 2021 11:19 UTC

On 10/2/2021 6:36 AM, Shadow wrote:
> On Fri, 1 Oct 2021 21:53:50 -0400, Paul <nospam@needed.invalid> wrote:
>
>> On 10/1/2021 4:36 PM, G.F. wrote:
>>> "Shadow" <Sh@dow.br> ha scritto nel messaggio
>>> news:99pelg5hhh0o2h4pghmb7qb93glcilgvo9@4ax.com...
>>>> On Fri, 1 Oct 2021 16:02:46 +0200, "G.F." <nospam@grazie.it> wrote:
>>>
>>>> Download the certificates from
>>>>
>>>> https://letsencrypt.org/certificates/
>>>
>>> I get "Invalid certificate" :-)
>>>
>>> I'm at the end of my rope. :-)
>>>
>>> GF
>>
>> This is to give you some idea how hard it will be to
>> bootstrap. Apparently Firefox has its own certificate store.
>> But (of course), a modern Firefox, like a Firefox 91 won't
>> run on Windows XP.
>>
>> I picked this post, the one at the end right now, to
>> show there are "hand tools" that are not browsers.
>>
>> https://borncity.com/win/2021/09/30/sept-30-2021-will-we-see-trouble-with-old-lets-encrypt-certificates/
>>
>> "Ubuntu 16.04 doesnt recognizes at all.
>> Tried to update the /etc/ssl/certs/ca-certificates.crt but no effect.
>>
>> The only thing that made it work was to update openssl package and
>> then update curl pointing to the new openssl (all done by compiling method)
>> to get the curl to work.
>>
>> wget still not working as its as pre-compiled with old openssl…
>> Still wondering if it has something to do with this topic or just a coincidence."
>>
>> What we'd need then, is a curl which is updated today, and
>> available on an http (not https) site.
>>
>> https://curl.se/download.html # Yeah, I know, https
>>
>> curl version: 7.79.1
>> Build: 7.79.1
>> Date: 2021-09-22 # Not today...
>>
>> https://curl.se/windows/dl-7.79.1/curl-7.79.1-win32-mingw.zip <=== advertised as...
>>
>> http://curl.se/windows/dl-7.79.1/curl-7.79.1-win32-mingw.zip <=== seems to work...
>>
>> WGET would be the better tool, because the description reads as this,
>> but as far as I know, it doesn't have internal certificates.
>>
>> "wget is a fantastic tool for downloading content and files. It can download files,
>> web pages, and directories. It contains intelligent routines to traverse links in
>> web pages and recursively download content across an entire website. It is
>> unsurpassed as a command-line download manager."
>>
>> Now CURL is supposed to have certificates, as part of pulling stuff
>> into its library.
>>
>> "curl satisfies an altogether different need. Yes, it can retrieve files, but it
>> cannot recursively navigate a website looking for content to retrieve."
>>
>> This usage of CURL is silly. Don't do this. The problem would be,
>> with binary or ISOs or the like. You want something that won't screw up,
>> if doing big downloads.
>>
>> cd /d C:\Downloads\CurlDir # Point at the dir with the EXE in it
>>
>> curl https://www.bbc.com > bbc.html
>>
>> Whereas this one, puts content into a file. The log should still
>> be dumped into Command Prompt.
>>
>> curl -o bbc.html https://www.bbc.com
>>
>> My WinXP computer broke two days ago (would freeze in memtest).
>> All the hardware is pulled from the computer case, the case is
>> just sitting near my shoulder, EMPTY!!! No hardwares. Can't test
>> diddly now. I'm running off Win7 at the moment, haven't moved
>> my email over, the usual mess.
>>
>> Now, we need any emergency OS with Firefox in it, on the
>> assumption it has certificates. I picked the Lite version,
>> for lower RAM consumption.
>>
>> https://mirror.clarkson.edu/zorinos/isos/15/Zorin-OS-15.3-Lite-32-bit.iso
>>
>> curl -o zorin153x86.iso https://mirror.clarkson.edu/zorinos/isos/15/Zorin-OS-15.3-Lite-32-bit.iso
>>
>> That's around 2GB, so should work in FAT32 for storage, and you
>> can burn a DVD of that for boot purposes.
>>
>> I tested in a VM, and that will boot on 512MB, but you can't
>> start Firefox unless the computer has about 1GB of RAM for "comfort".
>> Running a LiveDVD, RAM is used for scratch file space, which is
>> why these things jam up so easily.
>>
>> I can put that on a USB stick. I used rufus.ie to do a USB stick,
>> and it offered me a 26GB casper-rw persistent partition. This is
>> on a 32GB USB stick. This is an EXT partition and not just a loopback
>> mount as might be more normal (lots of persistent sticks have
>> just 4GB of storage on a bitmap file sitting on a FAT32 partition,
>> which is why they have the 4GB limit). This happens to be a Ubuntu at
>> the moment, and I can see a file stamping the stick as being
>> made by Rufus.
>>
>> --- /dev/sde
>> Block device, size 29.22 GiB (31376707072 bytes)
>> DOS/MBR partition map
>> Partition 1: 3.221 GiB (3458359296 bytes, 6754608 sectors from 2048, bootable)
>> Type 0x0C (Win95 FAT32 (LBA))
>> SYSLINUX boot loader
>> FAT32 file system (hints score 4 of 5)
>> Volume size 3.217 GiB (3454156800 bytes, 210825 clusters of 16 KiB)
>> Partition 2: 26.00 GiB (27917277696 bytes, 54525933 sectors from 6756656)
>> Type 0x83 (Linux)
>> Ext3 file system
>> Volume name "casper-rw"
>> UUID 69FD8B2A-C16A-8B42-9C60-6DDC9C4FE0E9 (DCE, v8)
>> Last mounted at "/"
>> Volume size 26.00 GiB (27917275136 bytes, 6815741 blocks of 4 KiB)
>>
>> The USB would be useful, if you've done these before, and your
>> machine has a USB boot capability. Otherwise, it's a DVD thing.
>> A DVD won't work on my first PC (1.1GHz Tualatin), and there
>> I need a CD instead (the BIOS does not grok DVD type as a hardware).
>>
>> This might not work due to github web code. But if it does, you can
>> play with using a USB stick instead of a DVD blank.
>>
>> curl.exe -o rufus315.exe https://github.com/pbatard/rufus/releases/download/v3.15/rufus-3.15p.exe
>>
>> Once you're booted into Zorin Live Lite, you can follow Shadows suggestions
>> and look at various web sites for certificate downloads.
>>
>> I don't know how far you'll get, but that's an idea of
>> how I'd try to escape the Houdini box you're in.
>>
>> Paul
>
> I understand what you did, but it's a bit of an overkill for a
> XP-only user.
>
> I just loaded the page(Palemoon - same dialogs as an old
> Firefox), got the invalid certificate warning, chose the "exception"
> (or whatever it's called)
>
> "Are you sure, you are playing with fire, you naughty person"
>
> I clicked "I LIKE playing with fire"
>
> The page opened, I downloaded the certs (pem, der AND txt -
> wasn't sure which ones I needed), then manually installed them both to
> XP and the browser.
>
> https://postimg.cc/QVbV07cG
>
> (yes, you need the certs to access Postimg)
>
> Of course, once they were working I checked the fingerprints
> at
>
> https://www.grc.com/fingerprints.htm
>
> (that uses a Digicert certificate)
>
> When you allow an exception, for all practical purposes you
> are using http ..... which can be tampered with. Best to be sure you
> got valid certs.
>
> My wget is v1.19.4, it's the last version that works with XP
> and apparently it uses the XP store of certs. It's working fine now.
>
> Incredible how many of my favorite sites broke because of the
> Let's Encrypt fsckup. Didn't realize how popular it was.
>
> PS I removed ALL references to Let'sEncrypt in my cert store
> before installing the new ones. Didn't want any conflicts.
> []'s
>
> --
> Don't be evil - Google 2004
> We have a new policy - Google 2012
> Google Fuchsia - 2021
>

I provided the info, to show that with some lucky,
you could bootstrap yourself. As long as just
a few developers remember to provide an http: path
to the goods, we'll be OK.

Nobody really has the energy to keep this stuff going forever.
It's too brittle for that.


Click here to read the complete article
Re: Invalid certificate

<sj9lgt$crr$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1219&group=microsoft.public.windowsxp.general#1219

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: mayayana@invalid.nospam (Mayayana)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Sat, 2 Oct 2021 09:04:57 -0400
Organization: A noiseless patient Spider
Lines: 29
Message-ID: <sj9lgt$crr$1@dont-email.me>
References: <sj74e2$15s4$1@gioia.aioe.org>
Injection-Date: Sat, 2 Oct 2021 13:06:37 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="61ab2a0f5e7a68e7f8e1ee027c821e29";
logging-data="13179"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+SHQnj0aM4T2rP2AGKie95PcHrxqXo3Ts="
Cancel-Lock: sha1:Wo8KjYvxW4AN0nJfBBUNvSjwKew=
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-Priority: 3
X-MSMail-Priority: Normal
 by: Mayayana - Sat, 2 Oct 2021 13:04 UTC

"G.F." <nospam@grazie.it> wrote

| Hi all.
| The number of websites unusable with XP is increasing, due to the "invalid
| certificate".
| 1) is there an easy way to install other certificates on XP?.
| 2) even if the certificate is invalid, the browser offers the option to
| continue. What may be the risk of continuing?
| I don't have any problems and I don't remember doing
anything specific. I just visited majorgeeks.com. No
problems. I have FF52.9 and New Moon 28.1. But some
things you might try:

Get New Moon browser.

Set browser.xul.error_pages.expert_bad_cert to true

Set browser.ssl_override_behavior to 1

Risks? In the vast majority of cases a bad cert is likely
to be because it expired. It can also be caused when a
hosted site is using a cert that's not for its own domain.
If you plan to enter a credit card number it matters. If
you're at majorgeeks and you just want to download, then
who cares? You can also usually see in the error page why
the cert was rejected.

Re: Invalid certificate

<q90rlghif8t4b8e6bnrr82kre10pns4aql@4ax.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1226&group=microsoft.public.windowsxp.general#1226

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: hayesstw@telkomsa.net (Steve Hayes)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Wed, 06 Oct 2021 12:59:39 +0200
Organization: Khanya Publications
Lines: 26
Message-ID: <q90rlghif8t4b8e6bnrr82kre10pns4aql@4ax.com>
References: <sj74e2$15s4$1@gioia.aioe.org>
Reply-To: hayesstw@yahoo.com
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Info: reader02.eternal-september.org; posting-host="7456f2c748b2c4203aedaa11842106fc";
logging-data="3387"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19cLXti/4seH+6SePCzCxN+b3GECuvAExE="
Cancel-Lock: sha1:FPeWVJhiAQiEY6ddTKB3ujG21vw=
X-No-Archive: yes
X-Antivirus-Status: Clean
X-Newsreader: Forte Free Agent 2.0/32.652
X-Antivirus: Avast (VPS 211005-4, 2021-10-05), Outbound message
 by: Steve Hayes - Wed, 6 Oct 2021 10:59 UTC

On Fri, 1 Oct 2021 16:02:46 +0200, "G.F." <nospam@grazie.it> wrote:

>Hi all.
>The number of websites unusable with XP is increasing, due to the "invalid
>certificate".
>1) is there an easy way to install other certificates on XP?.
>2) even if the certificate is invalid, the browser offers the option to
>continue. What may be the risk of continuing?

In Firefox I get "This site is untrusted", aznd in most cases I can
override it.

But in Maxthon I get this:

Avast has blocked access to https://share.social9.co/ because one of
the issuers of the server certificate has expired.

What is causing it, and can anything be done about it?

--
Steve Hayes from Tshwane, South Africa
Web: http://www.khanya.org.za/stevesig.htm
Blog: http://khanya.wordpress.com
E-mail - see web page, or parse: shayes at dunelm full stop org full stop uk

Re: Invalid certificate

<sjk4dl$5sl$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1227&group=microsoft.public.windowsxp.general#1227

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!rocksolid2!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Wed, 6 Oct 2021 08:21:47 -0400
Organization: A noiseless patient Spider
Lines: 29
Message-ID: <sjk4dl$5sl$1@dont-email.me>
References: <sj74e2$15s4$1@gioia.aioe.org>
<q90rlghif8t4b8e6bnrr82kre10pns4aql@4ax.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 6 Oct 2021 12:22:13 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="71fff6f5e9c2a095a6552b2de2a722ea";
logging-data="6037"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18oIBtxA6M7Vi3gtKMaE2hAU/AGN9s5vWg="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:p64XPOO/t+P2FayiK/HHKdQAgX8=
In-Reply-To: <q90rlghif8t4b8e6bnrr82kre10pns4aql@4ax.com>
Content-Language: en-US
 by: Paul - Wed, 6 Oct 2021 12:21 UTC

On 10/6/2021 6:59 AM, Steve Hayes wrote:
> On Fri, 1 Oct 2021 16:02:46 +0200, "G.F." <nospam@grazie.it> wrote:
>
>> Hi all.
>> The number of websites unusable with XP is increasing, due to the "invalid
>> certificate".
>> 1) is there an easy way to install other certificates on XP?.
>> 2) even if the certificate is invalid, the browser offers the option to
>> continue. What may be the risk of continuing?
>
> In Firefox I get "This site is untrusted", aznd in most cases I can
> override it.
>
> But in Maxthon I get this:
>
> Avast has blocked access to https://share.social9.co/ because one of
> the issuers of the server certificate has expired.
>
> What is causing it, and can anything be done about it?

Is the spelling of this

share.social9.co

correct, or is something missing ?

Paul

Re: Invalid certificate

<cinrlg5sr4d1rtcgq4qflg6mk5p9rovmrt@4ax.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1228&group=microsoft.public.windowsxp.general#1228

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.snarked.org!border2.nntp.dca1.giganews.com!nntp.giganews.com!buffer2.nntp.dca1.giganews.com!nntp.earthlink.com!news.earthlink.com.POSTED!not-for-mail
NNTP-Posting-Date: Wed, 06 Oct 2021 12:42:41 -0500
From: phamp@mindspring.com (pyotr filipivich)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Wed, 06 Oct 2021 10:42:47 -0700
Organization: Fortesque D&R Labs
Reply-To: phamp@mindspring.com
Message-ID: <cinrlg5sr4d1rtcgq4qflg6mk5p9rovmrt@4ax.com>
References: <sj74e2$15s4$1@gioia.aioe.org> <q90rlghif8t4b8e6bnrr82kre10pns4aql@4ax.com>
X-Newsreader: Forte Agent 3.3/32.846
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Lines: 29
X-Usenet-Provider: http://www.giganews.com
NNTP-Posting-Host: 73.59.74.45
X-Trace: sv3-jf8G35NdKjlbG1yh5vDybMXyRYYoL5uCAhnjQTxlDc5dGU+3AjFaKUOBcYC6ZUHjWoBVXq6K7Qh3CMz!bxrOEmeLjF1ZfbVSEADMuFR5cIZTHFVqmmFtLhJU1r5ZRzMVSoZhVwHAMgsyu7AP0oRWe5uSlR6s!epfCf+QjF+8vVMoN0A9U8aE=
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 2299
 by: pyotr filipivich - Wed, 6 Oct 2021 17:42 UTC

Steve Hayes <hayesstw@telkomsa.net> on Wed, 06 Oct 2021 12:59:39 +0200
typed in microsoft.public.windowsxp.general the following:
>On Fri, 1 Oct 2021 16:02:46 +0200, "G.F." <nospam@grazie.it> wrote:
>
>>Hi all.
>>The number of websites unusable with XP is increasing, due to the "invalid
>>certificate".
>>1) is there an easy way to install other certificates on XP?.
>>2) even if the certificate is invalid, the browser offers the option to
>>continue. What may be the risk of continuing?
>
>In Firefox I get "This site is untrusted", aznd in most cases I can
>override it.
>
>But in Maxthon I get this:
>
>Avast has blocked access to https://share.social9.co/ because one of
>the issuers of the server certificate has expired.

There was a report of one of the root certificates "expiring" (I
did not know they could do that) which will cause many "trust" issues
after 1 Oct.
>
>What is causing it, and can anything be done about it?
--
pyotr filipivich
This Week's Panel: Us & Them - Eliminating Them.
Next Month's Panel: Having eliminated the old Them(tm)
Selecting who insufficiently Woke(tm) as to serve as the new Them(tm)

Re: Invalid certificate

<1rna6dcqedo6c$.1b6lydn5huzz0$.dlg@40tude.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1229&group=microsoft.public.windowsxp.general#1229

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!wwlhla4zaRMAGLwj8sHq0w.user.46.165.242.91.POSTED!not-for-mail
From: jj4public@gmail.com (JJ)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Thu, 7 Oct 2021 10:47:06 +0700
Organization: Aioe.org NNTP Server
Message-ID: <1rna6dcqedo6c$.1b6lydn5huzz0$.dlg@40tude.net>
References: <sj74e2$15s4$1@gioia.aioe.org> <q90rlghif8t4b8e6bnrr82kre10pns4aql@4ax.com> <sjk4dl$5sl$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="32673"; posting-host="wwlhla4zaRMAGLwj8sHq0w.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: 40tude_Dialog/2.0.15.84
X-Bitcoin: 1LcqwCQBQmhcWfWsVEAeyLchkAY8ZfuMnS
X-Face: \*\`0(1j~VfYC>ebz[&O.]=,Nm\oRM{of,liRO#7Eqi4|!]!(Gs=Akgh{J)605>C9Air?pa d{sSZ09u+A7f<^paR"/NH_#<mE1S"hde\c6PZLUB[t/s5-+Iu5DSc?P0+4%,Hl
X-Notice: Filtered by postfilter v. 0.9.2
 by: JJ - Thu, 7 Oct 2021 03:47 UTC

On Wed, 6 Oct 2021 08:21:47 -0400, Paul wrote:
> On 10/6/2021 6:59 AM, Steve Hayes wrote:
>> On Fri, 1 Oct 2021 16:02:46 +0200, "G.F." <nospam@grazie.it> wrote:
>>
>>> Hi all.
>>> The number of websites unusable with XP is increasing, due to the "invalid
>>> certificate".
>>> 1) is there an easy way to install other certificates on XP?.
>>> 2) even if the certificate is invalid, the browser offers the option to
>>> continue. What may be the risk of continuing?
>>
>> In Firefox I get "This site is untrusted", aznd in most cases I can
>> override it.
>>
>> But in Maxthon I get this:
>>
>> Avast has blocked access to https://share.social9.co/ because one of
>> the issuers of the server certificate has expired.
>>
>> What is causing it, and can anything be done about it?
>
> Is the spelling of this
>
> share.social9.co
>
> correct, or is something missing ?
>
> Paul

I think it's `.com`. Not `.co`. Cause I don't think Colombia domains are
popular enough.

There doesn't seem to be a problem with its certificate when accessed from
XP.

https://www.ssllabs.com/ssltest/analyze.html?d=share.social9.com

Re: Invalid certificate

<5j4ulgpga27m73bdi6fms8k48ciu1a0sjc@4ax.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1230&group=microsoft.public.windowsxp.general#1230

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!p3JtVg1gut1Y6rBRpQ8bQQ.user.46.165.242.75.POSTED!not-for-mail
From: Sh@dow.br (Shadow)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Thu, 07 Oct 2021 12:46:09 -0300
Organization: A noiseless patient Shadow
Message-ID: <5j4ulgpga27m73bdi6fms8k48ciu1a0sjc@4ax.com>
References: <sj74e2$15s4$1@gioia.aioe.org> <q90rlghif8t4b8e6bnrr82kre10pns4aql@4ax.com> <sjk4dl$5sl$1@dont-email.me> <1rna6dcqedo6c$.1b6lydn5huzz0$.dlg@40tude.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="49871"; posting-host="p3JtVg1gut1Y6rBRpQ8bQQ.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-Newsreader: Forte Agent 3.3/32.846
X-Notice: Filtered by postfilter v. 0.9.2
 by: Shadow - Thu, 7 Oct 2021 15:46 UTC

On Thu, 7 Oct 2021 10:47:06 +0700, JJ <jj4public@gmail.com> wrote:

>On Wed, 6 Oct 2021 08:21:47 -0400, Paul wrote:
>> On 10/6/2021 6:59 AM, Steve Hayes wrote:
>>> On Fri, 1 Oct 2021 16:02:46 +0200, "G.F." <nospam@grazie.it> wrote:
>>>
>>>> Hi all.
>>>> The number of websites unusable with XP is increasing, due to the "invalid
>>>> certificate".
>>>> 1) is there an easy way to install other certificates on XP?.
>>>> 2) even if the certificate is invalid, the browser offers the option to
>>>> continue. What may be the risk of continuing?
>>>
>>> In Firefox I get "This site is untrusted", aznd in most cases I can
>>> override it.
>>>
>>> But in Maxthon I get this:
>>>
>>> Avast has blocked access to https://share.social9.co/ because one of
>>> the issuers of the server certificate has expired.
>>>
>>> What is causing it, and can anything be done about it?
>>
>> Is the spelling of this
>>
>> share.social9.co
>>
>> correct, or is something missing ?
>>
>> Paul
>
>I think it's `.com`. Not `.co`. Cause I don't think Colombia domains are
>popular enough.
>
>There doesn't seem to be a problem with its certificate when accessed from
>XP.
>
>https://www.ssllabs.com/ssltest/analyze.html?d=share.social9.com

http://share.social9.com redirects to https://shr.social9.com/

Which is a 404.
The site uses a Let's Encrypt R3 cert valid until Nov 15th
2021.
Can't find any references to the site on a Glugle search,
other than it's hosted on an Amacon server.

It's alternative https://9sh.re/shorturl

Has this in the description:

//marketing platform, audience insights, audience intelligence,
audience intel, managed service, social sharing, sharing, website
personalization, personalize website, personalization, share this,
plugins, best free plugins, widgets, best free widgets, best website
plugins, premium plugins, premium widgets, responsive tools,
responsive widgets, share buttons, facebook like, facebook share,
pinterest button, tweet button, twitter button, instagram button,
follow buttons, social buttons, social plugins, recommended content,
content widget, wordpress, joomla, blogger, get likes, get shares, get
followers//

Personally, I wouldn't trust it with or without a valid
certificate.
[]'s
--
Don't be evil - Google 2004
We have a new policy - Google 2012
Google Fuchsia - 2021

Re: Invalid certificate

<sjtnbt$9no$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1249&group=microsoft.public.windowsxp.general#1249

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: luweitest@gmail.com (Lu Wei)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Sun, 10 Oct 2021 11:40:42 +0800
Organization: A noiseless patient Spider
Lines: 23
Message-ID: <sjtnbt$9no$1@dont-email.me>
References: <sj74e2$15s4$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
Injection-Date: Sun, 10 Oct 2021 03:40:45 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="a5fae532e99a1e268e62adc3e96ac14e";
logging-data="9976"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX183ihXsF+9MlxS1n2Eyp6DR+K8Lvz3VzBM="
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:52.0) Gecko/20100101 Hamster-Pg/1.25.2.0
Thunderbird/52.9.1
Cancel-Lock: sha1:hvlMu5fYTQ2L7nojCjFXvLqGTM4=
In-Reply-To: <sj74e2$15s4$1@gioia.aioe.org>
Content-Language: en-US
Autocrypt: addr=luweitest@gmail.com; prefer-encrypt=mutual; keydata=
xsDiBEfowZoRBACCADBlqVDeCH7P6O66N5tSVPbgjaVTADFFUbpLSHnbkoqogTBFnKDOoQsr
HYXC4g/W0lLlfcIEdZ6alQTyIjCdHLwNQDVqOv//GL0jZQwBN2ziJfb7FaUOQmA6kiY6lWYQ
8Ij43sZh1+KdmTNAJy3EVnln9Gu4pJbDxWl5rygBzwCggSNybNNRl2S3Oiebd1YRi5gDEOMD
/0eFBG1Y8yNIxQZNjHWzYb2fRjI743Bi2C8x+NcfSSYy5pcTpYo47Xv5iv4INHionIHbTb2x
gFe5GkK3CQ1v/SOohU7GY6L6l3aAtVYkjGi1QSts0MiJ1+ZTz2Wfl54XwdRopPq5Ftek+Zki
afNMnLzh23X6cbvk1UATQVB7u1SWA/9CmUnS6cmlqg1LY9yEpSD/TbHWJuj0HYgMnEH36o5V
n2LkiWP6CcmBxhTIHh5uL0IWZSFBC64gVHs0UBEMwuxYKFTp8tiCUD9LLWwjaW9W1LX0i8M5
NguLEKvnRVuo7JTmQoOiZ3hKGyyhfGylZ5bp/4O8uDlpeD/K6wNZl/h+cs0cTHUgV2VpIDxs
dXdlaXRlc3RAZ21haWwuY29tPsKCBBMRAgBCAhsDBgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIX
gAIZARYhBGHl7m9JQjH4GqLG7qEv73WSzOHqBQJfHkKrBQka9+gRAAoJEKEv73WSzOHqwXIA
nidZzJAB7FLlqG8sUzlckiDH3KKoAJ9lS48hPgO8RoCP0oR0RLJSH9DE6s7BTQRH6MGaEAgA
xWn2jga6API5DqQ2+WjiUt9PIdL/g7aOESXsZAzDIsSzI4teO+G9rb+Am1TitTNZe4S0itnK
wBaR4uUEMWwe75mqKqmlsz9lc8YDLa+WU6obZuvYtpRZ2DHVm1lAqulGM+LTr+H5wFpEliLt
MqtS/cfUa/BJWhFXQHmUNFvpXd518lazfPgU6N4Yin8FIlSmsStrJR73KXtzzt8SJxcJBSFD
yrj0nfkehWUbZU3F1EV4fK94scni+5UK/5xNvtyfYtVZTcOE/1NIHWSOU1cloIgaUI9F4xvv
FJmmvfxlwvDtHDMhwUGGAXS7E82QtUfpJHsqXuq2OV7V8SwKzyIZOwADBQgAn4GC4TKWckZF
H8m4j44UUKfC5nAysiDnKxa5fqwg+p1duO19YQ8oUBwAAbl77/Cigwa3tTnD1ydi5JZ19T/P
s9lG4bPIloGRP/+G2W9tp3vm29fyHIXEU3N4gAzk7aGFbSenxKbey4K0S6yqTipbXZ1CWTpY
wM4SN1mCaehC7vjvPCN2AnNGjVLm+KM02x+qJLzjw4b5uXDoynjTx8Pb74aNSiIPM42Gpurq
MLj28GgMbIXi+3m/Je847Z4bilnSkN9Pm5cAPDtPQy0FXz4JgD9Sy/R2KVWbtpW7U7SIiMAI
6MItN6kBnOIYT65ZlbMdNHMK78B7Yract0+aZQrlq8JmBBgRAgAmAhsMFiEEYeXub0lCMfga
osbuoS/vdZLM4eoFAl8eQrMFCRr36BkACgkQoS/vdZLM4epzhgCfQH7mw3JA32XMOXNuoCrb
jkozWvQAn3tt3lBaRt6vN+iXfNJNVXjP/DRJ
Openpgp: id=61E5EE6F494231F81AA2C6EEA12FEF7592CCE1EA
 by: Lu Wei - Sun, 10 Oct 2021 03:40 UTC

On 2021-10-1 22:02, G.F. wrote:
> Hi all.
> The number of websites unusable with XP is increasing, due to the "invalid
> certificate".
> 1) is there an easy way to install other certificates on XP?.

Yes, XP can still update to the most recent OS|IE certificates. Try the tool at:
https://msfn.org/board/topic/175170-root-certificates-and-revoked-certificates-for-windows-xp/page/3/

And use a more recent browser:
https://rtfreesoft.blogspot.com/search/label/serpent

> 2) even if the certificate is invalid, the browser offers the option to
> continue. What may be the risk of continuing?
>

There's possibility of man-in-the-middle attack, trying to steal something from you. No risk if you do not provide personal information or install anything.

--
Regards,
Lu Wei
IM: xmpp:luweitest@riotcat.org
PGP: 0xA12FEF7592CCE1EA

Re: Invalid certificate

<u742r21kmz0z.1h68hasthr8v5$.dlg@40tude.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1250&group=microsoft.public.windowsxp.general#1250

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!IsjeSeFEaX8LPqsGNOmS1Q.user.46.165.242.91.POSTED!not-for-mail
From: jj4public@gmail.com (JJ)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Sun, 10 Oct 2021 13:37:39 +0700
Organization: Aioe.org NNTP Server
Message-ID: <u742r21kmz0z.1h68hasthr8v5$.dlg@40tude.net>
References: <sj74e2$15s4$1@gioia.aioe.org> <sjtnbt$9no$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="56174"; posting-host="IsjeSeFEaX8LPqsGNOmS1Q.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: 40tude_Dialog/2.0.15.84
X-Bitcoin: 1LcqwCQBQmhcWfWsVEAeyLchkAY8ZfuMnS
X-Notice: Filtered by postfilter v. 0.9.2
X-Face: \*\`0(1j~VfYC>ebz[&O.]=,Nm\oRM{of,liRO#7Eqi4|!]!(Gs=Akgh{J)605>C9Air?pa d{sSZ09u+A7f<^paR"/NH_#<mE1S"hde\c6PZLUB[t/s5-+Iu5DSc?P0+4%,Hl
 by: JJ - Sun, 10 Oct 2021 06:37 UTC

On Sun, 10 Oct 2021 11:40:42 +0800, Lu Wei wrote:
> On 2021-10-1 22:02, G.F. wrote:
>> Hi all.
>> The number of websites unusable with XP is increasing, due to the "invalid
>> certificate".
>> 1) is there an easy way to install other certificates on XP?.
>
> Yes, XP can still update to the most recent OS|IE certificates. Try the tool at:
> https://msfn.org/board/topic/175170-root-certificates-and-revoked-certificates-for-windows-xp/page/3/

The most recent Microsoft's official root certificates and certificate
revocations can be downloaded from below URLs. (long URL warning)

http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab

http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab

Extract the contents and double-click the STL files to import them.

Because there's no XP update to support new security chipers, don't use on
internet applications that use Windows built in cryptography libraries. Most
of such applications are available for Windows platform only (i.e. non cross
platform softwares).

Re: Invalid certificate

<XnsAE2977ABF502C37B93@144.76.35.252>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2012&group=microsoft.public.windowsxp.general#2012

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: pamela.private.mailbox@gmail.com (Pamela)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
Date: Mon, 24 Jan 2022 11:45:51 GMT
Organization: A noiseless patient Spider
Lines: 29
Message-ID: <XnsAE2977ABF502C37B93@144.76.35.252>
References: <sj74e2$15s4$1@gioia.aioe.org> <sjtnbt$9no$1@dont-email.me>
Injection-Info: reader02.eternal-september.org; posting-host="38196aa31d13ab1fbe0cc6ce3af8b2a3";
logging-data="4098"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19Pxjj7CJGHG15wWr6M4JqmedgoIuTydnI="
User-Agent: Xnews/2009.05.01
Cancel-Lock: sha1:pIvhrBLuxStSKwFJI5YsLGZVjAY=
 by: Pamela - Mon, 24 Jan 2022 11:45 UTC

On 03:40 10 Oct 2021, Lu Wei said:
> On 2021-10-1 22:02, G.F. wrote:
>>
>> Hi all.
>> The number of websites unusable with XP is increasing, due to the
>> "invalid certificate".
>> 1) is there an easy way to install other certificates on XP?.
>
> Yes, XP can still update to the most recent OS|IE certificates. Try
> the tool at:
> https://msfn.org/board/topic/175170-root-certificates-and-revoked-cert
> ificates-for-windows-xp/page/3/

Interesting old thread. Is all everything required to be done written on
that page (page three)? I don't have the stamina to go through 38 pages!

> And use a more recent browser:
> https://rtfreesoft.blogspot.com/search/label/serpent

I find MyPal (v.29) runs a bit slowly but is more compatible with sites
than Firefox v.52. Is Serpent better?

>> 2) even if the certificate is invalid, the browser offers the option
>> to continue. What may be the risk of continuing?
>>
>
> There's possibility of man-in-the-middle attack, trying to steal
> something from you. No risk if you do not provide personal
> information or install anything.

Re: Invalid certificate

<H39RqFz0Hs7hFwEr@a.a>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2017&group=microsoft.public.windowsxp.general#2017

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!news.mixmin.net!border2.nntp.dca1.giganews.com!nntp.giganews.com!buffer2.nntp.dca1.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Mon, 24 Jan 2022 09:13:45 -0600
Message-ID: <H39RqFz0Hs7hFwEr@a.a>
Date: Mon, 24 Jan 2022 15:12:52 +0000
From: G6JPG@255soft.uk (J. P. Gilliver (John))
Reply-To: G6JPG@255soft.uk
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Invalid certificate
References: <sj74e2$15s4$1@gioia.aioe.org> <sjtnbt$9no$1@dont-email.me>
<XnsAE2977ABF502C37B93@144.76.35.252>
Organization: 255 software
MIME-Version: 1.0
Content-Type: text/plain;charset=us-ascii;format=flowed
User-Agent: Turnpike/6.07-M (<j9oDLEkP8kSCVCEgcdTACgANXh>)
Lines: 49
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-D1K+J2/aIMKwUpj3VBbKwomNPrNie5no3/0vLrb7GVZ5GCAxUkVM9OVkirPpk9WACZzNVTpITX3dfxt!35QDBnFnXgeVHZTSxfsRZUjyWazoxd1z2IQkZavahPsKSpnPz8FzX37B/rr7c3o=
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 3179
 by: J. P. Gilliver (John - Mon, 24 Jan 2022 15:12 UTC

On Mon, 24 Jan 2022 at 11:45:51, Pamela
<pamela.private.mailbox@gmail.com> wrote (my responses usually follow
points raised):
>On 03:40 10 Oct 2021, Lu Wei said:
>> On 2021-10-1 22:02, G.F. wrote:
>>>
>>> Hi all.
>>> The number of websites unusable with XP is increasing, due to the
>>> "invalid certificate".
>>> 1) is there an easy way to install other certificates on XP?.
>>
>> Yes, XP can still update to the most recent OS|IE certificates. Try
>> the tool at:
>> https://msfn.org/board/topic/175170-root-certificates-and-revoked-cert
>> ificates-for-windows-xp/page/3/
>
>Interesting old thread. Is all everything required to be done written on
>that page (page three)? I don't have the stamina to go through 38 pages!
>
>> And use a more recent browser:
>> https://rtfreesoft.blogspot.com/search/label/serpent
>
>I find MyPal (v.29) runs a bit slowly but is more compatible with sites
>than Firefox v.52. Is Serpent better?

I don't think its a matter of better or worse, but that Firefox uses its
own certificate store, rather than using XP's store. (Based on a weak
understanding of what I've read here: I'm no longer on XP, and the
Firefox I use is a _very_ old one - I don't know if the one you use -
the latest that works under XP perhaps? - still uses its own store.
Certainly my ancient Firefox keeps asking this question for sites to
which Chrome has no problem.)
>
>>> 2) even if the certificate is invalid, the browser offers the option
>>> to continue. What may be the risk of continuing?
>>>
>>
>> There's possibility of man-in-the-middle attack, trying to steal
>> something from you. No risk if you do not provide personal
>> information or install anything.

It has always struck me as unusual that Firefox's "shall I store this
exception" box (i. e. allowing you to continue to use the site it thinks
has an invalid certificate, without asking every time) is pre-ticked.
Such things usually aren't, erring on the side of safety.
--
J. P. Gilliver. UMRA: 1960/<1985 MB++G()AL-IS-Ch++(p)Ar@T+H+Sh0!:`)DNAf

Does God believe in people?

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor