Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me

The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.

Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old February 23rd, 2006, 09:15 AM
moorehed moorehed is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2004
Posts: 222 moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 9 h 37 m 2 sec
Reputation Power: 17
GoDaddy SSL Problem: not trusted authority in FF?

We normally purchase our SSL certs through verisign or thawte for our customers, but we are trying out goDaddy for this one because they offer a much cheaper alternative:

TurboSSL just $19.95/yr
https://www.godaddy.com/gdshop/ssl/...p?se=%2B&ci=271

granted all they do is domain validation, but this should be sufficient for most of our clients.

Anyways, the installation process was not as troublefree as it has been with other authorities. GoDaddy has a ca_bundle with an intermediate and a root authority certificate that needed to be installed. Eventually I got it to work.

The problem is, when loading up the page in firefox I see:

Unable to verify the identity of praxishosting.com as a trusted site.

Possible reasons for this error:
-Your browser does not recognize the Certificate authority that issued the site's certificate.
-The site's certificate is incomplete due to a server misconfiguration.
-etc.

you can see this yourself here: https://praxishosting.com

Now I have talked with our host's support and with goDaddys support, and the best I can figure out is that the authority that goDaddy uses (Starfield Technologies Inc) is not one of the default trusted authorities for firefox... obviously this is not good for reselling to clients and would make me go back to paying 7x as much through thawte/verisign.

However, I am not really sure this is the problem. It is possible I installed something wrong, but GoDaddy support seems to have no clue. They told me to download the latest version of FF (which I have).

Basically I just want to know if this is always going to happen because GoDaddy goes through a non mainstreem authority, or if I have done something wrong on my end.

sorry for the long windedness of my first post in the Security forum. hopefully someone can help.

Reply With Quote
  #2  
Old February 26th, 2006, 06:46 PM
Eric M Eric M is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2004
Posts: 86 Eric M User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 14 h 48 m 34 sec
Reputation Power: 10
Works fine in firefox for me.

The root cert is only signed in 1999 so any browsers/operating system (eg windows 98) will not have support for that cert.

Reply With Quote
  #3  
Old April 19th, 2006, 08:31 AM
ewhittak ewhittak is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2003
Posts: 3 ewhittak User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 5 m 5 sec
Reputation Power: 0
I have the same prob. is there a solution or is godaddy a nogo for ssl?

Config:
Linux
Apache
cpanel 10
godaddy turbo ssl

Reply With Quote
  #4  
Old April 19th, 2006, 09:22 AM
moorehed moorehed is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2004
Posts: 222 moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 9 h 37 m 2 sec
Reputation Power: 17
I had given up on getting any replies on this.
As far as FireFox, if you have ever told it to trust goDaddy in the past, I think that it is okay. But doesn't come like that on install.

I don't believe there is an answer. I called goDaddy and got some support people that were just "Yes people" and obviously didn't really understand SSL.

Reply With Quote
  #5  
Old April 19th, 2006, 10:02 AM
ewhittak ewhittak is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2003
Posts: 3 ewhittak User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 5 m 5 sec
Reputation Power: 0
There are a lot of other people out there that don't seem to be having trouble with the godaddy certs. I'm still hoping it's a matter of installing them the 'right' way. Looks like it might be better to steer clear of chained certs unless you want to stuff about a bit.

Reply With Quote
  #6  
Old April 19th, 2006, 11:59 AM
moorehed moorehed is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2004
Posts: 222 moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 9 h 37 m 2 sec
Reputation Power: 17
It is possible that I installed it wrong (how would I know?), but I don't think I did. I don't have any issues with the cert in IE, or in FF after choosing to trust Starfield Technologies Inc.

Reply With Quote
  #7  
Old April 21st, 2006, 07:39 PM
TAK's Avatar
TAK TAK is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Location: North America
Posts: 147 TAK User rank is Private First Class (20 - 50 Reputation Level)TAK User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 1 Day 21 h 27 m 50 sec
Reputation Power: 9
Send a message via AIM to TAK Send a message via MSN to TAK
From what I have understood, some of the cheaper certificates do not have as high of a browser recognition rate - however I may be mistaken.

Anyways, take a look at http://www.rapidssl.com/ - You can get their basic certificate through some companies (eg. The Planet) for much cheaper and I have yet to have any problems with it.

Reply With Quote
  #8  
Old April 27th, 2006, 12:59 AM
ninjablademaste ninjablademaste is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2006
Posts: 1 ninjablademaste User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 5 m 53 sec
Reputation Power: 0
Godaddy Difficulty

I purchased the godaddy turbossl certificate and the first browser (firefox 1.5, winXP) that I used to view my site complained about it. That is absolutely unacceptable in an ssl certificate.

In a phone call to godaddy they agreed to revoke the certificate and refund the purchase price. Without cause, my refund was un-refunded by godaddy. I called godaddy again and they said they would give me a refund. I'm still waiting to see what happens with the second refund.

I should also mention that both godaddy representatives claim that I am the first person to report that firefox or any other browser doesn't recognize their certificates. bizarre.

Here's the order of events:
April 22, 6pm - order godaddy turbo ssl certificate
(authentication process pending)
April 22, 7pm - receive email containing my certificate
April 23, 8pm - receive email confirming my cancellation


******************************************************************
ITEM CANCELLATION CONFIRMATION
******************************************************************


Dear xx,

Per your request, the items listed below have been cancelled from your account, xx:

Turbo SSL (1 Year): 04/22/2007. xx.xx.xx

If you feel this cancellation has occurred in error or you need further assistance, our support staff is available 24 hours a day, 7 days a week:

+ Online Support: https://www.godaddy.com/gdshop/support.asp?prog_id=GoDaddy
+ Email: mailto:support@godaddy.com
+ Phone: (480) 505-8877

Thanks again for being a GoDaddy.com customer.

Sincerely,
GoDaddy.com


April 24, 3pm - un-refunded?

***********************************************
REFUND STATUS NOTIFICATION
***********************************************

Dear xx,

We recently received the following refund request:

Order ID Number: xx
Refund Amount: $14.99

Unfortunately, your request has been denied.

Please contact our customer support staff for additional information:

Email: mailto:support@godaddy.com
Phone: (480) 505-8877
Online FAQ: http://help.godaddy.com/?prog_id=GoDaddy

Sincerely,
GoDaddy.com


April 27, 12am - re-refunded?

===========================================================
REFUND CONFIRMATION
===========================================================

Wednesday, April 26, 2006 9:36:28 PM


Dear xx,

GoDaddy.com(R) has received a refund request for the following items:

QTY ITEM PRICE
--------------------------------------------------------------
-1 Turbo SSL (1 Year) $ (14.99)
--------------------------------------------------------------
Subtotal: $ (14.99)
Shipping & Handling: $ 0.00
Tax: $ 0.00
Total: $ (14.99)


Important Information concerning your purchase:

SSL Certificates
Product Info: http://help.godaddy.com/topic_list.php?topic_id=186&prog_id=GoDaddy



I will post again in a few days...

Reply With Quote
  #9  
Old April 27th, 2006, 02:36 AM
pabloj's Avatar
pabloj pabloj is offline
Modding: Oracle MsSQL Firebird
Dev Shed God 8th Plane (8500 - 8999 posts)
 
Join Date: Jun 2001
Location: Outside US
Posts: 8,527 pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level) 
Time spent in forums: 3 Months 1 Week 1 Day 3 h 19 m 49 sec
Reputation Power: 537
ninjablademaste: why not asking goDaddy to make a contribution to Mozilla foundation and asking inclusion of their CA in the trusted list?

Reply With Quote
  #10  
Old April 27th, 2006, 02:38 AM
pabloj's Avatar
pabloj pabloj is offline
Modding: Oracle MsSQL Firebird
Dev Shed God 8th Plane (8500 - 8999 posts)
 
Join Date: Jun 2001
Location: Outside US
Posts: 8,527 pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level)pabloj User rank is Colonel (50000 - 60000 Reputation Level) 
Time spent in forums: 3 Months 1 Week 1 Day 3 h 19 m 49 sec
Reputation Power: 537
A reource for all certificate buyers, Mozilla CA Certificate List Hope it helps

Reply With Quote
  #11  
Old April 27th, 2006, 09:27 AM
moorehed moorehed is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2004
Posts: 222 moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 9 h 37 m 2 sec
Reputation Power: 17
Well, I am glad if nothing else, that other people having this problem are finding this post when searching and know it isn't just them, because I couldn't find anything.

I love how godaddy reps deny things and basically have no idea what they are talking about.
Comments on this post
pabloj agrees: You might even point them to this thread, this should make them afraid of the word of mouth about
the bad experience

Reply With Quote
  #12  
Old April 27th, 2006, 01:36 PM
Gnome101's Avatar
Gnome101 Gnome101 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 322 Gnome101 User rank is Corporal (100 - 500 Reputation Level)Gnome101 User rank is Corporal (100 - 500 Reputation Level)Gnome101 User rank is Corporal (100 - 500 Reputation Level)Gnome101 User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 Days 16 h 37 m 49 sec
Reputation Power: 10
I just talked to the GoDaddy people.

They said that with the browsers, you need to have the intermediate signing certificate installed for the other browsers to not ask the user for acceptance.

He also said there are step by step guides to installing the cert on the web site.

Also, when dealing with the certs, don't call goDaddy, call 480.505.8852 the number should take you to Starfield tech.


Just an FYI.

Reply With Quote
  #13  
Old April 27th, 2006, 01:53 PM
moorehed moorehed is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2004
Posts: 222 moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level)moorehed User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 9 h 37 m 2 sec
Reputation Power: 17
Is there a way to tell for sure if the intermediate is installed correctly? I thought I installed it all correctly, but it is possible I did not.

Thanks for the phone number. I am sure that will prove more useful than the godaddy #.

Reply With Quote
  #14  
Old April 27th, 2006, 02:35 PM
Gnome101's Avatar
Gnome101 Gnome101 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 322 Gnome101 User rank is Corporal (100 - 500 Reputation Level)Gnome101 User rank is Corporal (100 - 500 Reputation Level)Gnome101 User rank is Corporal (100 - 500 Reputation Level)Gnome101 User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 Days 16 h 37 m 49 sec
Reputation Power: 10
I am not sure how the tech I talked to was able to tell, but he knew immediatly.

I would just call.

Reply With Quote
  #15  
Old May 9th, 2006, 03:11 PM
ad2015tokyo3 ad2015tokyo3 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2006
Posts: 1 ad2015tokyo3 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 25 m 9 sec
Reputation Power: 0
i've encountered this on our secure site myself.

figured out what misconfiguration i did on the server, and fixed it. make sure the admin look into installing the secure chain certificate properly on the server.

like on apache:
http://httpd.apache.org/docs/2.0/mod/mod_ssl.html.en#sslcertificatechainfile

the starfield chain certificate is issued by valicert, which is in turn what FF does have.

on the other hand opera, and IE have both valicert, and starfield, so even without configuring the chain certificate on the server, it just works.



opera rox
Comments on this post
raada agrees!

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > GoDaddy SSL Problem: not trusted authority in FF?

Developer Shed Advertisers and Affiliates



Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

© 2003-2013 by Developer Shed. All rights reserved. DS Cluster - Follow our Sitemap