mailGna security issue


Others Months | Index by Date | Thread Index
>>   [Date Prev] [Date Next] [Thread Prev] [Thread Next]

Header


Content

Posted by Sébastien Morin on November 24, 2010 - 16:02:
Hi,

Thanks to Fred Damberger, I just recalled observing a security-related issue with the Gna website.

Here is the message Firefox gives when trying to login on Gna:

========
This Connection is Untrusted

You have asked Firefox to connect
securely to gna.org, but we can't confirm that your connection is secure.

Normally, when you try to connect securely,
sites will present trusted identification to prove that you are
going to the right place. However, this site's identity can't be verified.

What Should I Do?

If you usually connect to
this site without problems, this error could mean that someone is
trying to impersonate the site, and you shouldn't continue.

Technical Details

gna.org uses an invalid security certificate.

The certificate is not trusted because the issuer certificate is unknown.

(Error code: sec_error_unknown_issuer)

I Understand the Risks

If you understand what's going on, you
can tell Firefox to start trusting this site's identification.
Even if you trust the site, this error could mean that someone is
tampering with your connection.

Don't add an exception unless
you know there's a good reason why this site doesn't use trusted identification.
========

Is this important ?
Should this be fixed by the Gna people ?

Cheers,


Séb  :)

--
Sébastien Morin, Ph.D.
Postdoctoral fellow
S. Grzesiek NMR Laboratory
Biozentrum, Universität Basel
Basel, Switzerland




Related Messages


Powered by MHonArc, Updated Tue Nov 30 08:20:15 2010