Author

Topic: GLBSE certificate mismatch on static.glbse.com (Read 1799 times)

hero member
Activity: 504
Merit: 500
Hey jothan,

we've just turned on cloudflare for GLBSE, there are some issues with the SSL cerfiticates at the moment which is something we have to wait for cloudflare to fix.

In the meantime it's safe to login to glbse.com

it won't let me log in...
full member
Activity: 184
Merit: 100
Feel the coffee, be the coffee.
Ok, thanks.

Looks like you are using a new wildcard certificate, nice !
hero member
Activity: 602
Merit: 513
GLBSE Support [email protected]
Hey jothan,

we've just turned on cloudflare for GLBSE, there are some issues with the SSL cerfiticates at the moment which is something we have to wait for cloudflare to fix.

In the meantime it's safe to login to glbse.com
full member
Activity: 184
Merit: 100
Feel the coffee, be the coffee.
The CSS and javascript went away for me on GLBSE. Looking with the Chrome webpage debugger, I see that the requests for the CSS and JS are hosted on an ip with a certificate mismatch. The faulty URLs start with https://static.glbse.com/.

This means anyone with a sane browser will be missing all the AJAX stuff necessary to buy and sell securities.

nefario, can you advise ?

Edit: I am now getting an SSL error on https://glbse.com/ too ! Ignoring the warning seems to work, but I would rather not risk logging in.
Edit 2: I flushed my DNS caches and everything seems ok now when using https://www.glbse.com/.

Certificate chain:

gnutls-cli static.glbse.com --port 443
Resolving 'static.glbse.com'...
Connecting to '199.27.135.223:443'...
- Session ID: 56:E7:21:F1:7C:37:AF:BA:E7:F5:32:FB:D0:3C:60:29:E5:C2:12:7C:6D:AB:EE:1A:AB:AA:B9:A5:E1:6C:52:EA
- Certificate type: X.509
 - Got a certificate list of 2 certificates.
 - Certificate[0] info:
  - subject `C=US,ST=CA,L=San Francisco,O=CloudFlare\, Inc.,CN=ssl2402.cloudflare.com', issuer `C=BE,O=GlobalSign nv-sa,CN=GlobalSign Organization Validation CA - G2', RSA key 2048 bits, signed using RSA-SHA1, activated `2012-05-14 11:39:11 UTC', expires `2016-10-05 15:04:02 UTC', SHA-1 fingerprint `732863bc659c2c06707e66c4ff573e2bfdcbb1fc'
 - Certificate[1] info:
  - subject `C=BE,O=GlobalSign nv-sa,CN=GlobalSign Organization Validation CA - G2', issuer `C=BE,O=GlobalSign nv-sa,OU=Root CA,CN=GlobalSign Root CA', RSA key 2048 bits, signed using RSA-SHA1, activated `2011-04-13 10:00:00 UTC', expires `2022-04-13 10:00:00 UTC', SHA-1 fingerprint `b9ee85a10fd495d994ed63488ab74a18cb8e6bfa'
- The hostname in the certificate does NOT match 'static.glbse.com'

Jump to: