Friday 26 September 2014

Security Certificate Fun&Games - or a warning to the wise


Recently there has been a difficulty reaching Google mainly on the XP machine. We keep getting the message about an SSL string too long. I know that I found an indication that TalkTAlk accepts responsibility and is working on it.  

As an attempt to cure the problem as it mostly appeared in Firefox and sometimes in Chrome, I went into Firefox options and deleted a number of Security certificates that looked dodgy, like the one for homeland security, and ones with a tk or ru suffix.

This caused grievous problems as we couldn't get into Facebook, 23snaps, or a number of other sites. I was told this morning that the banking site was unavailable as it didn't have a valid security certificate. During the week some sites have said that the certificate was not there and wouldn't work, and some would let me proceed if I allowed an exception, which I did. I should have kept a record of those.

Today I exported all of the certificates from the Linux computer Firefox, copied those that would on to a memory stick, and started importing them into XP's Firefox. I was able to export the certificates to disk as a single action, but had to import them back in one at a time in a tedious process.
Initially If the first of a named set indicated that it was already installed, I didn't bother with the sub-ones, but later at about the 'c's I realised that the sub-ones sometimes were not present when the main one was, so started being more thorough. I have now installed up to the 'g's, leaving 97 certificates not touched, and it looks like everything is back working. 
I'll keep the certificates on the memory stick for awhile until I am sure. .

Saturday and Amazon gave a certificate warning, so I have put back the rest of the certificates. Of course some were already installed, but I did have to restore some. I had 302 certificates on that memory stick. 

The moral of the story is, don't delete the certificates unless you have taken a backup first, and then only do a few at a time.



No comments: