Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What a fuck up. How did that go unnoticed.


It was noticed, but tested across a number of platforms did not show errors except for Android < v3.

The issue is with a weird Mac OS X chain issue that causes a chain to be downloaded to the login keystore in Keychain. Mac forces it to be used when validating the certificate chain. Most users have removed the cert and everything is working as it should.

Tracking down how and why that happens on Mac OS X is tough. Reaching Apple engineers has not been extremely successful. Not Apple's fault. Usually SSL Root Chain groups are distributed with organizations so it's not always clear who to go to.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: