Page MenuHomePhabricator

SSL cert invalid for bugzilla.wikipedia.org redirect
Closed, ResolvedPublic

Description

Various old links to https://bugzilla.wikipedia.org are currently showing an SSL cert error:

You attempted to reach bugzilla.wikipedia.org, but instead you
actually reached a server identifying itself as *.wikimedia.org.
This may be caused by a misconfiguration on the server or by something
more serious. An attacker on your network could be trying to get you
to visit a fake (and potentially harmful) version of
bugzilla.wikipedia.org. You should not proceed.

Note that https://bugs.mediawiki.org does not show an SSL error


Version: unspecified
Severity: normal

Details

Reference
bz35313

Event Timeline

bzimport raised the priority of this task from to Low.Nov 22 2014, 12:14 AM
bzimport added a project: HTTPS.
bzimport set Reference to bz35313.
bzimport added a subscriber: Unknown Object (MLST).

(In reply to comment #0)

Note that https://bugs.mediawiki.org does not show an SSL error

Both https://bugs.mediawiki.org and https://bugzilla.mediawiki.org are redirecting via SSL without SSL errors.

I claim it's fixed now by:

https://gerrit.wikimedia.org/r/#/c/112930/

21:02 mutante: DNS update - switch bz.wp to cluster redirect

please confirm ?:)

openssl s_client -connect bugzilla.wikipedia.org:443

...
subject=/C=US/ST=California/L=San Francisco/O=Wikimedia Foundation, Inc./CN=*.wikipedia.org
issuer=/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance CA-3
...

curl bugzilla.wikipedia.org

<title>301 Moved Permanently</title>

<p>The document has moved <a href="https://bugzilla.wikimedia.org/">here</a>.</p>