The certificate for download1.dd-wrt.com expired on8/20/2023

Post new topic   This topic is locked: you cannot edit posts or make replies.    DD-WRT Forum Index -> General Questions
Goto page Previous  1, 2
Author Message
inetquestion
DD-WRT User


Joined: 24 Sep 2015
Posts: 67

PostPosted: Thu Aug 24, 2023 12:16    Post subject: Reply with quote
Certificates are hard.

Upload your webserver logs, certs and keys, and we can debug it. :P
Sponsor
Patty
DD-WRT Novice


Joined: 23 Aug 2023
Posts: 3

PostPosted: Thu Aug 24, 2023 13:02    Post subject: Reply with quote
kris18890 wrote:
I've found that https://ftp.dd-wrt.com works, ish... It still gives a cert expired error, but you can add an exception for it as it's not using HSTS, whereas https://download1.dd-wrt.com is using HSTS, so no way to override

So instead of

https://download1.dd-wrt.com/dd-wrtv2/downloads/betas/2023/

use

https://ftp.dd-wrt.com/dd-wrtv2/downloads/betas/2023/


Unfortunetly doesn't work with Brave on Linux Minst 21.2 Cinnamon. Both these url's result in the same error (See attached image):

https://download1.dd-wrt.com/dd-wrtv2/downloads/betas/2023/[/quote]

https://ftp.dd-wrt.com/dd-wrtv2/downloads/betas/2023/[/quote]

We can still download btw, but this error always occurs.



2023-08-24_07-58.png
 Description:
Brave/Chromium Error Example
 Filesize:  53.9 KB
 Viewed:  2216 Time(s)

2023-08-24_07-58.png


Patty
DD-WRT Novice


Joined: 23 Aug 2023
Posts: 3

PostPosted: Thu Aug 24, 2023 13:09    Post subject: Reply with quote
Patty wrote:
kris18890 wrote:
I've found that https://ftp.dd-wrt.com works, ish... It still gives a cert expired error, but you can add an exception for it as it's not using HSTS, whereas https://download1.dd-wrt.com is using HSTS, so no way to override

So instead of

https://download1.dd-wrt.com/dd-wrtv2/downloads/betas/2023/

use

https://ftp.dd-wrt.com/dd-wrtv2/downloads/betas/2023/


Unfortunetly doesn't work with Brave on Linux Minst 21.2 Cinnamon. Both these url's result in the same error (See attached image):

https://download1.dd-wrt.com/dd-wrtv2/downloads/betas/2023/[...]

https://ftp.dd-wrt.com/dd-wrtv2/downloads/betas/2023/[...]

We can still download btw, but this error always occurs.


I say that, but downloads started working without the error all of a sudden. Unknown if the "Proceed Anyway" choice was remembered or if it's working as expected. Regardless, its been downloading over https the entire time.
itwontbewe
DD-WRT User


Joined: 29 Sep 2020
Posts: 260
Location: United States

PostPosted: Thu Aug 24, 2023 13:25    Post subject: Reply with quote
when you proceeded anyway it sets an exemption for the site

you have to manually remove the exemption

the cert is still expired
kris18890
DD-WRT Novice


Joined: 06 Oct 2011
Posts: 29
Location: Belfast, Ireland

PostPosted: Thu Aug 24, 2023 14:11    Post subject: Reply with quote
itwontbewe wrote:
when you proceeded anyway it sets an exemption for the site

you have to manually remove the exemption

the cert is still expired


Looks like https://download1.dd-wrt.com & https://ftp.dd-wrt.com use the same cert, but download1 has HSTS configured, which prohibits setting an exemption, ftp doesn't, which means an exemption can be set, but correct & agreed, it would need to be removed manually after, generally not a good thing to leave in place long term!

forun.dd-wrt.com, reg.dd-wrt.com, wiki.dd-wrt.com, support.dd-wrt.com, & shoparchiv.dd-wrt.com all share a cert too that's valid from 2023-08-08 to 2023-11-06, haven't checked if they're using HSTS, H2, TLS 1.3 etc

_________________
All the best,

Chris Cool

My DD-WRT Routers:
Linksys/Marvell WRT1900ACSv2 - bitchbox (gateway) (r55678 - daily use)
Linksys/Marvell WRT1900ACSv1 - hackybox (gateway) (r53633 - daily use)
Linksys/Marvell WRT1900ACSv1 - shelleybox (AP only) (r53633 - daily use)
Linksys/Marvell WRT1900ACSv1 - cookiejar (gateway) (r55678 - daily use)
Linksys/Marvell WRT1900ACv1 - coffeejar (AP only) (r55678 - daily use)
Linksys/Marvell WRT1900ACv1 - teajar (AP only) (r55678 - daily use)
Linksys/Broadcom E3000 - switchbox (gateway) (r55678 - not in use/in storage)
bushant
DD-WRT Guru


Joined: 18 Nov 2015
Posts: 2038

PostPosted: Thu Aug 24, 2023 14:47    Post subject: Reply with quote
egc wrote:
The problem should be resolved please clear browser cache (CTRL+F5)


I too was presented with the HSTS crap and could not proceed. First time for this.
After clearing cache (ctrl+f5) I got the option to "proceed anyway" and all is well.

Listen to @egc.
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 3006
Location: Germany

PostPosted: Thu Aug 24, 2023 17:09    Post subject: Reply with quote
the invalid certificate is still used for the download URLs.... so nothing was solved at all and there is no reason to spam the thread.

The certificate was often invalid in the past and I'm pretty sure that the admins have already been informed by email and know how to renew the certificate and fix the problem.

Rolling Eyes Rolling Eyes

_________________
Quickstart guides:
use Pi-Hole as simple DNS-Server with DD-WRT
VLAN configuration via GUI - 1 CPU port
VLAN configuration via GUI - 2 CPU ports (R7800, EA8500 etc)

Routers
Marvell OCTEON TX2 - QHora-322 - OpenWrt 23.05.3 - Gateway
Qualcomm IPQ8065 - R7800 - DD-WRT - WAP
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1959

PostPosted: Thu Aug 24, 2023 18:14    Post subject: Reply with quote
inetquestion wrote:
Certificates are hard.

Upload your webserver logs, certs and keys, and we can debug it. Razz

Coming from you, this is highly ironic <lol>

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
itwontbewe
DD-WRT User


Joined: 29 Sep 2020
Posts: 260
Location: United States

PostPosted: Tue Aug 29, 2023 14:04    Post subject: Reply with quote
it's been updated
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1959

PostPosted: Tue Aug 29, 2023 16:02    Post subject: Reply with quote



_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
mwchang
DD-WRT Guru


Joined: 26 Mar 2013
Posts: 1858
Location: Hung Hom, Hong Kong

PostPosted: Wed Aug 30, 2023 6:11    Post subject: Reply with quote
itwontbewe wrote:
it's been updated

Affirmative!!

See you all on Nov 27? Or maybe 3 Oct?? 9 Oct??? Smile

Code:

# echo | openssl s_client -connect download1.dd-wrt.com:443 2> /dev/null | openssl x509 -noout -issuer -su
bject -dates
issuer=C = US, O = Let's Encrypt, CN = R3
subject=CN = download1.dd-wrt.com
notBefore=Aug 29 11:22:39 2023 GMT
notAfter=Nov 27 11:22:38 2023 GMT

# echo | openssl s_client -connect dd-wrt.com:443 2> /dev/null | openssl x509 -noout -issuer -subject -dat
es
issuer=C = US, O = Let's Encrypt, CN = R3
subject=CN = dd-wrt.com
notBefore=Jul  5 12:53:43 2023 GMT
notAfter=Oct  3 12:53:42 2023 GMT

# echo | openssl s_client -connect svn.dd-wrt.com:443 2> /dev/null | openssl x509 -noout -issuer -subject
-dates
issuer=C = US, O = Let's Encrypt, CN = R3
subject=CN = svn.dd-wrt.com
notBefore=Jul 11 19:03:16 2023 GMT
notAfter=Oct  9 19:03:15 2023 GMT



Related:

DD-WRT :: View topic - New Build - 08/21/2023 - r53396
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=335000&start=4

DD-WRT :: View topic - Unable To Download New Builds Because Website Cert. Exp.
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=335040

_________________
Router: Asus RT-N18U (rev. A1)

Drink, Blink, Stretch! Live long and prosper! May the Force and farces be with you!

Facebook: https://www.facebook.com/changmanwai
Website: https://sites.google.com/site/changmw
SETI@Home profile: http://setiathome.berkeley.edu/view_profile.php?userid=211832
GitHub: https://github.com/changmw/changmw
Goto page Previous  1, 2 Display posts from previous:    Page 2 of 2
Post new topic   This topic is locked: you cannot edit posts or make replies.    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum