The certificate for download1.dd-wrt.com expired on8/20/2023

Post new topic   This topic is locked: you cannot edit posts or make replies.    DD-WRT Forum Index -> General Questions
Goto page 1, 2  Next
Author Message
r7000-2
DD-WRT User


Joined: 23 May 2022
Posts: 61

PostPosted: Sun Aug 20, 2023 13:02    Post subject: The certificate for download1.dd-wrt.com expired on8/20/2023 Reply with quote
It looks like let's encrypt certificate for download1.dd-wrt.com has been expired.

Please PM me if you need advice on automatically renewing those as well as DNS valid card certificates and EC Keys

_________________
Several NetGears with Broadcom and with Atheros
Mode: RIP2 Router, 2G/5G radios are active, Routed WiFi multiple SSID's/separated by IP subnets.
Remote Syslog, NTP, IPv6 management, WireGuard routed Site-2-Site VPNs
Sponsor
inetquestion
DD-WRT User


Joined: 24 Sep 2015
Posts: 67

PostPosted: Sun Aug 20, 2023 13:49    Post subject: Reply with quote
It was valid for ~4 months... Kinda odd.
r7000-2
DD-WRT User


Joined: 23 May 2022
Posts: 61

PostPosted: Sun Aug 20, 2023 13:52    Post subject: Reply with quote
inetquestion wrote:
It was valid for ~4 months... Kinda odd.



That's fine for Let's encrypt certificates. They do encourage frequent renewals/automation.

_________________
Several NetGears with Broadcom and with Atheros
Mode: RIP2 Router, 2G/5G radios are active, Routed WiFi multiple SSID's/separated by IP subnets.
Remote Syslog, NTP, IPv6 management, WireGuard routed Site-2-Site VPNs
mwchang
DD-WRT Guru


Joined: 26 Mar 2013
Posts: 1858
Location: Hung Hom, Hong Kong

PostPosted: Sun Aug 20, 2023 17:57    Post subject: Re: The certificate for download1.dd-wrt.com expired on8/20/ Reply with quote
r7000-2 wrote:
It looks like let's encrypt certificate for download1.dd-wrt.com has been expired.

Testing... Smile
Code:

# echo | openssl s_client -connect  download1.dd-wrt.com:443 2> /dev/null | openssl x509 -noou
t -issuer -subject -dates
issuer=C = US, O = Let's Encrypt, CN = R3
subject=CN = download1.dd-wrt.com
notBefore=May 22 11:10:56 2023 GMT
notAfter=Aug 20 11:10:55 2023 GMT
# openssl s_client -connect forum.dd-wrt.com:443 2>/dev/null </dev/null | openssl x509 -noout
-dates
notBefore=Aug  8 01:47:21 2023 GMT
notAfter=Nov  6 01:47:20 2023 GMT

Quote:
Please PM me if you need advice on automatically renewing those as well as DNS valid card certificates and EC Keys

A reminder might be sufficient. Or just mark the calendar.


Previous post about this:

DD-WRT :: View topic - download1.dd-wrt.com certificate expired
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=334584

_________________
Router: Asus RT-N18U (rev. A1)

Drink, Blink, Stretch! Live long and prosper! May the Force and farces be with you!

Facebook: https://www.facebook.com/changmanwai
Website: https://sites.google.com/site/changmw
SETI@Home profile: http://setiathome.berkeley.edu/view_profile.php?userid=211832
GitHub: https://github.com/changmw/changmw
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14249
Location: Texas, USA

PostPosted: Mon Aug 21, 2023 0:59    Post subject: Reply with quote
Danger, Will Robinson! Alert the media! The sky is falling! Rolling Eyes I'll add to the email clutter that is surely already in Sir BrainSlayer's inbox.
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
mwchang
DD-WRT Guru


Joined: 26 Mar 2013
Posts: 1858
Location: Hung Hom, Hong Kong

PostPosted: Tue Aug 22, 2023 13:53    Post subject: Reply with quote
kernel-panic69 wrote:
Danger, Will Robinson! Alert the media! The sky is falling! Rolling Eyes I'll add to the email clutter that is surely already in Sir BrainSlayer's inbox.

https://download1.dd-wrt.coms is still waiting for the certifeicate:

https://download1.dd-wrt.com/dd-wrtv2/downloads/betas/2023/08-21-2023-r53396/

BTW, if you were using Let's Encrypt certificates, an expiratioin email would be sent to you. I dunno about ZeroSSL.
Code:

From: Let's Encrypt Expiry Bot <expiry@letsencrypt.org>
Subject: Let's Encrypt certificate expiration notice for domain "xxx.xxx.xxx"

Your certificate (or certificates) for the names listed below will expire in 7 days (on 2023-mm-dd). Please make sure to renew your certificate before then, or visitors to your web site will encounter errors.

We recommend renewing certificates automatically when they have a third of their total lifetime left. For Let's Encrypt's current 90-day certificates, that means renewing 30 days before expiration. See https://letsencrypt.org/docs/integration-guide/ for details.

_________________
Router: Asus RT-N18U (rev. A1)

Drink, Blink, Stretch! Live long and prosper! May the Force and farces be with you!

Facebook: https://www.facebook.com/changmanwai
Website: https://sites.google.com/site/changmw
SETI@Home profile: http://setiathome.berkeley.edu/view_profile.php?userid=211832
GitHub: https://github.com/changmw/changmw
moribund
DD-WRT Novice


Joined: 21 Aug 2023
Posts: 13
Location: London

PostPosted: Wed Aug 23, 2023 12:59    Post subject: Reply with quote
Still happening to me
I am thinking of changing my browser
To one that dont give a tinkers cuss about certificates
any recommendations?
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12923
Location: Netherlands

PostPosted: Wed Aug 23, 2023 13:01    Post subject: Reply with quote
moribund wrote:
Still happening to me
I am thinking of changing my browser
To one that dont give a tinkers cuss about certificates
any recommendations?


The problem should be resolved please clear browser cache (CTRL+F5)

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087


Last edited by egc on Wed Aug 23, 2023 13:24; edited 1 time in total
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 3006
Location: Germany

PostPosted: Wed Aug 23, 2023 13:13    Post subject: Reply with quote
Is still the old expired certificate
_________________
Quickstart guides:
use Pi-Hole as simple DNS-Server with DD-WRT
VLAN configuration via GUI - 1 CPU port
VLAN configuration via GUI - 2 CPU ports (R7800, EA8500 etc)

Routers
Marvell OCTEON TX2 - QHora-322 - OpenWrt 23.05.3 - Gateway
Qualcomm IPQ8065 - R7800 - DD-WRT - WAP
Patty
DD-WRT Novice


Joined: 23 Aug 2023
Posts: 3

PostPosted: Wed Aug 23, 2023 15:20    Post subject: Reply with quote
Same here. NET::ERR_CERT_DATE_INVALID
Gameman Advanced Kid
DD-WRT Guru


Joined: 18 Nov 2012
Posts: 1158

PostPosted: Wed Aug 23, 2023 16:11    Post subject: Reply with quote
I am able to download the files just fine via file zilla.
_________________
For people who are new to the dd-wrt forums >> http://www.catb.org/~esr/faqs/smart-questions.html#rtfm

barryware wrote:
It takes a "community" to raise a router..


Internet Connection 1
Some Techicolor modem > Linksys WRT3200ACM

Internet connection 2
Ubiquiti Powerbeam Gen 2 > Netgear R9000

Official (but not really) dd-wrt General Discussion element/matrix chat

https://matrix.to/#/#dd-wrt-private-non-offical:matrix.org
yoyoma2
DD-WRT User


Joined: 24 Sep 2016
Posts: 373

PostPosted: Wed Aug 23, 2023 23:01    Post subject: Reply with quote
egc wrote:
The problem should be resolved please clear browser cache (CTRL+F5)

Is it fixed? Both links in the mwchang post two posts before yours give me errors in bing (a browser I never use so nothing is cached). The first link should end with .com not .coms .
kris18890
DD-WRT Novice


Joined: 06 Oct 2011
Posts: 29
Location: Belfast, Ireland

PostPosted: Thu Aug 24, 2023 0:38    Post subject: Reply with quote
I've found that https://ftp.dd-wrt.com works, ish... It still gives a cert expired error, but you can add an exception for it as it's not using HSTS, whereas https://download1.dd-wrt.com is using HSTS, so no way to override

So instead of

https://download1.dd-wrt.com/dd-wrtv2/downloads/betas/2023/

use

https://ftp.dd-wrt.com/dd-wrtv2/downloads/betas/2023/

_________________
All the best,

Chris Cool

My DD-WRT Routers:
Linksys/Marvell WRT1900ACSv2 - bitchbox (gateway) (r55678 - daily use)
Linksys/Marvell WRT1900ACSv1 - hackybox (gateway) (r53633 - daily use)
Linksys/Marvell WRT1900ACSv1 - shelleybox (AP only) (r53633 - daily use)
Linksys/Marvell WRT1900ACSv1 - cookiejar (gateway) (r55678 - daily use)
Linksys/Marvell WRT1900ACv1 - coffeejar (AP only) (r55678 - daily use)
Linksys/Marvell WRT1900ACv1 - teajar (AP only) (r55678 - daily use)
Linksys/Broadcom E3000 - switchbox (gateway) (r55678 - not in use/in storage)
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1959

PostPosted: Thu Aug 24, 2023 3:09    Post subject: Reply with quote
Depends on browser used, among other things (?). Epic doesn't balk on either so much. Chrome 116.0.5845.111, same. Edge, same. Firefox ESR and Quantum, same. Only SRWare Iron (on Linux, which is 113.x.x.x) is the one acting funny for us here. Windows version (115.0.5850.0) doesn't seem to be doing it at the moment.
_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
mwchang
DD-WRT Guru


Joined: 26 Mar 2013
Posts: 1858
Location: Hung Hom, Hong Kong

PostPosted: Thu Aug 24, 2023 6:54    Post subject: Reply with quote
kris18890 wrote:
I've found that https://ftp.dd-wrt.com works, ish... It still gives a cert expired error, but you can add an exception for it as it's not using HSTS, whereas https://download1.dd-wrt.com is using HSTS, so no way to override

Better change the download links of future build notices to reflect this??

If the certificate was for "dd-wrt.com", why did "https://ftp.dd-wrt.com" work but not "https://download1.dd-wrt.com"? Were they using different certs?
Code:
# echo | openssl s_client -connect download1.dd-wrt.com:443 2> /dev/null | openssl x509 -noout -issuer -su
bject -dates
issuer=C = US, O = Let's Encrypt, CN = R3
subject=CN = download1.dd-wrt.com
notBefore=May 22 11:10:56 2023 GMT
notAfter=Aug 20 11:10:55 2023 GMT
# echo | openssl s_client -connect ftp.dd-wrt.com:443 2> /dev/null | openssl x509 -noout -issuer -subject
-dates
issuer=C = US, O = Let's Encrypt, CN = R3
subject=CN = download1.dd-wrt.com
notBefore=May 22 11:10:56 2023 GMT
notAfter=Aug 20 11:10:55 2023 GMT
# echo | openssl s_client -connect www.dd-wrt.com:443 2> /dev/null | openssl x509 -noout -issuer -subject
-dates
issuer=C = US, O = Let's Encrypt, CN = R3
subject=CN = dd-wrt.com
notBefore=Jul  5 12:53:43 2023 GMT
notAfter=Oct  3 12:53:42 2023 GMT
# echo | openssl s_client -connect dd-wrt.com:443 2> /dev/null | openssl x509 -noout -issuer -subject -dat
es
issuer=C = US, O = Let's Encrypt, CN = R3
subject=CN = dd-wrt.com
notBefore=Jul  5 12:53:43 2023 GMT
notAfter=Oct  3 12:53:42 2023 GMT

_________________
Router: Asus RT-N18U (rev. A1)

Drink, Blink, Stretch! Live long and prosper! May the Force and farces be with you!

Facebook: https://www.facebook.com/changmanwai
Website: https://sites.google.com/site/changmw
SETI@Home profile: http://setiathome.berkeley.edu/view_profile.php?userid=211832
GitHub: https://github.com/changmw/changmw
Goto page 1, 2  Next Display posts from previous:    Page 1 of 2
Post new topic   This topic is locked: you cannot edit posts or make replies.    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum