<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Why ssl_error_bad_cert_domain is bad</title>
	<atom:link href="http://www.sslfail.com/2009/01/why-ssl_error_bad_cert_domain-is-bad/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sslfail.com/2009/01/why-ssl_error_bad_cert_domain-is-bad/</link>
	<description>1.2.840.113549.1.1</description>
	<lastBuildDate>Thu, 01 Jul 2010 03:13:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Sérgio Carvalho</title>
		<link>http://www.sslfail.com/2009/01/why-ssl_error_bad_cert_domain-is-bad/comment-page-1/#comment-4173</link>
		<dc:creator>Sérgio Carvalho</dc:creator>
		<pubDate>Fri, 25 Sep 2009 09:49:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=174#comment-4173</guid>
		<description>Hello, 

I have two sites with certificates in my IIS, but my problem is that the 
second site when opened in browser give certificate error and show the 
certificate of the first site. 

When I view certificate in properties of the site in IIS, show the correct 
certificate. 

what is the problem ? 

you can view the problem accessing https://www.prevoironline.pt</description>
		<content:encoded><![CDATA[<p>Hello, </p>
<p>I have two sites with certificates in my IIS, but my problem is that the<br />
second site when opened in browser give certificate error and show the<br />
certificate of the first site. </p>
<p>When I view certificate in properties of the site in IIS, show the correct<br />
certificate. </p>
<p>what is the problem ? </p>
<p>you can view the problem accessing <a href="https://www.prevoironline.pt" rel="nofollow">https://www.prevoironline.pt</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Dickey</title>
		<link>http://www.sslfail.com/2009/01/why-ssl_error_bad_cert_domain-is-bad/comment-page-1/#comment-14</link>
		<dc:creator>Michael Dickey</dc:creator>
		<pubDate>Thu, 15 Jan 2009 20:04:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=174#comment-14</guid>
		<description>Yeah, I&#039;m disappointed in how IE uses newer certs like EV SSL. Well, ok, I&#039;m disappointed only because it takes more effort to support that pretty green bar in IE than it does in Firefox. 

I notied that akamai thing too, and I consider that bad, just like you do. Seriously, the name sounds Chinese, and they&#039;re causing an error in my browser. Hackers, hackers!

You&#039;re absolutely right, although I&#039;d word it that there are three parts to SSL:
1. technical (encyption)
2. verification (technical/CA trust?)
3. user trust/perception

The first part is easy, really. The second part is more robust these days, but still pretty much on the heads of the CAs to get it right. The third part is touchy. I&#039;m not a huge fan of user education to solve this because I don&#039;t know how to teach my parents right now, since this whole issue is a mess. I think sites need to get it right on the technical level, which can be more difficult than it looks at first. :(</description>
		<content:encoded><![CDATA[<p>Yeah, I&#8217;m disappointed in how IE uses newer certs like EV SSL. Well, ok, I&#8217;m disappointed only because it takes more effort to support that pretty green bar in IE than it does in Firefox. </p>
<p>I notied that akamai thing too, and I consider that bad, just like you do. Seriously, the name sounds Chinese, and they&#8217;re causing an error in my browser. Hackers, hackers!</p>
<p>You&#8217;re absolutely right, although I&#8217;d word it that there are three parts to SSL:<br />
1. technical (encyption)<br />
2. verification (technical/CA trust?)<br />
3. user trust/perception</p>
<p>The first part is easy, really. The second part is more robust these days, but still pretty much on the heads of the CAs to get it right. The third part is touchy. I&#8217;m not a huge fan of user education to solve this because I don&#8217;t know how to teach my parents right now, since this whole issue is a mess. I think sites need to get it right on the technical level, which can be more difficult than it looks at first. <img src='http://www.sslfail.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jgraver</title>
		<link>http://www.sslfail.com/2009/01/why-ssl_error_bad_cert_domain-is-bad/comment-page-1/#comment-13</link>
		<dc:creator>jgraver</dc:creator>
		<pubDate>Wed, 14 Jan 2009 22:37:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=174#comment-13</guid>
		<description>SSL has helped the Web become what it is today (think eCommerce and online banking). From the user perspective any misconfiguration in SSL that causes a warning / popup will cause them to question the site&#039;s security.

SSL might be encryption and authentication but from the perspective of a user on the other end of the browser, SSL is trust. Users don&#039;t really know / care what these different errors are. They are bad and look suspicious to the untrained eye.

We will post more on the issue of trust in SSL.</description>
		<content:encoded><![CDATA[<p>SSL has helped the Web become what it is today (think eCommerce and online banking). From the user perspective any misconfiguration in SSL that causes a warning / popup will cause them to question the site&#8217;s security.</p>
<p>SSL might be encryption and authentication but from the perspective of a user on the other end of the browser, SSL is trust. Users don&#8217;t really know / care what these different errors are. They are bad and look suspicious to the untrained eye.</p>
<p>We will post more on the issue of trust in SSL.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
