📜 ⬆️ ⬇️

The IP address of the Digicert certification center is entered in the registry of prohibited sites

On September 29, Roskomnadzor, following the decision of the Oktyabrsky District Court of Stavropol of 2013, entered the IP address 93.184.220.29 into the register of prohibited sites. This court decision obliges to block websites and mobile applications of some bookmakers, and if everything is obvious with website blocking, then, most likely, experts of the Stavropol Prosecutor’s Office (the claim was filed on their behalf) were limited for the first time, and just declared all the IP addresses that the application accessed at launch, including the CRL (certificate revocation list) addresses and the OCSP servers (certificate status checking server) of global certification prices used for HTTPS encryption.

Screenshot of eais.rkn.gov.ru

This decision of the court became known due to blocking links to Comodo CRL files in July of this year ( “Roskomnadzor blocked himself and some government sites (Comodo)” from BupycNet ), now the address belonging to another certifying center, Digicert, is entered in the register.
$ host crl3.digicert.com crl3.digicert.com is an alias for cs9.wac.phicdn.net. cs9.wac.phicdn.net has address 93.184.220.29 $ host ocsp.digicert.com ocsp.digicert.com is an alias for cs9.wac.phicdn.net. cs9.wac.phicdn.net has address 93.184.220.29 
So, when you try to open sites that use Digicert certificates in Firefox and Chrome, you will encounter a 3 or 10 second delay due to the inability to check the status of the certificate, or even see an error in browsers that do not allow you to open the site in case of problems checking the certificate on revocation (Safari on OS X).
')
The author and commentators of the website shortcut.ru in the article “Why Facebook isn’t working on Mac”? They note the inoperability of Facebook.com and Github.com in Safari since October 3 and suggest disabling feedback checking in the OS settings.
 X509v3 Subject Alternative Name: DNS:*.facebook.com, DNS:*.facebook.net, DNS:*.fb.com, DNS:*.fbcdn.net, DNS:*.fbsbx.com, DNS:*.m.facebook.com, DNS:*.messenger.com, DNS:*.xx.fbcdn.net, DNS:*.xy.fbcdn.net, DNS:*.xz.fbcdn.net, DNS:facebook.com, DNS:fb.com, DNS:messenger.com X509v3 CRL Distribution Points: Full Name: URI:http://crl3.digicert.com/sha2-ha-server-g5.crl Full Name: URI:http://crl4.digicert.com/sha2-ha-server-g5.crl 

Registry entry on Roskomsvoboda website

UPD: IP is excluded from the registry 10.10.2016.

Source: https://habr.com/ru/post/357196/


All Articles