{"id":8280,"date":"2019-01-11T13:12:21","date_gmt":"2019-01-11T18:12:21","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=8280"},"modified":"2023-04-10T10:14:27","modified_gmt":"2023-04-10T14:14:27","slug":"80-gov-ssl-tls-certificates-have-expired-during-the-shutdown","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/80-gov-ssl-tls-certificates-have-expired-during-the-shutdown\/","title":{"rendered":"80+ .gov SSL\/TLS Certificates have expired during the shutdown"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-the-government-shutdown-continues-and-more-and-more-sites-are-going-down\">The government shutdown continues, and more and more sites are going down.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Right now dozens of US government websites are unreachable\nas a result of certificate expirations during the shutdown. This has affected\nagencies like NASA, the US Department of Justice and the Court of Appeals and\ninclude government payment portals and remote access services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">More than 80 SSL\/TLS certificates have expired over the 21+\ndays this shutdown has gone on for, and that is only exacerbated by the fact\nsome of these websites are on the HSTS preload list, which makes them unreachable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, today we\u2019re going to talk about certificate expiry and the\ndouble-edged sword that is the HSTS preload list.<\/p>\n\n\n\n<p>Let\u2019s hash it out.<\/p><span id=\"newline\"><\/span>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-this-is-what-happens-when-your-ssl-tls-certificate-expires\">This is what happens when your SSL\/TLS certificate expires<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We talk all the time about <a href=\"https:\/\/www.thesslstore.com\/blog\/what-happens-when-your-ssl-certificate-expires\/\">what happens when your SSL\/TLS certificate expires<\/a>. We toss out high profile examples like <a href=\"https:\/\/www.thesslstore.com\/blog\/expired-certificate-ericsson-o2\/\">Ericsson<\/a>, <a href=\"https:\/\/www.thesslstore.com\/blog\/the-equifax-data-breach-went-undetected-for-76-days-because-of-an-expired-certificate\/\">Equifax<\/a>, <a href=\"https:\/\/www.thesslstore.com\/blog\/linkedin-ssl-certificate-expired\/\">LinkedIn<\/a>, <a href=\"https:\/\/www.thesslstore.com\/blog\/expired-ssl-certificate-in-cisco-vpn-kit-breaks-network-provisioning\/\">Cisco<\/a>\u2014you name it. Most of those cases were a result of negligence or oversight. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This, however, is a direct result of the current US government shutdown.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We already talked, earlier this week, about <a href=\"https:\/\/www.thesslstore.com\/blog\/the-government-shutdown-is-catastrophic-for-us-cybersecurity\/\">how catastrophic this shutdown was going to be to the US Cybersecurity apparatus long-term<\/a>. That\u2019s because, much like the 2013 shutdown did with the NSA, this is going to dissuade the best and the brightest from taking a government job instead of heading to the far more lucrative private sector.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But, there are still some employees that have stayed on to handle the \u201cessential\u201d functions required for cyber defense. Apparently, certificate management was not considered an essential function, which is why \u2013 <a href=\"https:\/\/news.netcraft.com\/archives\/2019\/01\/10\/gov-security-falters-during-u-s-shutdown.html\">according to Netcraft<\/a> \u2013 over 80 SSL\/TLS certificates have expired since the shutdown.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8230;the hundreds of thousands of unpaid federal employees might not be the only ones hurting. As more and more certificates used by government websites inevitably expire over the following days, weeks \u2014 or maybe even months \u2014 there could be some <g class=\"gr_ gr_4 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling\" id=\"4\" data-gr-id=\"4\">realistic<\/g> opportunities to undermine the security of all U.S. citizens.<\/p>\n<cite><a href=\"https:\/\/news.netcraft.com\/archives\/2019\/01\/10\/gov-security-falters-during-u-s-shutdown.html\">Paul Mutton, Netcraft<\/a><\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-hsts-preload-list-is-not-helping-in-this-case\">The HSTS Preload List is not helping in this case<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As you no doubt are aware, HSTS or HTTP Strict Transport\nSecurity, is a security header that forces browsers to only attempt HTTPS\nconnections. Or to put it another way, it eliminates the ability for anyone to\nmake non-encrypted HTTP connections with your site.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, there\u2019s a tiny little window where an\ninternet user is vulnerable. It exists on the very first visit to a given\nwebsite, before the header has been downloaded. To close this window, many\nsites, like the Department of Justice\u2019s, add themselves to the HSTS preload\nlist. Browsers know to only make secure HTTPS connections with any site on the\nlist, even if the users has never visited it before.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can probably see where this is going\u2026 ows2.usdoj.gov, is a DOJ website with an SSL\/TLS certificate that expired on Dec. 17. It has not been renewed. The site is down and cannot be reached. That\u2019s actually not the worst thing in the world, and it\u2019s far more secure than finding a way to connect via HTTP.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"610\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/usdoj-1024x610.png\" alt=\"\" class=\"wp-image-8281\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/usdoj-1024x610.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/usdoj-1024x610-300x179.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/usdoj-1024x610-768x458.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Ironically, the government\u2019s own ineptitude has saved some websites\nfrom HSTS pitfall.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">However, only a few of the affected .gov sites implement <a href=\"https:\/\/news.netcraft.com\/archives\/2016\/03\/17\/95-of-https-servers-vulnerable-to-trivial-mitm-attacks.html\">correctly-functioning HSTS policies<\/a>. Just a handful of the sites appear in the HSTS preload list, and only a small proportion of the rest attempt to set a policy via the Strict-Transport-Security HTTP header \u2013 but the latter policies will not be obeyed when they are served alongside an expired certificate, and so will only be effective if the user has already visited the sites before.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">As a result, most of these websites will just display the\nstandard interstitial warning that usually comes with an expired certificate. &nbsp;A few sites will even allow you to get to\ntheir login pages via HTTP if you click through the connection. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Obviously, don\u2019t do that.<\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<p class=\"wp-block-paragraph\"><em>As always, leave any\ncomments or questions below\u2026<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The government shutdown continues, and more and more sites are going down. Right now dozens of US government websites are unreachable as a result of certificate expirations during the shutdown&#8230;.<\/p>\n","protected":false},"author":6,"featured_media":8282,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[180,3367],"class_list":["post-8280","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-expiration","tag-us-government","post-with-tags"],"views":18093,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/bigstock-A-rubber-stamp-style-image-wit-223126585.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/8280","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=8280"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/8280\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/8282"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=8280"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=8280"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=8280"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}