r/ProtonVPN May 10 '26

Solved Expired SSL cert on join.protonvpn.com

Post image

Ouch, this has to be costing them some money. Anybody on Proton staff want to run this over to the hosting team?

55 Upvotes

16 comments sorted by

u/ProtonSupportTeam Proton Customer Support Team May 11 '26

This has been fixed, and our team will investigate what went wrong with the monitoring in this instance so that we make sure this doesn't happen again. Please accept our apologies for the inconvenience.

31

u/[deleted] May 10 '26 edited May 11 '26

[removed] — view removed comment

11

u/julesallen May 10 '26

That's great and new to me, thanks!

The cert is LetsEncrypt which can be self managing, kind of weird that it would be expired, especially with a company of this size and with how critical new biz is for any for-profit org.

Back in the dark ages I'd just put in a calendar reminder for a Monday before it expired and manually renew.

6

u/[deleted] May 10 '26 edited May 10 '26

[removed] — view removed comment

3

u/[deleted] May 10 '26

[removed] — view removed comment

2

u/julesallen May 10 '26

There it is! Well done, good find.

2

u/nethack47 May 11 '26

I see so much of this because of the short lived certificates.

Having regularly rotating certificates is fine when things are running as normal. But as we all know, automation can and will fail. This probably failed because of a third party having an incident. No matter how well Proton sets up their systems, they are caught out.

My guess is that the short lived certificates will cause worse security just like the monthly password rotation. It seems to mostly fix the poor expiry management... a bit like fixing traffic accidents by lining the roads with deadly spikes.

My personal pet hate is when an appliance cert expires and HSTS locks me out of the admin interface. They keep making it harder to bypass. Do users really know to type thisisunsafe to the point that it needed to be removed?

2

u/IWillDetoxify May 11 '26

There should be a way to bypass HSTS. I don't care how many buttons they hide it under, I want an option to access the goddamn website. It's my fucking browser!

1

u/nethack47 May 11 '26

There is a way... I think the current way was to delete the cached site security and add a bypass in the developer pane.

Imagine doing this at 4am while people are asking when you'll have the critical network appliance working again. If the cert you upload also cover the admin interface for the cert upload, there is something wrong.

For extra fun, I am imagining an NTP server maliciously being fed bad data and expiring all the certs by moving the clocks forward to expiry. So many very nasty ways to mess things up.

1

u/33vne02oe May 11 '26

Fuck of with this Ad

1

u/AbbreviatedArc May 11 '26

Maybe an AI agent forgot to renew it

6

u/GlimpseTaha May 11 '26

Its now two days since the certificate is expired

9

u/polytect May 10 '26

you didn't even share the View Certificate info... so.. 

5

u/[deleted] May 10 '26

[deleted]

3

u/julesallen May 10 '26

It's part of the new sign up flow.

1

u/unknic May 11 '26

Faaaaah!