Page 1 of 1

My Ooma uses outdated SSL cert, Chrome blocks it

Posted: Sat Aug 04, 2018 5:10 pm
by shoek
Using Chrome dev channel Version 70.0.3510.2 gives the following message on https://my.ooma.com:

Of course most users are not on this version yet, but it will be in beta channel and stable channel in the next weeks.

Code: Select all

Your connection is not private

Attackers might be trying to steal your information from my.ooma.com (for example, passwords, messages, or credit cards). Learn more
NET::ERR_CERT_SYMANTEC_LEGACY

Warnings may be common while websites update their security. This should improve soon.

my.ooma.com normally uses encryption to protect your information. When Google Chrome tried to connect to my.ooma.com this time, the website sent back unusual and incorrect credentials. This may happen when an attacker is trying to pretend to be my.ooma.com, or a Wi-Fi sign-in screen has interrupted the connection. Your information is still secure because Google Chrome stopped the connection before any data was exchanged.

You cannot visit my.ooma.com right now because the website uses HSTS. Network errors and attacks are usually temporary, so this page will probably work later.

Re: My Ooma uses outdated SSL cert, Chrome blocks it

Posted: Mon Aug 13, 2018 3:56 pm
by holmes4
It's not "outdated", it's from Symantec. Chrome has been gradually removing trust of Symantec-issued certificates, and as of Chrome 70, they'll all be distrusted. https://security.googleblog.com/2017/09 ... antec.html has the details.

I would suggest filing a support ticket on this as well, though I expect you'll have an uphill battle getting the 1st and 2nd level support techs to understand the issue. I had a similar complaint regarding a web host I used, and they eventually fixed it.

Re: My Ooma uses outdated SSL cert, Chrome blocks it

Posted: Tue Oct 16, 2018 3:01 pm
by Oomazapam
It is very disconcerting to me. a new Ooma Telo customer, for Chrome to block access to ooma support with a warning, "site blocked due to unsafe certificate/cooties."
Ooma has had months of advanced warning that this was coming.

Re: My Ooma uses outdated SSL cert, Chrome blocks it

Posted: Mon Dec 03, 2018 2:55 pm
by holmes4
They did fix it eventually.