My Ooma uses outdated SSL cert, Chrome blocks it

Problems using My Ooma? Ideas on how we can make it better? You’ve come to the right place.
Post Reply
shoek
Posts:5
Joined:Wed Sep 08, 2010 8:53 am
My Ooma uses outdated SSL cert, Chrome blocks it

Post by shoek » Sat Aug 04, 2018 5:10 pm

Using Chrome dev channel Version 70.0.3510.2 gives the following message on https://my.ooma.com:

Of course most users are not on this version yet, but it will be in beta channel and stable channel in the next weeks.

Code: Select all

Your connection is not private

Attackers might be trying to steal your information from my.ooma.com (for example, passwords, messages, or credit cards). Learn more
NET::ERR_CERT_SYMANTEC_LEGACY

Warnings may be common while websites update their security. This should improve soon.

my.ooma.com normally uses encryption to protect your information. When Google Chrome tried to connect to my.ooma.com this time, the website sent back unusual and incorrect credentials. This may happen when an attacker is trying to pretend to be my.ooma.com, or a Wi-Fi sign-in screen has interrupted the connection. Your information is still secure because Google Chrome stopped the connection before any data was exchanged.

You cannot visit my.ooma.com right now because the website uses HSTS. Network errors and attacks are usually temporary, so this page will probably work later.

holmes4
Posts:539
Joined:Wed Mar 20, 2013 3:18 pm
Location:New Hampshire

Re: My Ooma uses outdated SSL cert, Chrome blocks it

Post by holmes4 » Mon Aug 13, 2018 3:56 pm

It's not "outdated", it's from Symantec. Chrome has been gradually removing trust of Symantec-issued certificates, and as of Chrome 70, they'll all be distrusted. https://security.googleblog.com/2017/09 ... antec.html has the details.

I would suggest filing a support ticket on this as well, though I expect you'll have an uphill battle getting the 1st and 2nd level support techs to understand the issue. I had a similar complaint regarding a web host I used, and they eventually fixed it.
Steve

Oomazapam
Posts:2
Joined:Tue Oct 16, 2018 11:56 am

Re: My Ooma uses outdated SSL cert, Chrome blocks it

Post by Oomazapam » Tue Oct 16, 2018 3:01 pm

It is very disconcerting to me. a new Ooma Telo customer, for Chrome to block access to ooma support with a warning, "site blocked due to unsafe certificate/cooties."
Ooma has had months of advanced warning that this was coming.

holmes4
Posts:539
Joined:Wed Mar 20, 2013 3:18 pm
Location:New Hampshire

Re: My Ooma uses outdated SSL cert, Chrome blocks it

Post by holmes4 » Mon Dec 03, 2018 2:55 pm

They did fix it eventually.
Steve

Post Reply