You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If rather than https://flatpak.org, a user visits https://www.flatpack.org, an SSL cert for *.apps.openshift.gnome.org will be used rather than the expected flatpak.org domain.
I tried a few variants and included a quick breakdown of valid vs. invalid certificates by URL.
As far as I can tell, errors occur with all https://www. variants.
Additionally, errors occur at https://flatpak.org/, but only for that specific URL with a slash at the end.
Aside from the above, https://flatpak.org and all its subpages appear to use the correct certificate.
I also included a full breakdown of the URLs i tried below the screenshots in the details.
Details
I stumbled on this accidentally while clicking a link to https://www.flatpak.org from documentation elsewhere:
Inspecting the certificate shows a wildcard cert of *.apps.openshift.gnome.org
❌ https://flatpak.org/ - wildcard openshift cert. Note: Your browser may strip the slash off the end of the URL when you click the link, but manually entering it into the address bar cause the issue.
Summary
If rather than
https://flatpak.org
, a user visitshttps://www.flatpack.org
, an SSL cert for*.apps.openshift.gnome.org
will be used rather than the expectedflatpak.org
domain.I tried a few variants and included a quick breakdown of valid vs. invalid certificates by URL.
https://www.
variants.https://flatpak.org/
, but only for that specific URL with a slash at the end.https://flatpak.org
and all its subpages appear to use the correct certificate.I also included a full breakdown of the URLs i tried below the screenshots in the details.
Details
I stumbled on this accidentally while clicking a link to
https://www.flatpak.org
from documentation elsewhere:Inspecting the certificate shows a wildcard cert of
*.apps.openshift.gnome.org
Full breakdown
flatpak.org
domain.Note: Your browser may strip the slash off the end of the URL when you click the link, but manually entering it into the address bar cause the issue.
Given the case with the
/
at the end of the domain, I also checked a few URLs in addition the base URL:/about/
)/setup/
)/setup/Manjaro
)The text was updated successfully, but these errors were encountered: