Oh Dear's SSL certificate monitoring checks every 30 minutes per site, which allowed it to detect a misconfiguration at a large CDN provider where some edge servers were returning their own wildcard certificate instead of the customer's certificate. The post explains how the issue was discovered through SNI-based certificate fetching, how Oh Dear improved its tooling to expose the specific IP address used during checks, and how they collaborated with the CDN provider to identify and fix two misbehaving edge servers across thousands worldwide.

5m read timeFrom ohdear.app
Post cover image
Table of contents
Why we found it in the first place #What happened here? #Changes made at Oh Dear to help verify this #Working together with the CDN #
202 Impressions