Re: SSL Difficulties with older browsers

by "Paul Wilson" <webguroo(at)tampabay.rr.com>

 Date:  Tue, 4 Dec 2001 14:42:58 -0500
 To:  "Jay Smith" <jay(at)JaySmith.com>,
<hwg-techniques(at)hwg.org>
 Cc:  "Emerald Spirit" <emerald_spirit(at)yahoo.com>
 References:  deere WORKGROUP JaySmith
  todo: View Thread, Original
> The older browsers, at the time they were installed or last updated,
> had knowledge of the "known" providers of secure keys.  I don't think
> that Thawte is a terribly recent entrant, but until recently they were
> not prominently used in North America (the are/were Australian,
> right??).  Thus it is reasonable that some distributions of older
> browsers either pre-date them or simply did not have the necessary
> data built into them.
> 
> It seems to me that you are in a bad spot if you must use Thawte AND
> if you must care about the the older browsers.  The older browser
> users are obviously already shown a disinclination to upgrade and thus
> there is little you can do about them.
> 
> I do not know of anyway that browser sniffing is going to help you. 
> Okay so you sniff, but then what do you do that is different from what
> you were doing before?  If there NEEDS to be a secure site and the
> certificate is Thawte, about all you can do is route the browser to a
> page that explains the problem. HOWEVER, if I were a suspicious user,
> I would wonder if that was just an explanation to cover a scam.
> 
> We use EQUIFAX which was recently bought out by somebody.  My reason
> for choosing them was that their price was much, much, much lower than
> other prices I had seen.  I think http://secure.equifax.com works. 
> Otherwise search the web for "equifax ssl". In any case we have not
> had any reports of problems, from our clients, with their certificate.
> I can't really offer much help - but just as an FYI, I
> wanted to mention that we use Thawte certificates and
> have not had that problem. We did have a different
> problem, where older browsers without 128-bit
> encryption got a page-not-found error rather than a
> security level error.  We fixed that with (if I
> remember correctly) with a new SSL module in Apache.
> 
> I don't know what platform you are running, but you
> might look into a problem with the platform.


 I don't think Thawte is the problem since my host 
informed me we were using Equifax and he has all
the latest patches installed.

I also think many more of us are having this problem than 
may know about it.  I spent many hours chasing this down.

Many webmasters build a site and get very little feedback 
from their clients.  The ones that do, don't get enough info
from the client and they just chalk problems up to being a 
non computer user problem.

I work direct for one company.  We prefer our customers 
buy online because this way they are responsible for 
inputing the correct address and selecting the product they 
want.  It also takes a lot more time for us which increases 
costs.  

When someone calls up to place an order, we ask why they
didn't place it online. Many times it is paranoia or laziness
but in some cases we are told that their browser told them 
the certificate was expired.  We have figured out it's only old 
browsers doing this.

Evidently there is a real problem here because Charles
Upsdell sent me the link below which explains that there 
are two Y2K problems with older browsers.  Folks with
Netscape 4.02 and older and I.E. 4.0 and older are having
problems.  

See   http://www.upsdell.com/BrowserNews/y2k.htm


Paul Wilson
webguroo(at)tampabay.rr.com

HWG hwg-techniques mailing list archives, maintained by Webmasters @ IWA

This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.