# SSL Certificate expired on \[cdn-business2.discourse.org\]

**URL:** <https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474>\
**Category:** Support\
**Created:** [2017年九月20日 18:38 UTC](https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474 "2017-09-20T18:38:26Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![rfindley](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rfindley/32/71814_2.png) [@rfindley](https://meta.discourse.org/u/rfindley)\
**Post date:** [2017年九月20日 18:38 UTC](https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474/1 "2017-09-20T18:38:26Z")

</div>

Just an FYI, my antivirus is reporting that the SSL certificate on [cdn-business2.discourse.org](http://cdn-business2.discourse.org) has expired. Looking at the certificate info, it looks like it expired on 9/15/2017.

 ![image](https://global.discourse-cdn.com/meta/original/3X/f/9/f956aeb2c16c708d41a0286e944d2592f105e79f.png)

---

<div class="post-metadata">

**Author:** ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)\
**Post date:** [2017年九月20日 18:49 UTC](https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474/2 "2017-09-20T18:49:33Z")

</div>

That CDN should no longer be in use. What site are you seeing this on?

---

<div class="post-metadata">

**Author:** ![rfindley](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rfindley/32/71814_2.png) [@rfindley](https://meta.discourse.org/u/rfindley)\
**Post date:** [2017年九月20日 18:52 UTC](https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474/3 "2017-09-20T18:52:00Z")

</div>

[wanikani.com](http://wanikani.com), and email notifications from the same.  
Should I let them know directly? I know Discourse hosts them.

---

<div class="post-metadata">

**Author:** ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)\
**Post date:** [2017年九月20日 18:58 UTC](https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474/4 "2017-09-20T18:58:35Z")

</div>

We do host them so that’s on us. Will look into this.

---

<div class="post-metadata">

**Author:** ![rfindley](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rfindley/32/71814_2.png) [@rfindley](https://meta.discourse.org/u/rfindley)\
**Post date:** [2017年九月20日 19:06 UTC](https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474/5 "2017-09-20T19:06:01Z")

</div>

I’m trying to figure out what file is coming from there, but if I select ‘block’ in my anti-virus, I still don’t see any failed files in Chrome’s dev tools, so I’m not sure. But I can trigger it every time I refresh the page, so… it’s in there somewhere.

---

<div class="post-metadata">

**Author:** ![rfindley](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rfindley/32/71814_2.png) [@rfindley](https://meta.discourse.org/u/rfindley)\
**Post date:** [2017年九月20日 19:26 UTC](https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474/6 "2017-09-20T19:26:07Z")

</div>

I’ve narrowed down _some_ of the links.

In my email messages, it’s due to emojis in archived (i.e. old) mail. So that makes perfect sense. No problem there.

If I go to [community.wanikani.com](http://community.wanikani.com) and refresh the page, I don’t get any warnings. But if I open the developer console (Chrome), I immediately get the warning, and will also get it every time I refresh the page with developer console still open.

It’s worth noting that I have “Disable Cache” checked in the developer console, so it’s reloading everything every time, whereas with the console closed, it will use cache. That may explain the difference.

I’ve checked under Firefox, and get similar behavior.

IE doesn’t have any problems.

---

<div class="post-metadata">

**Author:** ![supermathie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/supermathie/32/507518_2.png) [@supermathie](https://meta.discourse.org/u/supermathie)\
**Post date:** [2017年九月21日 15:49 UTC](https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474/10 "2017-09-21T15:49:01Z")

</div>

I’ve looked at this and can’t find any references to the old CDN (cdn-business2) on the live site. Also, I don’t get any warnings with the developer console open.

Are there any specific pages with which you’re having trouble? With that information I’ll be able to address the problem.

---

<div class="post-metadata">

**Author:** ![rfindley](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rfindley/32/71814_2.png) [@rfindley](https://meta.discourse.org/u/rfindley)\
**Post date:** [2017年九月21日 16:16 UTC](https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474/11 "2017-09-21T16:16:28Z")

</div>

The home page of [community.wanikani.com](http://community.wanikani.com) was doing it, as well as most others I tried.  
I couldn’t find any references to cdn-business2 either, though the security popup must be finding it somewhere.

Unfortunately, yesterday I told my antivirus to accept the SSL certificate, and I can’t find where to revoke it now, so I’m not sure I can replicate the issue anymore ☹

But we have a large population of fellow software people on the site for some reason, so I can ask if anyone else is seeing this, and point them to this thread.

Thanks for looking into it!

---

<div class="post-metadata">

**Author:** ![tgxworld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tgxworld/32/106117_2.png) [@tgxworld](https://meta.discourse.org/u/tgxworld)\
**Post date:** [2017年九月22日 03:28 UTC](https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474/12 "2017-09-22T03:28:31Z")

</div>



---

<div class="post-metadata">

**Author:** ![rfindley](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rfindley/32/71814_2.png) [@rfindley](https://meta.discourse.org/u/rfindley)\
**Post date:** [2017年九月22日 16:40 UTC](https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474/13 "2017-09-22T16:40:27Z")

</div>

One of the members at wanikani was able to find a reference to [cdn-business2.discourse.org](http://cdn-business2.discourse.org).  
His initial comment about .org vs .com is due to my mistyping when I posted an inquiry on [wanikani.com](http://wanikani.com).

> [@carloswaldo](#):
>
> I just noticed the issue is not with [cdn-business2.discourse.com](http://cdn-business2.discourse.com) but [cdn-business2.discourse.org](http://cdn-business2.discourse.org) which DOES exist and have an invalid certificate. (so NOD32 is right to complain)
> 
> This is the request:
> 
> ![image](https://global.discourse-cdn.com/meta/original/3X/4/d/4d65bca74a94dc65bdff2ef7f4db413804924d1f.png)  
> (Maybe this helps the Discourse team to debug)
> 
> This is the exact url: [https://cdn-business2.discourse.org/assets/plugin-8bb7a7a3d6d016496acaa8df06bd691326dfec1aaf169e60160556d9794ddfbc.js.map](https://cdn-business2.discourse.org/assets/plugin-8bb7a7a3d6d016496acaa8df06bd691326dfec1aaf169e60160556d9794ddfbc.js.map)
> 
> EDIT:
> 
> The reference to that url comes from:
> 
> [https://discourse-cdn-sjc1.com/business2/brotli\_asset/plugin-8bb7a7a3d6d016496acaa8df06bd691326dfec1aaf169e60160556d9794ddfbc.js](https://discourse-cdn-sjc1.com/business2/brotli_asset/plugin-8bb7a7a3d6d016496acaa8df06bd691326dfec1aaf169e60160556d9794ddfbc.js)
> 
> There is a commented line that says:
> 
> //# sourceMappingURL=[https://cdn-business2.discourse.org/assets/plugin-8bb7a7a3d6d016496acaa8df06bd691326dfec1aaf169e60160556d9794ddfbc.js.map](https://cdn-business2.discourse.org/assets/plugin-8bb7a7a3d6d016496acaa8df06bd691326dfec1aaf169e60160556d9794ddfbc.js.map)
> 
> Maybe Chrome/Firefox console tries to resolve any url for debugging purposes?

---

<div class="post-metadata">

**Author:** ![Carloswaldo](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/carloswaldo/32/79251_2.png) [@Carloswaldo](https://meta.discourse.org/u/Carloswaldo)\
**Post date:** [2017年九月22日 17:01 UTC](https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474/14 "2017-09-22T17:01:57Z")

</div>

> [@rfindley](#):
>
> Maybe Chrome/Firefox console tries to resolve any url for debugging purposes?

I think my suspicions are right. I tested with a basic html file like this:

```plaintext
<!DOCTYPE html>
<html>
<head>
	<script>
		//# sourceMappingURL=https://cdn-business2.discourse.org/assets/plugin-8bb7a7a3d6d016496acaa8df06bd691326dfec1aaf169e60160556d9794ddfbc.js.map
	</script>
</head>
<body>
	<h1>Cabecera</h1>
	<p>Párrafo.</p>
</body>
</html>

```

If I open this with Firefox (with the dev console open) it makes the request to [cdn-business2.discourse.org](http://cdn-business2.discourse.org) and the AV complains.

---

<div class="post-metadata">

**Author:** ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)\
**Post date:** [2017年九月23日 12:07 UTC](https://meta.discourse.org/t/ssl-certificate-expired-on-cdn-business2-discourse-org/70474/15 "2017-09-23T12:07:25Z")

</div>

Oh yes, excellent sleuthing work all!
