SSL / Security Certificate problem with paizo.com's secure login?


Website Feedback


Dunno if you guys are having an issue with your SSL, but I had to add a security exception to log in to my account tonight, just a minute or so prior to the timestamp on this post.

(I'm sure the web team's already on it if it is a big deal, but I habitually report crap like this for my own job while combing company websites and the compulsion is hard to break. =] )

Paizo Employee Senior Software Developer

We made some changes to the sign in code today. During the sign in process we have to redirect you between the regular server and the secure server, and there is a bug in the new code that occasionally causes a mismatch between the server to which we're redirecting you and the protocol used to talk to that server. In this case we're telling your browser to connect via https to paizo.com, but it should be https to secure.paizo.com, causing the certificate mismatch.

This is actually a bug that I was unable to duplicate earlier, but seeing your post just jogged my brain into figuring out what must be happening. This should be a) a reasonably rare occurrence, and b) fixed sometime tomorrow.

If you don't want to accept an incorrect cert, remove any paizo.com cookies and try to sign in again. My apologies for the difficulties -- having people associate certificate problems with paizo.com is definitely not something we want to have happen.


Gary Teter wrote:

We made some changes to the sign in code today. During the sign in process we have to redirect you between the regular server and the secure server, and there is a bug in the new code that occasionally causes a mismatch between the server to which we're redirecting you and the protocol used to talk to that server. In this case we're telling your browser to connect via https to paizo.com, but it should be https to secure.paizo.com, causing the certificate mismatch.

This is actually a bug that I was unable to duplicate earlier, but seeing your post just jogged my brain into figuring out what must be happening. This should be a) a reasonably rare occurrence, and b) fixed sometime tomorrow.

If you don't want to accept an incorrect cert, remove any paizo.com cookies and try to sign in again. My apologies for the difficulties -- having people associate certificate problems with paizo.com is definitely not something we want to have happen.

Firefox was giving me the same warnings. I actually took a look at the certificate and verified the issuer was legit. Not really familiar with how these work, but your explanation matches what Firefox was reporting (I think the term was domain mismatch). I only set the exception for one time figuring this was a temporary hiccup. Good to hear you know what the problem is and will have it sorted out quickly.

Dark Archive

Same here


Pathfinder Rulebook Subscriber

I got it this morning too.

Scarab Sages

Me too, just now.

Liberty's Edge

I'm also having this problem.

More of a notice for other people poking around and trying to figure out what's going on, than for anyone a Paizo. I know you guys are working on it still.

Paizo Employee Senior Software Developer

I believe this has been fixed now. If you find this problem again, please email webmaster@paizo.com, and let us know a) the URL of the page with the bad link, and b) the link you were trying to click on when you got the bad certificate message.

Sorry for the inconvenience and confusion everybody, and thanks for your patience.


No, I'm still getting errors. I just got the following two errors in the past several minutes and I keep having to refresh frequently:

The webpage at http://paizo.com/cgi-bin/WebObjects/Store.woa/wa/browse?path=paizo%2Fmessag eboards might be temporarily down or it may have moved permanently to a new web address.
Error 330 (net::ERR_CONTENT_DECODING_FAILED): Unknown error.

and

Unable to make a secure connection to the server. This may be a problem with the server, or it may be requiring a client authentication certificate that you don't have.
Error 107 (net::ERR_SSL_PROTOCOL_ERROR): SSL protocol error.

Paizo Employee Senior Software Developer

Urizen, there was definitely something weird going on for you at the time you posted. I think I may have fixed that particular issue -- please let me know if you continue to see weirdness.


Gary Teter wrote:
Urizen, there was definitely something weird going on for you at the time you posted. I think I may have fixed that particular issue -- please let me know if you continue to see weirdness.

That has calmed down, but there is a separate issue.

Your hawtness that was meant to fix duplicate spamming posts of the same word / phrases? I've had instances in the past 24 to 48 hours where I'm responding to something lengthy in quote and I had hit 'submit post' and then the actual post appeared, but I'm still in editing mode with the same text I was currently editing. It only does this when there's a drag on the secure server sending the message to be posted. I've been going back and deleting the duplicate post. But should it happen again, do you want me to leave it extant and flag it so you can see what's going on?

Paizo Employee Senior Software Developer

I think the code I just rolled should help with that particular problem. If you see it happen again go ahead and flag it as a double post. You can remove the duplicate and just flag the original if you like.


Gary Teter wrote:
I think the code I just rolled should help with that particular problem. If you see it happen again go ahead and flag it as a double post. You can remove the duplicate and just flag the original if you like.

Ok. :)


::decollapses 10' pole; pokes::

Community / Forums / Paizo / Website Feedback / SSL / Security Certificate problem with paizo.com's secure login? All Messageboards

Want to post a reply? Sign in.
Recent threads in Website Feedback