"Connection is not secure" using older computers/devices

Modified on Tue, 19 Oct 2021 at 12:21 PM

Summary

Since October 2021, accessing DotGolf sites and service from devices with outdated operating systems is more likely to produce certificate errors such as the following:



Why is this suddenly happening?

DotGolf encrypts traffic to our sites for privacy and security.  We do this using a third party Certificate Authority (CA) called LetsEncrypt.  Using this service means we can quickly provision new certificates for sites in an automated way, an important feature for the many club websites that we host.


On September 30th, 2021, one of the certificate authorities in the trust chain for LetsEncrypt certificates expired.  This is a normal thing that happens; CAs only have a specific lifespan - this is by design.  There is more to it than this simplified explanation; see the technical info here.

Devices are normally informed about CA changes through software/operating system updates from their respective vendors (this is called the device "trust store").  DotGolf has no control over this process.


In order to access the Internet at large, your device requires an up-to-date trust store; if the trust store is allowed to get out of date, an increasing number of websites will cease to be accessible.


Which devices/operating system versions are affected?

The following devices are known to be a problem with the current trust chain:

  • Apple macOS < 10.12.1
  • Apple iOS < 10
  • Mozilla Firefox < 50
  • Android v2.3.5 and earlier
  • Windows XP earlier than SP3

To confirm that this is the problem, you can visit other sites using the same certificate; for example:

  1. https://nginx.org/
  2. https://www.elemental.co.nz/

You should receive the same error message when visiting these sites, since they use the same certificate trust chain as DotGolf.

How can we fix this?

Unfortunately, DotGolf has no control over the trust store on your device(s); we can offer some pointers as to how you might be able to resolve the problem, but please speak to your regular IT service providers/computer technicians to obtain independent advice; we cannot be held responsible for the outcome if you follow the advice below without knowing the implications.


  1. Install the latest operating system and security updates for your device.  

    Unfortunately, this step may not work for everyone; particularly with Apple devices, hardware quickly becomes unsupported and the latest iOS updates will not install on these devices. Please consult your hardware documentation to see if you can install at least macOS 10.13 OR iOS 10.

  2. If your device is a PC or Apple Mac, you can install and use the latest version of Firefox.

    Firefox ships with its own trust chain, which means it is independent from the potentially outdated device trust store.

  3. Upgrade your hardware.

    While there is a financial outlay, there are many benefits to upgrading to modern hardware; you'll see much better performance, better power efficiency (and therefore longer battery life for a device the same spec), and an up to date operating system is much less vulnerable to security issues.


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select atleast one of the reasons

Feedback sent

We appreciate your effort and will try to fix the article