Incorrect SSL certificates

One of my domains bucksccc.org.uk, moved to a new host last Thursday. A new secure SSL certificate was issued and the site is now working correctly on machines all over the globe, inc phones, tablets, PCs etc. The one place it is not is my Mac. On any browser, I am given an error message saying site is insecure and certificate is not trusted. When I view the certificate it is showing the old one. I also have Windows 10 on my Mac and the site is fine on that. It is an old mac running (OS High Sierra). I have cleared cache on all browsers, refreshed Firefox, uninstalled Avast Security, rebooted - you name it I have tried it (obviously except the fix!)


Thanks for ideas - Frank

iMac 21.5", macOS 10.13

Posted on Apr 13, 2020 3:19 AM

Reply
41 replies

Apr 15, 2020 9:56 AM in response to a brody

Thank you for that lesson, very instructive. i think i will have to do a reinstall, but on a machine so old, it has probably built up a lot of rubbish on it over the years. i will then start saving for a nice new machine. This one is 10 yrs old so has earned its keep.


If the new certificate works I will let you know, but will still probably do a reinstall.


Thanks

Apr 15, 2020 10:44 AM in response to a brody

a brody wrote:

MrHoffman. Avast has stopped as of January that nefarious practice. I saw the article which stated they realized they were mistaken in their procedures.


"Mistaken"? Avast either knew or should have known that this was a privacy disaster. They went ahead and did it anyway. They went ahead and implemented this, and sold access. That's a policy decision from Avast management, and not a "mistake". And if Avast management somehow didn't know this was a "mistake", that's arguably yet worse.


More recently than this "mistake", Avast had a privileged parser with untrusted input, and insecurely designed. "Despite being highly privileged and processing untrusted input by design, it is unsandboxed and has poor mitigation coverage. Any vulnerabilities in this process are critical, and easily accessible to remote attackers." This is a classic security design error, and the results of this error can and variously do introduce vulnerabilities into the app—and this error is a part of a security tool. A tool which will absolutely itself be targeted, too.


None of which engenders my trust in Avast.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Incorrect SSL certificates

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.