geo-um.btrll.com Untrusted Certificate

Hello,


I'v noticed since upgrading from El Cap to Sierra (10.12.1) using Safari (10.0.1) I am constantly getting, geo-um.btrll.com pop up errors. (This may be unrelated to the Sierra upgrade - it just started not long after)


What is this and how do I make it stop? Seems particularly common when I hit Yahoo's homepage. Is this a virus or some type of malware? Anyone else getting this, or know how to get rid of it? I will get dozens of them and not always from geo-um.btrll.com.


I have even repeatedly cleared my history, cache, cookies, and even restarted. Still comes back, but with no definite pattern — some days not so bad, others it's constant.


FYI - I use OpenDNS to get to the internet. Thanks for any advice.


User uploaded file

iMac (Retina 5K, 27-inch, Late 2015), iOS 10.1.1

Posted on Nov 8, 2016 6:47 AM

Reply
2 replies

Apr 19, 2017 8:12 AM in response to Deepsky06

I too use https://umbrella.cisco.com/ and I am sharing a similar problem with *.btrll.com somehow creeping into my macOS system.


First, thanks for being alert and including a picture of the certificate. Next, be aware that Cisco Umbrella protects you and me from malware sites like *.btrll.com by intercepting the DNS request, and re-directing the active web browser to an Cisco Umbrella warning page alerting you that you were almost hijacked.


The reason why you are getting the pop-up for an untrusted certificate -- and not seeing the expected Cisco Umbrella warning page -- is that your macOS system has not yet been told to "Trust" the Cisco Umbrella root level certificate.


My recommendation is that you click to "Always Trust" certificates from Cisco Umbrella -- which will then allow you to see the Cisco Umbrella warning page.


For a longer-winded explanation of the above, see https://docs.umbrella.com/product/umbrella/rebrand-cisco-certificate-import-info rmation/


In closing : I do not install anti-virus products on my macOS, but I _highly recommend_ use of Cisco's Umbrella product (formerly known as OpenDNS.com Umbrella). Although my copy of Cisco Umbrella protects me from *.btrll.com and other malware sites, I am have a devil of a time figuring out _what web sites_ are bringing in the unwelcome *.btrll.com references.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

geo-um.btrll.com Untrusted Certificate

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.