HTTPS failure on https://repository.spotify.com

Status: Closed

Navigating to https://repository.spotify.com/pool/non-free/s/spotify-client/ on chrome gives an https failure. It looks like the certs are misconfigured.

 

This is espeically concerning as this link is used to download software.

 

Chrome Version: 54.0.2840.100 (64-bit)

OS Version: Linux 3.13.0-101-generic

Error: There are issues with the site's certificate chain (net::ERR_CERT_COMMON_NAME_INVALID).

Hi guys!

 

We're closing this thread as we haven't heard back from you in a while. Don't hesitate to give us a shout if you still have the same issue.

 

Have a great day 🙂

Comments
Alejandro_C
Status changed to: Closed

Hey, thanks for letting us know about this!

 

Just to confirm, this happens across different web browsers and several types of connection?

 

We'll see what we can suggest. 

joerichey

Was able to repoduce the certificate errors on Chrome (54.0.2840.98) and Safari (12602.2.14.0.7) on macOS Sierra (10.12.1) and on Chrome (54.0.2840.91) and Safari on iOS (10.1.1). Trying to use wget to download the package gives "ERROR: no certificate subject alternative name matches requested host name ‘repository.spotify.com’."

 

All these are running into problems with the wildcard *.cloudfare.com certificate.

RodrigoPalma

Thanks for the update, @joerichey!

 

The same thing happens if you change your WiFi connection? Give it a try and let us know how that goes.

 

We'll be waiting for your answer 🙂

joerichey

 @RodrigoPalma, yes the issue persited with connections via work wifi, home wifi, and on mobile data.

 

The error (net::ERR_CERT_COMMON_NAME_INVALID) is caused by the website vending a cert that was issued to *.cloudfront.com not *.spotify.com. This name mismatch is triggering the TLS related error.

 

Cert thumprint: ‎f2 07 b0 c2 15 8d d4 82 da 6b 8e 78 fe 7a 63 5e 01 0e d9 78

Issued To: *.cloudfare.com

 

I also got the issue to reproduce on Chrome and Edge on Windows 10

Sophia

Thanks for getting back to us @joerichey!

 

Just to check, can you let us know where you get the link from? We tried opening the link and it seems it's broken. Once we have that information, we'll see what we can suggest. 

 

Let us know if you have any questions 🙂

 

Sophia, 

RodrigoPalma
Status changed to: Closed

Hi guys!

 

We're closing this thread as we haven't heard back from you in a while. Don't hesitate to give us a shout if you still have the same issue.

 

Have a great day 🙂

joerichey

@Sophia The link if on your website for downloading the spotify linux client https://www.spotify.com/us/download/linux/.  I went to the link to grab the .deb file and tried the https version and it broke.

 

@RodrigoPalma Sorry for the late responce, hopefully you can reopen this

marek_sebera

This issue shouldn't be closed, as the certificate issue is still present currently.

https://repository.spotify.com is still served via incorrect certificate for *.cloudfront.com