back to article Elexon's Insight into UK electricity felled by expired certificate

Demonstrating that Microsoft is not alone in its inability to keep track of certificates is UK power market biz Elexon. Elexon is an important cog in the UK's wholesale electricity market machine and provides operational data via its Insight Solution platform. Want to know the balance of fuel types used in power generation? No …

  1. My other car WAS an IAV Stryker

    You know an issue is becoming a little too widespread

    ...when El Reg creates a category to cover it specifically!

  2. Dave Pickles

    That explains why the National Grid monitor at https://grid.iamkate.com/ stopped working shortly after midnight...

    1. Mishak Silver badge

      And Gridwatch, which also had a "Elexon is broken" banner for a while.

      1. cyberdemon Silver badge

        That was due to "intermittent data" though, and it was visible in their graphs, with some sources spuriously dropping to zero. I don't think an expired cert would cause that? Probably a separate issue.

        However, I did notice that Drax Electric Insights (which provides the same data, not as good IMO as gridwatch except that they also have a price graph) was unavailable for an entire month, and that seems more likely to have been caused by this certificate issue.

        Gridwatch did not seem to be affected so much, maybe they simply ignored the cert all along?

        1. dinsdale54

          From Gridwatch - which I like because of the dials :

          UPDATE

          Tuesday 9th July

          The TLS certificate on https://data.exelon.co.uk has expired, rendering their website and its data inaccessible

          Regards Webmaster @ templar.co.uk

        2. Mishak Silver badge

          No, there was a message on the site during the day to say there was an issue with the feed. However, something else had gone wrong about a month ago as some of the data was frozen (also fixed now*).

          * turns out this was due to an API change that happened when the owner of the site had to take a month off for medical reasons. Glad to see they are back on their feet and wish them well.

  3. OhForF' Silver badge
    Meh

    >an invalid certificate means the connection is not secure, and the data transmitted on it could be modified or stolen<

    A day after the expire date the certificate is no longer trusted but most likely still as secure as the day before. If you have trusted that certificate (after vetting it the first time) it is likely safer to trust it than trusting a new certificate issued by some of the CA's that your browser trusts blindly.

    Of course trusting it isn't supported by the CA infrastructure as it is formally invalid (and would be in the way of making money with renewals).

    1. jokerscrowbar

      Safari doesn't give me an option to override the warning about invalid certificates. There’s no ‘Visit Anyway’ option on a classified ads site (hosted via GoDaddy) that went down on the 17th of last month. I doubt the site will survive losing three weeks of ad revenue and sales.

      1. Doctor Syntax Silver badge

        If they haven't discovered it went down they don't deserve to survive.

    2. talk_is_cheap

      You don't have to purchase certs nowadays. Even Eloxon's main website uses certs from Cloudflare as I guess they use Cloudflare as their CDN. They can then use Cloudflare certs on their own systems or choose another vendor.

      The fact that the Insight web pages are using a cert from DigiCert likely means that no one in the tech team at Eloxon has upgraded their infrastructure to use Let's Encrypt certs which are also free.

    3. Jamie Jones Silver badge
      Headmaster

      Yep, and even apart from that, the connection is still secure, you just can't be sure you're talking to the correct person, so whilst a MITM could be possible, the bit you quoted implies the connection drops down to unencrypted.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like