NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
Ayebeegee
Feb 18, 2022Guide
Orbi cert error all websites
Hi there! I have an Orbi system (router + 2 sats) that has been working well for years. Router FW is V2.7.3.22, and nothing shows as available to upgrade.
Internet connection shows that it is working as well.
An apple tv that is hardwired to the router is working.
All wireless devices are getting cert errors regardless of platform (Win 10 pro, Win 11 pro, macos, ios)
"
NET::ERR_CERT_COMMON_NAME_INVALID
Subject: www . routerlogin . net
Issuer: www . routerlogin . net
Expires on: Jan 6, 2031
Current date: Feb 18, 2022
"
****Spaces added by me so it didn't show up as HTML
I cannot click through this to allow the cert as valid
This is an intermittent error that I am seeing across my entire house / various devices.
Some Google-fu show that routerlogin.net is owned by netgear so I'm not sure what I can do.
Thoughts? We are still WFH so this is a major impact (tethered to my phone right now).
Thanks!!!
10 Replies
Sorry for the double post. Am tethered to my phone and the connection hung when posting.
Are Parental Controls or Bitdefender Armor enabled on this router?
No they are not.
Thanks!
This issue has appeared on the forum before, and I cannot remember the resolution. (sigh. age.)
If you don't want to read my rant, please jump to the bottom.
Yes, Netgear's SSL certificate situation is a mess. Many years ago, Netgear managed to register an SSL certificate that covered a bunch of URL's, including routerlogin.com, routerlogin.net, orbilogin.com, orbilogin.net.. (and some more). In August 2019, that SSL certificate expired and was not renewed. There has never been an explanation. Some think that Netgear simply forgot to renew it. Others think that the certificate authority refused to renew it for some reason. (Perhaps other router manufacturers claimed it was unfair for Netgear to 'own' routerlogin.com. Perhaps they realized that all those 1,000's of web sites claiming to be routerlogin.com are not really Netgear. Late in 2019 Netgear released new firmware which included a self-signed SSL certifiate.
The goofy part is that the router never sends the URL routerlogin.com (orbilogin.net, etc.) to a DNS server to be resolved. (Which IP would a DNS authority say it points to?) The router intercepts the DNS request and says, "that is ME". And, the SSL certificate doesn't matter because the router web management is not a secure web site. (It is http, not https)
All was good until web browsers decided to prioritize secure web sites over plain web sites. Chrome, Edge, Firefox, Opera, Safari... all of them decided to first look for a secure web site before looking for what the user typed in. So, if the user wants to open http://ford.com, the browser first looks for https://ford.com. If that URL exists, the browser opens it. If not, then it tries the insecure web site.
For some reason, when your devices try to open web sites, there is an error that causes the web browser to be redirected to the Orbi web management system. The browser tries to open 192.168.1.1 as a secure web site and receives that self-signed SSL certificate. But browsers do not trust self-signed SSL certificates, so the browser says, "ALERT ALERT UNSAFE GO BACK GO BACK"
There is usually a tiny link somewhere on the page that allows the user to tell the browser, "yes, I know it is unsafe, but I want to go there anyway. Just open the web page." Can you try that and report what comes up?
- Knight69Aspirant
Ayebeegee wrote: www.myindigocard.comHi there! I have an Orbi system (router + 2 sats) that has been working well for years. Router FW is V2.7.3.22, and nothing shows as available to upgrade.
Internet connection shows that it is working as well.
An apple tv that is hardwired to the router is working.
All wireless devices are getting cert errors regardless of platform (Win 10 pro, Win 11 pro, macos, ios)
"
NET::ERR_CERT_COMMON_NAME_INVALIDSubject: www . routerlogin . net
Issuer: www . routerlogin . net
Expires on: Jan 6, 2031
Current date: Feb 18, 2022
"
****Spaces added by me so it didn't show up as HTML
I cannot click through this to allow the cert as valid
This is an intermittent error that I am seeing across my entire house / various devices.
Some Google-fu show that routerlogin.net is owned by netgear so I'm not sure what I can do.
Thoughts? We are still WFH so this is a major impact (tethered to my phone right now).
Thanks!!!
There is an error that causes the web browser to be redirected to the Orbi web management system. The browser tries to open 192.168.1.1 as a secure web site and receives that self-signed SSL certificate.