Community
Wiki Posts
Search

cannot log into aa.com website

Thread Tools
 
Search this Thread
 
Old Dec 8, 2017, 8:24 am
  #16  
 
Join Date: Nov 2008
Location: UK/USA
Programs: AA EXP
Posts: 830
I cant get on it. ipad, mac etc no joy.
IflyonAA is offline  
Old Dec 8, 2017, 8:32 am
  #17  
 
Join Date: Nov 2003
Location: CGK/KOA
Programs: AA ExPlat HH Diamond
Posts: 1,689
Not working for me either from Jakarta. Not on safari, firefox, and google.
Penguinmoon is offline  
Old Dec 8, 2017, 8:34 am
  #18  
Moderator: American AAdvantage
 
Join Date: May 2000
Location: NorCal - SMF area
Programs: AA LT Plat; HH LT Diamond, Matre-plongeur des Muccis
Posts: 62,946
No problem logging in with my iPad Air 2, OS 11 and Safari, or Chrome.
JDiver is offline  
Old Dec 8, 2017, 8:56 am
  #19  
 
Join Date: Sep 2013
Location: MSN
Programs: AA, BAEC Gold
Posts: 3,936
Both Firefox and Safari on an iMac show the security certificate to have been revoked by Entrust. It was not due to expire until May 23, 2019 so it may have been compromised in some way. If you can connect then the risk is that anything you transmit can be read by a third party.
MADPhil is online now  
Old Dec 8, 2017, 9:03 am
  #20  
 
Join Date: Nov 2016
Location: SE ASIA
Programs: SQ KF GO, OZ GO, QR PC PLAT, TG ROP SL, LCAH SL, IHG SPIRE, Marriott BONVOY GO, HILTON GO
Posts: 641
Question Same here

Originally Posted by elliottishere
I am having the same problem as well. Must be an issue on AA's end.

My browser says:

Your connection is not private

Attackers might be trying to steal your information from www.aa.com (for example, passwords, messages, or credit cards). Learn more

NET::ERR_CERT_REVOKED
Trying to check on my seating assignment for a booking I made last night, with a code share flight on CX.
So does this mean that for many users who can't get into the AA website, that this translates to bookings not made & lost revenue?
That can't be good for business.
kaffir76 is offline  
Old Dec 8, 2017, 9:21 am
  #21  
FlyerTalk Evangelist
 
Join Date: Feb 2003
Location: Denver, CO, USA
Programs: Sometimes known as [ARG:6 UNDEFINED]
Posts: 26,809
Appears to be back up as of 9:20 AM MT.
DenverBrian is offline  
Old Dec 8, 2017, 9:22 am
  #22  
 
Join Date: Nov 2008
Location: UK/USA
Programs: AA EXP
Posts: 830
Yes back up for me too! Mac Chrome.
IflyonAA is offline  
Old Dec 8, 2017, 9:24 am
  #23  
 
Join Date: Dec 2017
Programs: AA
Posts: 36
Originally Posted by IflyonAA
Yes back up for me too! Mac Chrome.
The TLS certificate appears to have changed to a newly issued certificate. Sounds like someone doing maintenance last night forgot to use the new certificate. I notice that the look and feel to the site has changed overnight.
JDiver likes this.
eastmanrg is offline  
Old Dec 8, 2017, 10:03 am
  #24  
 
Join Date: Mar 2009
Posts: 2,295
Anyone able to provide a technical answer as that what may have happened?

It's back up for me, but I couldn't use it all morning (rep did waive the phone booking fee when I called and inquired about an award ticket during the outage.)
danpeake is offline  
Old Dec 8, 2017, 10:47 am
  #25  
 
Join Date: May 2012
Location: HNL
Programs: AA PP 1.8MM, PC Spire, Hertz 5*, Hyatt Globalist
Posts: 1,030
Originally Posted by danpeake
Anyone able to provide a technical answer as that what may have happened?

It's back up for me, but I couldn't use it all morning (rep did waive the phone booking fee when I called and inquired about an award ticket during the outage.)
My guess is that they made some changes last night and pushed out code. Any good global company will have cached pages across the world, CDN. When new code is pushed it should slowly push to all the locations. Either bad certs have been pushed or new good one's have been pushed. Either way it seems like there are different certs at different locations and thus some can login and some can't depending on which node you are getting your data from.

This happens at our company from time to time. Some code doesn't automatically cache out to the secondary nodes and a forced refresh of the cache needs to be done to all the secondary nodes. Although you would think by now AA would have fixed it.
danpeake likes this.
nutwpinut is offline  
Old Dec 8, 2017, 10:48 am
  #26  
 
Join Date: Jun 2016
Programs: ex-multiyear AA EXP/OWE, now SA Gold/AC Super Elite
Posts: 165
Originally Posted by danpeake
Anyone able to provide a technical answer as that what may have happened?
Quite simply: someone in AA's security team issued a revocation of their SSL certificate. (The mechanism that allows you to communicate with the site "securely".) This can be for a number of reasons, up to and including them believing someone obtained a copy of their private certificate. With public key cryptography, even the suspicion that your private certificate may have been exposed will require companies on the ball to immediately revoke the certificate and obtain a new one.

A copy of your certificate in the wild means an attacker would be able to spoof aa.com and you would not know you weren't at the legitimate site.

Keep in mind that the issue may not have necessarily been due to a malicious or nefarious incident, someone at AA themselves may have inadvertently exposed the private key (it happens).

Some background reading, for those that may be interested: https://www.globalsign.com/en/ssl-in...l-certificate/
A great post that explains how public/private key cryptography works: https://blog.vrypan.net/2013/08/28/p...for-non-geeks/

The bottom line: an incident like this is painful for a company, but the alternative is much worse. It's entirely possible we may never know what led to them revoking their cert.
JDiver, nutwpinut, A1pax and 1 others like this.
RichVan is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.