It's entertaining when you try and visit a CyberSecurity company website and it's blocked because it uses an invalid security certificate.
Why is this becoming an issue? Because Mozilla are removing trust bits for really old CAs. So there are a few CAs that are starting to drop out of the list of trusted CAs that Mozilla publish, and that propagates through to distributions as explained on the Mozilla wiki.