As if things couldn't get more bizzare....
As a rooted D1 user, and seeing as how I have a basic idea on how Certifying Authorities and trust stores work (I've been successful at my company in implementing SSL, setting up an in house CA to sign our server certs, chains, and other such nonsense) I took it upon myself to update /etc/security/cacerts.bak myself. I found that I needed the bouncycastle (I kid you not) crypto provider to read and/or change the keystore (thanks so much for not using std. jks). I then found the offending (or rather *missing*) CA Certs, starting with the one from Thawte (now Verisign). I went straight to the Verisign website as I sure as hell wasn't going to trust some odd download. I unpacked the zipped up FULL CA list and stuffed the appropriate item into the CA store. Swapped out the store (after copy and backup of the original), rebooted the phone just for the halibut, and pointed my browser back to slashdot.org and voila, NO warning. Gives one a bit of confidence doesn't it? So I repeated the process for the stupid one VZW's website was hollerin' about. This was a touch more complex because the signing cert was part of a chain so I needed BOTH items in the store. Added them, and again success! THEN I discovered that my VZW DVR manager now REFUSED TO CONNECT. After a temporary red herring (I added a network printer to my network and needed to kick over the wireless router, and also found that for a short time I could not use VZW website to manage my dvr) everything seemed to be back to normal EXCEPT my droid's DVR manager app. So on a lark, I switched the bks files back to the original that was on my droid. The result was:
1) my dvr manager app could now connect and all was well...
2) the warnings I WAS getting in my browser DISAPPEARED completely.
WTF is going on here??? This is patently stupid. I not so crazy to think I could not have done something wrong... but all I did was ADD a couple of CA certs to the keystore... how on earth could this have broken DVR manager's connectivity since whatever certs it needed are STILL in the store? I sure as heck didn't take one out! And since I WAS getting these messages on the *original* keystore, *why did the warnings go away when I put the original back*? (unless by some miracle slashdot/google/vzw changed things back on their servers!)