3 ms·
> Website owners install Secure Sockets Layer (“SSL”) certificates to protect and encrypt online interactions with their servers. If an SSL certificate expires
by brianpgordon 7y ago
> Website owners install Secure Sockets Layer (“SSL”) certificates to protect and encrypt online interactions with their servers. If an SSL certificate expires, transactions are no longer protected. As part of an IT management effort unrelated to the Apache Struts vulnerability, Equifax installed dozens of new SSL certificates on the night of July 29, 2017, to replace certificates that had expired. This included a new certificate for the expired SSL certificate for its online dispute portal. The SSL certificate needed to be up-to-date to properly monitor the online dispute portal, but had expired eight months earlier in November 2016. Almost immediately after updating the SSL certificate, company employees observed suspicious internet traffic
Obviously "if an SSL certificate expires, transactions are no longer protected" is just wrong, so what were they trying to say here? Maybe Equifax's internal monitoring tools were refusing to connect to the target host because of the expired cert?
- colek42 7y agoFrom my understanding the monitoring client would refuse to connect due to the expired cert.