4 ms·
Hi, Heroku engineer here. We rekeyed our certificates, including the one for *.herokuapp.com, meaning we resent our original certificate requests (CSR) to our C
by dpiddy 13y ago
Hi, Heroku engineer here. We rekeyed our certificates, including the one for *.herokuapp.com, meaning we resent our original certificate requests (CSR) to our CA but signed with new private keys. This is why the dates didn't change.
Our CA will eventually revoke the previous incarnations of our certificates, signed with the old private keys, making them invalid.
- gojomo 13y agoThanks! It might be reassuring to others who see the same mixed-signals if the official blogpost made specific mention of APPNAME.herokuapp.com HTTPS, and that the certificates may look older but really are fresh.
- craigkerstiens 13y agoThanks for the feedback, we have updated the blog post to include some information regarding this.
- smw 13y agoAm I missing something, or doesn't the browser have to explicitly check for key revocation? I know the checkbox was off in my version of Chrome. Maybe I set it, but I'm not sure. This [1] Seems to suggest that Firefox, for instance, only checks for EV certs? [1] http://news.netcraft.com/archives/2013/05/13/how-certificate-revocation-doesnt-work-in-practice.html http://news.netcraft.com/archives/2013/05/13/how-certificate...
- orblivion 13y agoSo is there a simple way to check if an arbitrary site updated their certs?
- grittygrease 13y agoThis is completely the wrong approach. Your private key might have been compromised and you're generating another certificate for the same compromised private key? What is that supposed to do?
- schrodinger 13y agoI think you misread... the poster said they used a new private key with the same CSR.
- grittygrease 13y agoThe CSR contains the public key for a unique private key. How do you have a new private key with an old CSR?
- dpiddy 13y agoAs discussed on twitter (https://twitter.com/grittygrease/status/453606054698692608 https://twitter.com/grittygrease/status/453606054698692608), I should have said: We generated new CSRs, with new private keys, but with the same dates and details as the originals. This let us get fresh certs without going through a full renewal. Thanks for the prod.
- grittygrease 13y agoThanks for the update. Happy revocation day!