4 ms·
The important thing to know here is that you not only have to change your current certs you ALSO HAVE TO REVOKE THE OLD ONE. If you only change your current ce
by danielpal 12y ago
The important thing to know here is that you not only have to change your current certs you ALSO HAVE TO REVOKE THE OLD ONE.
If you only change your current cert to get a new key but you don't go through the revocation process of the old certificate if someone managed to get the old one they can still use it for a MiTM attack - as both certs would be valid to any client.
- gojomo 12y agoAlso, cert revocation just barely works, in some browsers, with EV certificates, after old CRLs expire over a course of months: http://news.netcraft.com/archives/2013/05/13/how-certificate-revocation-doesnt-work-in-practice.html http://news.netcraft.com/archives/2013/05/13/how-certificate...
- pixl97 12y agoTime for every browser to change that behavior.
- btown 12y agoIs there a tutorial (for multiple browsers/platforms) for browser users to manually initiate downloading and processing of the latest CRL? Is this even exposed by most modern browsers, i.e. as part of the "clear cache" functionality? If so, I'd want to tell my [self/family/friends/coworkers] to do this in the coming weeks to minimize the amount of time they might happen to send private information to a MITM attacking, say, an e-commerce site. Specifically, I'd be most interested for such a walkthrough for Google Chrome on OS X, which most people I know use.
- gsnedders 12y agoChrome doesn't check revocations by default. See "Check for server certificate revocation" in settings, which has for a while been disabled by default.
- nodesocket 12y agoWith GoDady, when you rekey, it automatically revokes the old cert after 72 hours.