3 ms·
Erm... Heartbleed has absolutely nothing to do with what version of OpenSSL you use to generate the cert.
by ayrx 12y ago
Erm... Heartbleed has absolutely nothing to do with what version of OpenSSL you use to generate the cert.
- spain 12y agoYou're right, so I fixed my post. What I meant was that my particular cert wasn't compromised. Either way, the StartSSL/Heartbleed fiasco is a real thing and I've added a link to the original discussion I was citing.
- EwanToo 12y agoNo, but if your SSL certificate has been exposed by Heartbleed, it would be sensible to revoke that certificate to prevent potential spoofing attacks, wouldn't it? StartSSL charge you for revoking that exposed certificate, so your choices are you pay for the revocation, or wait until the certificate expires.
- dspillett 12y agoIn there defence this their treatment of revocation requests is made quite plain in their policies, and any heartbleed exposure was not their fault (their signing certs were not affected IIRC). Now if there had been a problem with their signing certificates then I would have expected them to revoke anything affected for free and offer replacements similarly at no cost. OK, they could have done that anyway (or perhaps offered a discount on the revoke charge) as an good will gesture, but they didn't, so what.
- Joeboy 12y agoLeaving aside the question of whether their response was reasonable (I see the arguments either way), it turned out that using their service to secure your website was not free.
- lazylizard 12y agoactually, what i think is.. they're as near 'free' as it gets, probably. at least there's no up front cost using them. then its a lottery as to when u need to pay them to revoke... it could still end up cheaper than paying yearly fees for other certs, i imagine.. total cost of ownership or something..
- dspillett 12y ago> it turned out that using their service to secure your website was not free All they claim is to provide free certificates for non-commercial use, and that they do provide. If people read something else into that it isn't because they were deliberately led to. Though many people picking up a cert without really knowing the infrastructure won't know about revocation infrastructure and such so might have mislead themselves by having not read the Ts&Csm.
- ayrx 12y agoCheers HN for downvoting a factually correct statement because the parent post got edited after I pointed out an error...