3 ms·
It becomes especially tricky when any given customer can hard code an SSL cert into the Websphere or Tomcat server without the service provider knowing anything
by jonathanoliver 12y ago
It becomes especially tricky when any given customer can hard code an SSL cert into the Websphere or Tomcat server without the service provider knowing anything about it. Then, when the service provider needs to rotate the certificate because it's about to expire and is renewed or perhaps it's suddenly rotated (because of Heartbleed, for example), it breaks the customer.
What kind of communication channels have you guys seen or used for that kind of scenario? A separate Twitter feed? A blog? Sending an email to all customer every time the SSL certificate changes in any way?
- boz_x 12y agoMore or less any communication channel will work, provided clients are aware of it and checking it regularly. Personally I would recommend a mailing list that your clients can subscribe to in order to be notified of any upcoming changes.