DigiCert Revocation Incident

Author
Discussion

James6112

Original Poster:

5,164 posts

33 months

Tuesday 30th July
quotequote all
https://www.digicert.com/support/certificate-revoc...

Hang onto your hats, potential for some problems tonight..

.:ian:.

2,277 posts

208 months

Tuesday 30th July
quotequote all
I remember the same thing happening a while ago, that was fun, replacing the certs and ca on 15,000 machines, luckily mostly linux laugh

I left there 2 years ago, I wonder if they are affected again... biglaugh

wombleh

1,878 posts

127 months

Tuesday 30th July
quotequote all
How long are the random hostnames that digicert generate. Sounds unlikely to be much risk, just strict application of the standard.

Looks like they were supposed to revoke in 24hrs and are actually aiming for 120hrs, presumably to allow for customer notification, getting grief on CABF for it. I can imagine lots of big orgs wouldn’t be able to react in 24hrs, especially if they’d outsourced cert management.

James6112

Original Poster:

5,164 posts

33 months

Tuesday 30th July
quotequote all
wombleh said:
How long are the random hostnames that digicert generate. Sounds unlikely to be much risk, just strict application of the standard.

Looks like they were supposed to revoke in 24hrs and are actually aiming for 120hrs, presumably to allow for customer notification, getting grief on CABF for it. I can imagine lots of big orgs wouldn’t be able to react in 24hrs, especially if they’d outsourced cert management.
I can’t see any update to say it’s 120 hours?

wombleh

1,878 posts

127 months

Tuesday 30th July
quotequote all
Was looking at the ticket on cabf bugzilla, few comments about when the renovation period starts:

https://bugzilla.mozilla.org/show_bug.cgi?id=19103...

James6112

Original Poster:

5,164 posts

33 months

Tuesday 30th July
quotequote all
Thankyou