DigiCert Revocation Incident

Author
Discussion

James6112

Original Poster:

5,408 posts

35 months

Tuesday 30th July
quotequote all
https://www.digicert.com/support/certificate-revoc...

Hang onto your hats, potential for some problems tonight..

.:ian:.

2,340 posts

210 months

Tuesday 30th July
quotequote all
I remember the same thing happening a while ago, that was fun, replacing the certs and ca on 15,000 machines, luckily mostly linux laugh

I left there 2 years ago, I wonder if they are affected again... biglaugh

wombleh

1,916 posts

129 months

Tuesday 30th July
quotequote all
How long are the random hostnames that digicert generate. Sounds unlikely to be much risk, just strict application of the standard.

Looks like they were supposed to revoke in 24hrs and are actually aiming for 120hrs, presumably to allow for customer notification, getting grief on CABF for it. I can imagine lots of big orgs wouldn’t be able to react in 24hrs, especially if they’d outsourced cert management.

James6112

Original Poster:

5,408 posts

35 months

Tuesday 30th July
quotequote all
wombleh said:
How long are the random hostnames that digicert generate. Sounds unlikely to be much risk, just strict application of the standard.

Looks like they were supposed to revoke in 24hrs and are actually aiming for 120hrs, presumably to allow for customer notification, getting grief on CABF for it. I can imagine lots of big orgs wouldn’t be able to react in 24hrs, especially if they’d outsourced cert management.
I can’t see any update to say it’s 120 hours?

wombleh

1,916 posts

129 months

Tuesday 30th July
quotequote all
Was looking at the ticket on cabf bugzilla, few comments about when the renovation period starts:

https://bugzilla.mozilla.org/show_bug.cgi?id=19103...

James6112

Original Poster:

5,408 posts

35 months

Tuesday 30th July
quotequote all
Thankyou