Skip to content

Comment on OpenSSL Security Advisory: TLS heartbeat read overrunparent

Comments

All reasonable certificate authorities will — at no cost — revoke your existing certificate and issue you a new certificate with the same expiration date as your old certificate. You'd just need to send the CA a new certificate signing request created from a newly-generated RSA key pair.

If your CA wants you to buy a new certificate to recover from a key compromise, your CA is taking you for a ride, and you should find a less horrible CA to throw your money at.

I think startssl requires $$$$ to revoke and/or reissue those "free" certs before they expire :-/

Is there another good CA that doesn't charge $$$ for both issuing and revocations?

I just got a revocation request accepted with no charge there.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.