Skip to content

Comment on Amateur hour at AWSparent

Comments

So wait until you see this message: https://aws.amazon.com/security/security-bulletins/heartblee...

and then update your certs again just to be safe.

So you pay for revocation of certificates twice. The first time you revoked the certicates, someone could have compromised them immediately afterwards. How is that a good solutions?

There's not always a perfect solution, gotta work with what you're given.

If you absolutely can't wait for the updated status message then the solution I gave was the only solution.

If the price of the revocation (which my issuer doesn't charge) is too high for your business then your only option is to wait.

Is payment for revocation standard practice? I've reissued and revoked probably a dozen Comodo certs (both directly and via Namecheap as a reseller) without issue.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.