I got an eMail from a certmaster denying me a free rekey, for a soon-to-be tax-exempt non-profit society of public utility (so there is no money here, and we do not even process credit card data or anything). And that after someone else did get a free rekey citing this vulnerability. Clearly, Startcom is either swimming in money today and losing their status as trusted Root CA very soon, or they got to change their attitude RSN, pronto.
Comments
I got an eMail from a certmaster denying me a free rekey, for a soon-to-be tax-exempt non-profit society of public utility (so there is no money here, and we do not even process credit card data or anything). And that after someone else did get a free rekey citing this vulnerability. Clearly, Startcom is either swimming in money today and losing their status as trusted Root CA very soon, or they got to change their attitude RSN, pronto.
For what its' worth, they have finally released a statement:-
https://www.startssl.com/?app=43
This claims that CRLs and OCSP would then be expensive / lots of downloads....