Customers of HTTPS certificate reseller Trustico are reeling after being told their website security certs – as many as 23,000 – will be rendered useless within the next 24 hours. . This is allegedly due to a security blunder in which the private keys for said certificates ended up in an email sent by Trustico. Those keys are supposed to be secret, and only held by the cert owners, and certainly not to be disclosed in messages. In the wrong hands, they can be used by malicious websites to masquerade as legit operations.. A significant security mishap at Certify has resulted in 25,000 SSL certificates being rendered invalid after private keys were compromised.. HTTPS Certificate Revocation, Trustico Security Issue, Private Key Protection, Certificate Management. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.