Jump to content

Recommended Posts

Posted
I got affected by this, fortunately trustico sent out emails with a coupon to redeem a new certificate for free....and thankfully i updated my documentation 3 months ago with all the locatiosn i have to update for a certificate replacement :p
Posted (edited)

https://www.digicert.com/blog/digicert-statement-trustico-certificate-revocation/

 

"Trustico requested revocation of their Symantec, GeoTrust, Thawte and RapidSSL certificates, claiming the certificates were compromised. When we asked for proof of the "compromise", Trustico did not provide details on why they were requesting the immediate revocation. Trustico’s CEO indicated that Trustico held the private keys for those certificates, and then emailed us approximately 20,000 certificate private keys. When he sent us those keys, his action gave us no choice but to act in accordance with the CA/Browser Forum Baseline Requirements, which mandate that we revoke a compromised certificate within 24 hours. As a CA, we had no choice but to follow the Baseline Requirements. Following our standard revocation process, we gave notice via email to each certificate holder whose private keys had been exposed to us by Trustico, so they could have time to get a replacement certificate.

 

In communications today, Trustico has suggested that this revocation is due to the upcoming Google Chrome distrust of Symantec roots. That is incorrect. We want to make it clear that the certificates needed to be revoked because Trustico sent us the private keys; this has nothing to do with future potential distrust dates.

 

The upcoming Chrome distrust situation is entirely separate. We are working closely to help customers with certificates affected by the browser distrust, and we are offering free replacement certificates through their existing customer portals. That process is well underway."

 

https://twitter.com/GossiTheDog/status/968834765888589825

 

AxOMun.png

 

qqi0ha.jpg

Edited by Arthur
Posted

:eek:

 

Trustico website goes dark after someone drops critical flaw on Twitter

 

The website for Trustico went offline on Thursday morning, about 24 hours after it was revealed that the CEO of the UK-based HTTPS certificate reseller emailed 23,000 private keys to a partner.

 

The website closure came shortly after a website security expert disclosed a critical vulnerability on Twitter that appeared to make it possible for outsiders to run malicious code on Trustico servers. The vulnerability, in a trustico.com website feature that allowed customers to confirm certificates were properly installed on their sites, appeared to run as root. By inserting commands into the validation form, attackers could call code of their choice and get it to run on Trustico servers with unfettered "root" privileges, the tweet indicated.

 

https://twitter.com/cujanovic/status/969229397508153350

 

qpeaOc.png

 

d0ioTr.jpg

Posted

They have made a monster of a mistake......

I am still waiting for my renewed cert. one minute its says processing on their site, the next thing its gone......

Posted

I am very tempted to do a CC charge back and get it from somewhere else

Been online chat queue for 1hr so far and 15th in the queue wait time approx 114minutes!

Posted

i believe we are still awaiting reissued certs / looked elsewhere (NM had the joy of dealing with this one)

someones head must have rolled for sending out the private keys surely

Posted
i think they provide a service where they generate private keys as part of issuing the cert if you dont provide it yourself/not able to generate one
Posted
i think they provide a service where they generate private keys as part of issuing the cert if you dont provide it yourself/not able to generate one

 

This is what happened, that alone is not the bad thing, what happened they sent the private keys via email..... WHY JUST WHY

Posted (edited)
I am very tempted to do a CC charge back and get it from somewhere else

Been online chat queue for 1hr so far and 15th in the queue wait time approx 114minutes!

 

If you could do this, I would. I personally would not be comfortable using certificates from a provider that had ever held on to private keys. They should never have had them in the first place, and despite putting "don't use in production" on the webpage for generating them, to my mind it's essentially maintaining a public nuisance to have a page like that at all.

 

This is what happened, that alone is not the bad thing, what happened they sent the private keys via email..... WHY JUST WHY

 

No, that is a terrible thing. Your certificate's private keys should remain privately held on the server that uses them. There's even a clue in the name.

 

They should never have generated private keys for customers in the first place. They should never have held on to private keys in the first place.

Edited by Roberto
  • 3 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...