SHimmer45 Posted February 28, 2018 Posted February 28, 2018 For people who might have had confusing emails regarding SSL certs issued via Trustico / RapidSSL/Digicert
mrbios Posted February 28, 2018 Posted February 28, 2018 I got affected by this, fortunately trustico sent out emails with a coupon to redeem a new certificate for free....and thankfully i updated my documentation 3 months ago with all the locatiosn i have to update for a certificate replacement
Arthur Posted February 28, 2018 Posted February 28, 2018 (edited) https://www.digicert.com/blog/digicert-statement-trustico-certificate-revocation/ "Trustico requested revocation of their Symantec, GeoTrust, Thawte and RapidSSL certificates, claiming the certificates were compromised. When we asked for proof of the "compromise", Trustico did not provide details on why they were requesting the immediate revocation. Trustico’s CEO indicated that Trustico held the private keys for those certificates, and then emailed us approximately 20,000 certificate private keys. When he sent us those keys, his action gave us no choice but to act in accordance with the CA/Browser Forum Baseline Requirements, which mandate that we revoke a compromised certificate within 24 hours. As a CA, we had no choice but to follow the Baseline Requirements. Following our standard revocation process, we gave notice via email to each certificate holder whose private keys had been exposed to us by Trustico, so they could have time to get a replacement certificate. In communications today, Trustico has suggested that this revocation is due to the upcoming Google Chrome distrust of Symantec roots. That is incorrect. We want to make it clear that the certificates needed to be revoked because Trustico sent us the private keys; this has nothing to do with future potential distrust dates. The upcoming Chrome distrust situation is entirely separate. We are working closely to help customers with certificates affected by the browser distrust, and we are offering free replacement certificates through their existing customer portals. That process is well underway." https://twitter.com/GossiTheDog/status/968834765888589825 Edited February 28, 2018 by Arthur
Arthur Posted March 2, 2018 Posted March 2, 2018 Trustico website goes dark after someone drops critical flaw on Twitter The website for Trustico went offline on Thursday morning, about 24 hours after it was revealed that the CEO of the UK-based HTTPS certificate reseller emailed 23,000 private keys to a partner. The website closure came shortly after a website security expert disclosed a critical vulnerability on Twitter that appeared to make it possible for outsiders to run malicious code on Trustico servers. The vulnerability, in a trustico.com website feature that allowed customers to confirm certificates were properly installed on their sites, appeared to run as root. By inserting commands into the validation form, attackers could call code of their choice and get it to run on Trustico servers with unfettered "root" privileges, the tweet indicated. https://twitter.com/cujanovic/status/969229397508153350
wickit Posted March 5, 2018 Posted March 5, 2018 They have made a monster of a mistake...... I am still waiting for my renewed cert. one minute its says processing on their site, the next thing its gone......
clockend25 Posted March 5, 2018 Posted March 5, 2018 Bit confused. Have had our replacement certificate issued, but can't convert to PFX as this page is now not available: https://www.trustico.co.uk/ssltools/ssl-certificate-tools.php Was it that causing the issue in the first place I wonder?
wickit Posted March 5, 2018 Posted March 5, 2018 I am very tempted to do a CC charge back and get it from somewhere else Been online chat queue for 1hr so far and 15th in the queue wait time approx 114minutes!
Arthur Posted March 5, 2018 Posted March 5, 2018 I am very tempted to do a CC charge back and get it from somewhere else I would. I'd be very surprised if Trustico stay in business for much longer due to their incompetence! - - - Updated - - - but can't convert to PFX as this page is now not available: https://www.trustico.co.uk/ssltools/ssl-certificate-tools.php That's due to this... www.edugeek.net/forums/enterprise-software/193719-trustico-ssl.html#post1656108
SHimmer45 Posted March 5, 2018 Author Posted March 5, 2018 i believe we are still awaiting reissued certs / looked elsewhere (NM had the joy of dealing with this one) someones head must have rolled for sending out the private keys surely
jthompson Posted March 5, 2018 Posted March 5, 2018 Are they even meant to be storing private keys in the first place? (90% sure that that's a rhetorical question).
SHimmer45 Posted March 5, 2018 Author Posted March 5, 2018 i think they provide a service where they generate private keys as part of issuing the cert if you dont provide it yourself/not able to generate one
wickit Posted March 5, 2018 Posted March 5, 2018 i think they provide a service where they generate private keys as part of issuing the cert if you dont provide it yourself/not able to generate one This is what happened, that alone is not the bad thing, what happened they sent the private keys via email..... WHY JUST WHY
wickit Posted March 5, 2018 Posted March 5, 2018 Bit confused. Have had our replacement certificate issued, but can't convert to PFX as this page is now not available: https://www.trustico.co.uk/ssltools/ssl-certificate-tools.php Was it that causing the issue in the first place I wonder? Just got off chat https://www.onebricktech.com/ssltools/ssl-converter.php For those needing conversion
Roberto Posted March 5, 2018 Posted March 5, 2018 (edited) I am very tempted to do a CC charge back and get it from somewhere else Been online chat queue for 1hr so far and 15th in the queue wait time approx 114minutes! If you could do this, I would. I personally would not be comfortable using certificates from a provider that had ever held on to private keys. They should never have had them in the first place, and despite putting "don't use in production" on the webpage for generating them, to my mind it's essentially maintaining a public nuisance to have a page like that at all. This is what happened, that alone is not the bad thing, what happened they sent the private keys via email..... WHY JUST WHY No, that is a terrible thing. Your certificate's private keys should remain privately held on the server that uses them. There's even a clue in the name. They should never have generated private keys for customers in the first place. They should never have held on to private keys in the first place. Edited March 5, 2018 by Roberto
Arthur Posted March 23, 2018 Posted March 23, 2018 Statement from Trustico... Statement In Regard To DigiCert Revocation & Symantec Distrust
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now