JRA Posted April 19, 2018 Posted April 19, 2018 I sure did! Comodo certs now. Have a read if not: https://www.theregister.co.uk/2018/02/07/beware_the_coming_chrome_certificate_apocalypse/ Bleh, first Dale Winton and now this. What a day.
ADMaster Posted April 19, 2018 Posted April 19, 2018 I had a skim of the new v66 gpos and saw a policy to continue trusting them if you want. https://www.chromium.org/administrators/policy-list-3#EnableSymantecLegacyInfrastructure 1
JRA Posted April 20, 2018 Author Posted April 20, 2018 Cheers, yes I saw that too. It'd 'do' for use on site for sure (well, until the world becomes either full of spoofed certs or this all blows over by Christmas ofc) but it won't help the parents dramatically stabbing at the website and phoning reception full of frenzied cyber-paranoia. Worth having those GPOs in mind though.
Opendium_Steve Posted April 23, 2018 Posted April 23, 2018 Did Symmantec not contact all of their customers? Seems pretty poor if not - this was announced 7 months ago. For what it's worth, FireFox will also distrust Symmantec certificates from next month.
SimonHooker Posted April 23, 2018 Posted April 23, 2018 This definitely came up last year. Was very annoying as I had, the week before, ordered another 10 certificates because I was bored of buying them one by one, all 3 year certificates which have since been discontinued. If it were viable I would definitely have looked to switch over to Let's Encrypt and may yet do so. As it stands Comodo certificates will do nicely certainly JRA
Opendium_Steve Posted April 23, 2018 Posted April 23, 2018 This definitely came up last year. Was very annoying as I had, the week before, ordered another 10 certificates because I was bored of buying them one by one, all 3 year certificates which have since been discontinued. Out of interest, will Symmantec refund you for certificates that are no longer trusted? It is, after all, their fault that everyone is distrusting them...
Arthur Posted April 23, 2018 Posted April 23, 2018 (edited) Did Symantec not contact all of their customers? Google gave a whole years notice... www.edugeek.net/forums/news/181855-google-chrome-stop-trusting-all-symantec-issued-tls-certificates.html Edited April 23, 2018 by Arthur
5tu Posted April 23, 2018 Posted April 23, 2018 This definitely came up last year. Was very annoying as I had, the week before, ordered another 10 certificates because I was bored of buying them one by one, all 3 year certificates which have since been discontinued. My cert supplier (SSL247) just reissued my Symantec certificate free of charge. The new certificate is simply issued by different/updated Intermediate and Root certs. More info here - https://www.digicert.com/replace-your-symantec-ssl-tls-certificates/
SimonHooker Posted April 25, 2018 Posted April 25, 2018 (edited) Out of interest, will Symmantec refund you for certificates that are no longer trusted? It is, after all, their fault that everyone is distrusting them... The affected certificates were bought via SSLs.com I think, something like that. They refunded the certificates which had not been validated. Existing certificates were able to be reissued however the few we had were up for renewal shortly after and so we decided to simply change to Comodo at that point instead of mess around with Symantec. Some of our sites do use Letsencrypt already, I just need to find a way to integrate it with some other bits before I can make use of it globally Edited April 25, 2018 by SimonHooker
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now