Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This actually happened recently and some older stuff stopped working. there's a write up here: https://www.namecheap.com/blog/sectigo-ssl-certificate-root-...


That blog article is a poor explanation of the issue.

The root CA from namecheap was expiring. They tried to recreate it, only changing the date, to continue to issue certificates to customers with it the same way.

They hoped users/systems would accept their newer CA automatically after the old CA expired. CA are additive, there are many configured on a system, it's standard practice to add more by keeping existing ones and adding new ones.

This blew up in their face monumentally because having two identical CA is conflicting. Things failed to verify after the original CA expired.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: