<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: rapidssl]]></title>
    <link>http://securityratty.com/tag/rapidssl</link>
    <description></description>
    <pubDate>Sat, 17 May 2008 03:20:37 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Free Certificate Reissuance From VeriSign]]></title>
      <link>http://securityratty.com/article/efb481208ef9b0e30c0410f3cd14b3f4</link>
      <guid>http://securityratty.com/article/efb481208ef9b0e30c0410f3cd14b3f4</guid>
      <description><![CDATA[Owing to the recent severe bug in Debian's OpenSSL implementation , VeriSign is offering free reissuance of certificates . Patching the flawed software is not enough: certificates containing public...]]></description>
      <content:encoded><![CDATA[Owing to <a href="http://blogs.eweek.com/cheap_hack/content/networking/debian_openssl_blunder_1.html">the recent severe bug in Debian's OpenSSL implementation</a>, VeriSign is offering <a href="https://blogs.verisign.com/ssl-blog/2008/05/the_debian_keypairs_security_f.html">free reissuance of certificates</a>.

Patching the flawed software is not enough: certificates containing public keys generated by the buggy versions of OpenSSL have to be revoked and replaced with new copies generated by fixed versions of the software. For customers of trusted certificate authorities this also means having the CA resign the certificate.

CAs normally charge for revoking and replacing certificates, but because a software error is involved, VeriSign is not charging for revocation and replacement of VeriSign, Thawte, GeoTrust, and RapidSSL SSL Certificates. <a href="https://blogs.verisign.com/ssl-blog/2008/05/free_reissuance_for_code_signi.html">This includes code signing certificates</a> as well as SSL certificates.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=cb0b9ea4ec60ffbcea3529d565a3e672" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=cb0b9ea4ec60ffbcea3529d565a3e672" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/292238908" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 17 May 2008 03:20:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/verisign">verisign</category>
      <category domain="http://securityratty.com/tag/software error">software error</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/rapidssl ssl">rapidssl ssl</category>
      <category domain="http://securityratty.com/tag/openssl implementation">openssl implementation</category>
      <category domain="http://securityratty.com/tag/recent severe bug">recent severe bug</category>
      <category domain="http://securityratty.com/tag/openssl">openssl</category>
      <category domain="http://securityratty.com/tag/ssl">ssl</category>
      <category domain="http://securityratty.com/tag/buggy versions">buggy versions</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/292238908/free_certificate_reissuance_from_verisign_1.html">Free Certificate Reissuance From VeriSign</source>
    </item>
  </channel>
</rss>
