» VIEW ALL POSTS May 19 2008   2:29PM GMT

VeriSign offering free re-issues of SSL certificates



Posted by: Dennis Fisher
Security, Information Security Threats

In response to the mess created by the OpenSSL vulnerability in Debian-based Linux distributions, the folks at VeriSign are offering to re-issue SSL certificates to any of its customers who believe their certificates may have been compromised. VeriSign officials say that none of the certificates issued by its brands, including GeoTrust, thawte, RapidSSL and VeriSign, is affected directly by the flaw, but customers who use one of the affected Linux distributions could have used that OS to generate key pairs for one of the certificates, which would in turn make the certificate vulnerable.

The implications of the OpenSSL flaw are far-reaching and security experts say that it’s difficult to know how many users are affected and whether there have been any widespread attacks exploiting the problem. But there have been some reports of isolated attacks, so it’s wise to update your certs and encryption keys as soon as you can.

Comment on this Post


You must be logged-in to post a comment. Log-in/Register

VeriSign offering free re-issues of SSL certificates  |   May 19 2008   5:18PM GMT

[...] Here is the original post: VeriSign offering free re-issues of SSL certificates [...]