In this episode we discuss the value for enterprises in running mass revocation drills and compare the merits of tabletop exercises versus voluntary revocation events.
Resource Library
Showing 1 to 18 of 21 resources
Deliberate delayed revocation weakens security and trust. Sectigo calls on CAs to prioritize immediate revocation and protect the integrity of the web PKI
An enterprise SSL subscriber recently used a Temporary Restraining Order to prevent the proper revocation of misissued certificates. We explain.
We detail mandatory revocation periods for leaf certificates and intermediates and explain when a 24-hour versus a 120-hour revocation deadline applies.
We discuss misuse of wildcard certificates, failure to revoke on time, and how these two failures magnify each other.
An epidemic of delayed revocations has infected the public CA community. We track delayed revocations since the beginning of 2021 and discuss root causes.
Digital certificates drive security. Lifecycle management, including revocation, prevents vulnerabilities. Understand its purpose and importance.
If you issue public certificates that are fully compliant except they don't reflect what your CPS says, are they misissued? Do they require revocation?
We explain the allowed public SSL revocation reason codes, along with some explicitly forbidden reason codes and the backstory behind them.
Concerns recently have been raised about OCSP real-time certificate checking and its potential to violate privacy.
Research of public revocation information examines revocation behavior from public CAs. Listen for the main takeaways and "revocation transparency."
Apple's Big Sur OS rollout drove a slowdown in the company's OCSP responders, affecting all Apple operating systems. We explain what happened and why.
14 public CAs have to revoke intermediates and destroy their keys, putting millions of active SSL, S/MIME, and other public certificates at risk.
Sectigo Blog
Security Flaw to Force Revocation of Intermediate Certificates from Major CAs; Sectigo Unaffected
Google has identified intermediate certificates from public CAs that violate CABF Baseline Requirements and pose security risk. Sectigo is unaffected.
One essential portion of the certificate lifecycle is the ability to revoke certificates. Public SSL certificates use a pair of mechanisms to communicate this revocation status to client machines, CRL and OCSP. In this episode we explain how these…
Certificate revocation is an essential part of the certificate lifecycle. Join our hosts as they discuss revocation by the CA, code signing, and malware.
Following Chronicle’s study on signed malware registered on VirusTotal scanning service over a one-year period, Sectigo carried their own investigation to identify abused certificates and revoke them.
Recent reports of Comodo / Sectigo Code Signing certificates used for malware contain numbers that are difficult to understand and may lead to false conclusions. In this post we clarify the numbers behind the reported malware signing.
Need assistance?
Contact our team for help with your purchase or issuing your certificate.