translation

This is an AI translated post.

해리슨 블로그

DigiCert Certificate Crisis: Urgent SSL/TLS Security Issue Requires Action Within 24 Hours

Select Language

  • English
  • 汉语
  • Español
  • Bahasa Indonesia
  • Português
  • Русский
  • 日本語
  • 한국어
  • Deutsch
  • Français
  • Italiano
  • Türkçe
  • Tiếng Việt
  • ไทย
  • Polski
  • Nederlands
  • हिन्दी
  • Magyar

Summarized by durumis AI

  • DigiCert has mistakenly issued some certificates due to a bug in the domain verification process, and has revoked and reissued those certificates.
  • Although the affected certificates are only about 0.4% of the total, immediate action is required for users to ensure website security.
  • Especially if you are using DigiCert's custom SSL/TLS certificates on cloud services like GCP, you need to check and reissue your certificates to maintain website security.

GCP Console

DigiCert announced (http://www.digicert.com/support/certificate-revocation-incident) that they would revoke certain certificates which were issued without proper Domain Control Validation. If you are affected by the issue, DigiCert will have sent a notification to your contact email address. You will see a CNAME revocation incident banner when you log in to CertCentral. To reissue/rekey your certificates, refer to the DigiCert announcement (http://www.digicert.com/support/certificate-revocation-incident). Once you have reissued the certificates, update your Google Cloud HTTP(S) Load Balancer configuration by following these instructions(https://cloud.google.com/load-balancing/docs/ssl-certificates/self-managed-certs). If you need additional help, please contact Google Cloud Support using https://cloud.google.com/support


Upon logging into GCP, I encountered a warning/notice message. After following the provided links and summarizing the information, the overall message was that DigiCert would be revoking certain certificates issued without proper domain control validation. While DigiCert claims a mere 0.4% of certificates are affected, this might not seem like a major issue at first glance.

It is likely that most cloud administrators utilize TLS certificates provided by their respective cloud vendors or Let's Encrypt certificates. Other cases may involve on-premises or custom certificates, but a widespread internet disruption is unlikely.

In general, here is a summary of the details:

1. Cause of the issue

DigiCert experienced a bug in their domain verification process where an underscore (_) was not added when using DNS CNAME records. This bug persisted from August 2019 until recently, and the root cause was the omission of a crucial security procedure during their system modernization process.

2. Scope of the impact

Approximately 0.4% of certificates issued by DigiCert have been affected by this issue. While this might appear to be a small percentage, considering the vast number of certificates used globally, a significant number of websites could be impacted.

3. Actions to be taken

Affected certificates must be revoked and reissued within 24 hours. This is a crucial measure for security reasons.

4. User response methods

  • Login to your CertCentral account and verify affected certificates.
  • Generate a new CSR (Certificate Signing Request).
  • Reissue and install the certificate.

5. Precautions for cloud service users

Users of GCP or other cloud services who utilize custom certificates from DigiCert could be directly affected by this issue and should take immediate action. If you are using default certificates from cloud providers or Let's Encrypt, you should be unaffected.

6. Future outlook

This incident serves as a reminder of the importance and complexity of digital certification. It is expected that certification authorities will implement stricter verification processes and system checks in the future.

In conclusion, while this DigiCert certificate issue is unlikely to cause significant disruption to the entire internet, it remains a critical matter for affected website administrators. Especially for those using custom SSL/TLS certificates within cloud services like GCP, it is crucial to immediately verify certificates and take necessary actions. This will ensure website security and provide users with safe services.

해리슨
해리슨 블로그
해리슨의 깜짝 블로그
해리슨
KT Hacking Incident: Man-in-the-Middle Attack at the National Telecommunications Network Level and its Impact The KT customer device hacking incident is a serious incident that requires a review of Korea's overall cybersecurity system, as it is a man-in-the-middle attack at the national telecommunications network level. KT directly hacked customers' PCs to steal

July 13, 2024

Troubleshooting Gemini Code Assist for VS Code
Troubleshooting Gemini Code Assist for VS Code If you are encountering an error with Gemini Code Assist v2.15.0 where you cannot connect to the authentication server, downgrading to the previous version v2.14.0 can resolve the issue.

July 26, 2024

Linksys Router Security Vulnerability Found: Risk of User Data Exposure Belgian consumer organization Testaankoop has discovered a serious security vulnerability in the Linksys Velop Pro 6E and 7 routers that sends user Wi-Fi login credentials unencrypted to Amazon servers. This could expose users to man-in-the-middle attacks

July 13, 2024

Sellease Launches 'SafeNoti', a Certificate, Subscription, and Service Expiry Notification Service Sellease has launched 'Sellease SafeNoti', a service that helps businesses manage their assets such as certificates, domains, and subscriptions in one place to prevent business interruption risks. It provides expiry notifications, integrated management, a
스타트업 커뮤니티 씬디스 (SeenThis.kr)
스타트업 커뮤니티 씬디스 (SeenThis.kr)
스타트업 커뮤니티 씬디스 (SeenThis.kr)
스타트업 커뮤니티 씬디스 (SeenThis.kr)

May 22, 2024

Using CDN with Google Cloud Storage and Cloud Run - 2 durumis uses Cloud Storage and Cloud Run in 8 regions around the world to provide fast service to global users. The required resources are pre-deployed in each region, and when a user requests, the resources are transmitted from the nearest region.
두루미스 기술 블로그
두루미스 기술 블로그
durumis uses Cloud Storage and Cloud Run in 8 regions around the world to provide fast service to global users. The required resources are pre-deployed in each region, and when a user requests, the resources are transmitted from the nearest region.
두루미스 기술 블로그
두루미스 기술 블로그

September 6, 2024

Serving Static Files Using Cloud Run - 1 This article describes how to improve web page delivery speed to increase the frequency of Google crawler visits. durumis provides services by deploying GKE in 8 regions worldwide, but to achieve faster speeds, we migrated some logic to Cloud Run. As a re
두루미스 기술 블로그
두루미스 기술 블로그
This article describes how to improve web page delivery speed to increase the frequency of Google crawler visits. durumis provides services by deploying GKE in 8 regions worldwide, but to achieve faster speeds, we migrated some logic to Cloud Run. As a re
두루미스 기술 블로그
두루미스 기술 블로그

September 4, 2024

Issuance of Family Register Certificates Suspended Nationwide in Japan Due to System Error On Monday, July 8th, issuance of family register certificates became impossible nationwide in Japan. The Ministry of Justice has stated that this issue is due to an error in the nationwide issuance system for family registers.
durumis AI News Japan
durumis AI News Japan
durumis AI News Japan
durumis AI News Japan

July 8, 2024

How to Cancel the Name Theft Prevention Service - mSafer 3-Second Solution The mSafer Name Theft Prevention Service can be canceled from PC, mobile, or telecom carrier branches. You need to verify your identity through Kakao Certificate or Pass Certificate.
후도리블로그
후도리블로그
후도리블로그
후도리블로그

August 26, 2024

KADOKAWA's cyber attack shuts down 'Niconico Video' service for over a month, new releases and reprints may be delayed Japanese major publisher KADOKAWA was hit by a ransomware attack, causing partial outages in its website, online shopping mall, book ordering and logistics system, accounting system, and more. While aiming to restore its core systems by the end of June, s
durumis AI News Japan
durumis AI News Japan
durumis AI News Japan
durumis AI News Japan

June 15, 2024