home.social

#sectigo — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sectigo, aggregated by home.social.

fetched live
  1. #Sectigo maliciously revoked #RustDesk 's code signing certificate because #VirusTotal says two engines are marking it as malware. Sectigo only give them 24 hours to resolve the issue, but most antivirus companies needs few days to resolve the false positives.

    Now, all of the false positives are resolved, but Sectigo still no response for this incident for a week.

    x.com/rustdesk/status/19982351

    github.com/rustdesk/rustdesk/d

    virustotal.com/gui/file/4a3185

  2. #Sectigo wirft #GÉANT in marketing mails eine unfaire Darstellung der Situation vor, die zur einseitigen und vorzeitigen Kündigung der Verträge geführt hatte. Sie führen einerseits finanzielle Gründe auf, was sicher auch stimmen kann, behaubten aber in einem verlinkten PDF später folgendes:

    "Our decision to step away from GÉANT was guided by our responsibility to remain in full compliance with the CA/Browser Forum Baseline Requirements, as well as the
    root program policies established by major browser and operating system vendors, [...]"

    Spannende Formulierung. GÉANT hätte also, laut Sectigos Darstellung hier, mit ihrer fortlaufenden Nutzung der Sectigo Dienstleistungen gegen CA Richtlinien verstoßen? Oder Sectigo dazu genötigt, das zu tun? Da wäre ich wirklich mal an den Details interessiert. Anyone?

  3. #Sectigo wirft #GÉANT in marketing mails eine unfaire Darstellung der Situation vor, die zur einseitigen und vorzeitigen Kündigung der Verträge geführt hatte. Sie führen einerseits finanzielle Gründe auf, was sicher auch stimmen kann, behaubten aber in einem verlinkten PDF später folgendes:

    "Our decision to step away from GÉANT was guided by our responsibility to remain in full compliance with the CA/Browser Forum Baseline Requirements, as well as the
    root program policies established by major browser and operating system vendors, [...]"

    Spannende Formulierung. GÉANT hätte also, laut Sectigos Darstellung hier, mit ihrer fortlaufenden Nutzung der Sectigo Dienstleistungen gegen CA Richtlinien verstoßen? Oder Sectigo dazu genötigt, das zu tun? Da wäre ich wirklich mal an den Details interessiert. Anyone?

  4. Let's #Encrypt rolls out free IP address #certificates • The Register

    Let's Encrypt, a #CertificateAuthority (CA) known for its free TLS/SSL certificates, has begun issuing digital certificates for IP addresses.

    It's not the first CA to do so. #PositiveSSL , #Sectigo, and #GeoTrust all offer TLS/SSL certificates for use with IP addresses, at prices ranging from $40 to $90 or so annually. But Let's Encrypt does so at no cost.
    #security #tls #ssl #privacy

    theregister.com/2025/07/03/let

  5. Let's #Encrypt rolls out free IP address #certificates • The Register

    Let's Encrypt, a #CertificateAuthority (CA) known for its free TLS/SSL certificates, has begun issuing digital certificates for IP addresses.

    It's not the first CA to do so. #PositiveSSL , #Sectigo, and #GeoTrust all offer TLS/SSL certificates for use with IP addresses, at prices ranging from $40 to $90 or so annually. But Let's Encrypt does so at no cost.
    #security #tls #ssl #privacy

    theregister.com/2025/07/03/let

  6. Let's Encrypt, a #certificate authority (CA) known for its free #TLS/SSL certificates, has begun issuing digital certificates for #IP addresses.
    It's not the first #CA to do so. #PositiveSSL, #Sectigo, and #GeoTrust all offer TLS/SSL certificates for use with IP addresses, at prices ranging from $40 to $90 or so annually. But Let's Encrypt does so at no cost.
    theregister.com/2025/07/03/let

  7. Let's Encrypt, a #certificate authority (CA) known for its free #TLS/SSL certificates, has begun issuing digital certificates for #IP addresses.
    It's not the first #CA to do so. #PositiveSSL, #Sectigo, and #GeoTrust all offer TLS/SSL certificates for use with IP addresses, at prices ranging from $40 to $90 or so annually. But Let's Encrypt does so at no cost.
    theregister.com/2025/07/03/let

  8. So, issuing a #Sectigo Business #SSL certificate via #IONOS requires you to lie about your country of residence because the order form has a mandatory "German Bundesland" field no matter which country you select. I'm sure that's fine. 🤷‍♂️

  9. So, issuing a #Sectigo Business #SSL certificate via #IONOS requires you to lie about your country of residence because the order form has a mandatory "German Bundesland" field no matter which country you select. I'm sure that's fine. 🤷‍♂️

  10. @geant what a mess with #sectigo certificates

    How could a european research institute like #geant ever even think about signing a contract with a non EU provider?

  11. @geant what a mess with #sectigo certificates

    How could a european research institute like #geant ever even think about signing a contract with a non EU provider?

  12. Aus gegebenem Anlass:

    Das könnte für einige von euch eine gewisse Relevanz aufweisen: solltet ihr GÉANT-Zertifikate für für euch wichtige Dienste nutzen, solltet Ihr die unbedingt jetzt noch einmal erneuern, um mehr Spielraum zu haben. Es ist nämlich im Moment davon auszugehen, dass #Sectigo ab dem 10. Januar keine mehr ausstellen wird. Die #DFN-PKI Global ist aber nicht mehr und wird auch nicht wiederkommen.

    doku.tid.dfn.de/de:dfnpki:tcsf

  13. Aus gegebenem Anlass:

    Das könnte für einige von euch eine gewisse Relevanz aufweisen: solltet ihr GÉANT-Zertifikate für für euch wichtige Dienste nutzen, solltet Ihr die unbedingt jetzt noch einmal erneuern, um mehr Spielraum zu haben. Es ist nämlich im Moment davon auszugehen, dass #Sectigo ab dem 10. Januar keine mehr ausstellen wird. Die #DFN-PKI Global ist aber nicht mehr und wird auch nicht wiederkommen.

    doku.tid.dfn.de/de:dfnpki:tcsf

  14. Les #administrateurs #système sont furieux après qu'Apple a proposé une réduction « cauchemardesque » de la durée de vie des certificats #SSL/TLS, de 398 jours actuellement à seulement 45 jours d'ici à 2027

    Dans la pratique il faudrait automatiser le renouvellement de tous les certificats. #Sectigo, fournisseur de certificats, y trouve sont compte car vendant ce type d'outils

    Et pour les appliances difficiles ou impossible à automatiser ? On en parle ?

    securite.developpez.com/actu/3

  15. MARC.info cert verified by Sectigo Limited... If you hit something like that while fetching your favorite patches:
    '''
    TLS handshake failure: certificate verification failed: certificate has expired
    '''
    you should remove the AddTrust certificate from cert.pem.
    #workaround #sectigo #tls #ssl