Distrusting certificates – Time to act if you use a StartCom (StartSSL) or WoSign certificate

Info: If you are using a certificate from StartCom (for example the free StartSSL certificate) or WoSign you should start switching to another certificate (from Let’s Encrypt or any other trusted one). Otherwise, your site will be marked as insecure an…


This content originally appeared on justmarkup and was authored by justmarkup

Info: If you are using a certificate from StartCom (for example the free StartSSL certificate) or WoSign you should start switching to another certificate (from Let’s Encrypt or any other trusted one). Otherwise, your site will be marked as insecure and might not be accessible to users in the next stable Version of Chrome (56) and Firefox (51) which will both be released at the beginning of 2017.

This month my SSL certificate from StartSSL for justmarkup.com had to be renewed. This task is normally done pretty quick and I didn’t expect any problem. Some days later I updated my Chrome to Version 56 and suddenly my site was marked as insecure and I had to explicitly allow it to access it.

Chrome 56 showing justmarkup.com as insecure because of a StartSSL certificate. Screenshot by  Anselm Hannemann

Chrome 56 showing justmarkup.com as insecure because of a StartSSL certificate. Screenshot by Anselm Hannemann

I tried to access it in other browsers, but they all showed the site as secure and after some debugging and trying to find the problem I came across an article by the Google security team. As you can read there, as of Chrome 56 (and also Firefox 51 as I later found out) certificates from StartCom (including their free StartSSL certificates) and WoSign will no longer be accepted and sites using them will be marked as insecure.

Before Let’s encrypt came out a lot of people got their certificate from StartCom as they were one of the only ones available for free. I expect a lot of people still use them and I hope they find out about the problem soon enough so their sites will still be available after the next stable releases.

Thanks to Anselm Hannemann for reminding me about the issue yesterday, so I finally took the time to switch servers and to Let’s Encrypt.


This content originally appeared on justmarkup and was authored by justmarkup


Print Share Comment Cite Upload Translate Updates
APA

justmarkup | Sciencx (2016-12-20T15:37:28+00:00) Distrusting certificates – Time to act if you use a StartCom (StartSSL) or WoSign certificate. Retrieved from https://www.scien.cx/2016/12/20/distrusting-certificates-time-to-act-if-you-use-a-startcom-startssl-or-wosign-certificate/

MLA
" » Distrusting certificates – Time to act if you use a StartCom (StartSSL) or WoSign certificate." justmarkup | Sciencx - Tuesday December 20, 2016, https://www.scien.cx/2016/12/20/distrusting-certificates-time-to-act-if-you-use-a-startcom-startssl-or-wosign-certificate/
HARVARD
justmarkup | Sciencx Tuesday December 20, 2016 » Distrusting certificates – Time to act if you use a StartCom (StartSSL) or WoSign certificate., viewed ,<https://www.scien.cx/2016/12/20/distrusting-certificates-time-to-act-if-you-use-a-startcom-startssl-or-wosign-certificate/>
VANCOUVER
justmarkup | Sciencx - » Distrusting certificates – Time to act if you use a StartCom (StartSSL) or WoSign certificate. [Internet]. [Accessed ]. Available from: https://www.scien.cx/2016/12/20/distrusting-certificates-time-to-act-if-you-use-a-startcom-startssl-or-wosign-certificate/
CHICAGO
" » Distrusting certificates – Time to act if you use a StartCom (StartSSL) or WoSign certificate." justmarkup | Sciencx - Accessed . https://www.scien.cx/2016/12/20/distrusting-certificates-time-to-act-if-you-use-a-startcom-startssl-or-wosign-certificate/
IEEE
" » Distrusting certificates – Time to act if you use a StartCom (StartSSL) or WoSign certificate." justmarkup | Sciencx [Online]. Available: https://www.scien.cx/2016/12/20/distrusting-certificates-time-to-act-if-you-use-a-startcom-startssl-or-wosign-certificate/. [Accessed: ]
rf:citation
» Distrusting certificates – Time to act if you use a StartCom (StartSSL) or WoSign certificate | justmarkup | Sciencx | https://www.scien.cx/2016/12/20/distrusting-certificates-time-to-act-if-you-use-a-startcom-startssl-or-wosign-certificate/ |

Please log in to upload a file.




There are no updates yet.
Click the Upload button above to add an update.

You must be logged in to translate posts. Please log in or register.