Join the community today
Become a Member

SSL Google nullifies all Symantec EV SSL Certificates

Discussion in 'Domains, DNS, Email & SSL Certificates' started by eva2000, Mar 25, 2017.

  1. eva2000

    eva2000 Administrator Staff Member

    59,284
    12,509
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,141
    Local Time:
    5:38 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    Wow this is huge news in SSL certificate world in that Google has punished Symantec by nullifying all Symantec EV (Extended Validation) SSL certificates Google takes Symantec to the woodshed for mis-issuing 30,000 HTTPS certs [updated] !

    and eventually all Symantec SSL certificates will meet a similar fate !


     
  2. eva2000

    eva2000 Administrator Staff Member

    59,284
    12,509
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,141
    Local Time:
    5:38 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    Google Groups
     
  3. buik

    buik “The best traveler is one without a camera.”

    2,044
    527
    113
    Apr 29, 2016
    Flanders
    Ratings:
    +1,691
    Local Time:
    9:38 AM
    If its good or bad to you, your neighbor or anyone else, it does not matter.
    Fact is that Google has become way too powerful.
     
  4. BamaStangGuy

    BamaStangGuy Active Member

    669
    192
    43
    May 25, 2014
    Ratings:
    +272
    Local Time:
    2:38 AM
    It is a catch 22 for me. I love it. While I hate monopolies, I feel like they still remain on the better side of morals when it comes to large corporations and they continuously fight against the U.S. surveillance state.
     
  5. eva2000

    eva2000 Administrator Staff Member

    59,284
    12,509
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,141
    Local Time:
    5:38 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    indeed finding that balance

    But seriously Symantec mis-issuing 30,000 EV SSL certificates is crazy - that erodes the trust in the EV SSL process ! How should Symantec be penalised otherwise ?
     
  6. buik

    buik “The best traveler is one without a camera.”

    2,044
    527
    113
    Apr 29, 2016
    Flanders
    Ratings:
    +1,691
    Local Time:
    9:38 AM
    True but finding the balance is hard.
    Symantec should be penalized but now the genuine consumers are in fact screwed.
    Google is the same evil ... like almost all big techies.

    It gives a double feeling.
    A little bit of: It is a case of the pot calling the kettle black.
     
  7. eva2000

    eva2000 Administrator Staff Member

    59,284
    12,509
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,141
    Local Time:
    5:38 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    Yeah but I wonder how those companies paying for Symantec EV SSL certificates feel if some 3rd party managed to mis-issue and maliciously use a copy of their domains' EV SSL certificates ? Don't think the article states whether domain validated SSL certs have been mis-issued too though ? As a customer, I'd be moving off Symantec anyway for SSL certs.
     
  8. buik

    buik “The best traveler is one without a camera.”

    2,044
    527
    113
    Apr 29, 2016
    Flanders
    Ratings:
    +1,691
    Local Time:
    9:38 AM
    I'm curious how many customers say they go away and then really migrate the infrastructure afterwards.
    Symantec/VeriSign SSL is a big fish.

    Many large customers like Oracle and Governments with their complex solutions depends on Symantec/VeriSign SSL.
    You could migrate website SSL certs easy peasy but it does not apply of course to complex authentication mechanisms.
     
  9. Revenge

    Revenge Active Member

    469
    93
    28
    Feb 21, 2016
    Portugal
    Ratings:
    +354
    Local Time:
    8:38 AM
    1.9.x
    10.1.x
    Chrome is giving more than a year. Its more than enough for them to change to a more reliable company that issues certificates.
     
  10. Jimmy

    Jimmy Well-Known Member

    1,799
    391
    83
    Oct 24, 2015
    East Coast USA
    Ratings:
    +999
    Local Time:
    3:38 AM
  11. buik

    buik “The best traveler is one without a camera.”

    2,044
    527
    113
    Apr 29, 2016
    Flanders
    Ratings:
    +1,691
    Local Time:
    9:38 AM
    1 year is actual not that much.
    It's all about politics in cases like this.
    Nothing about the actual solutions created by engineers.

    Symantec Backs Its CA
     
    Last edited: Mar 25, 2017
  12. eva2000

    eva2000 Administrator Staff Member

    59,284
    12,509
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,141
    Local Time:
    5:38 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    Will be interesting to see how this all plays out either way !
     
  13. eva2000

    eva2000 Administrator Staff Member

    59,284
    12,509
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,141
    Local Time:
    5:38 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    wow Symantec just put their foot in their mouth again http://thehackernews.com/2017/03/symantec-ssl-certificates.html

    and to make it worse Symantec knew of this since 2015!
     
  14. eva2000

    eva2000 Administrator Staff Member

    59,284
    12,509
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,141
    Local Time:
    5:38 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
  15. eva2000

    eva2000 Administrator Staff Member

    59,284
    12,509
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,141
    Local Time:
    5:38 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    Google Groups

    still an uphill battle it seems

     
  16. eva2000

    eva2000 Administrator Staff Member

    59,284
    12,509
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,141
    Local Time:
    5:38 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    The end is near for Symantec ssl certificates Google to kill Symantec certs in Chrome 66, due in early 2018
     
  17. Andy

    Andy Active Member

    546
    90
    28
    Aug 6, 2014
    Ratings:
    +134
    Local Time:
    2:38 AM
    What SSL cert are you recommending George? I got my SSL from RapidSSL which is affected.
    Is it better to get a commercial ssl or just the free cert that can be generated with the centmin script?
     
  18. eva2000

    eva2000 Administrator Staff Member

    59,284
    12,509
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,141
    Local Time:
    5:38 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    As I resell paid SSL certificates, I provide my own for my own sites as well for Premium members Premium User Membership Explained (was at a discount back end though prices have come down on retail but not on wholesale heh).

    GGSSL/Comodo branded paid SSL certs but I only use paid SSL wildcard certs for *.domain.com as I has 100s of subdomains all covered by 1x SSL wildcard cert works out quite cheaply for ~US$40-80/yr

    But Centmin Mod free letsencrypt SSL certs do just fine too if you need domain validated (not wildcard ssl) SSL certs. Letsencrypt in Jan 2018 will start offering SSL wildcard certs too :)

    For existing Centmin Mod sites on 123.09beta01 Migrating Existing Nginx Vhost From HTTP to HTTP/2 based HTTPS With Letsencrypt SSL Certificates - you'd skip steps 7, 8 and 9 as you already have HTTPS default site and step 6 only need to replace your ssl cert and key paths with letsencrypt ones
     
  19. deltahf

    deltahf Premium Member Premium Member

    597
    273
    63
    Jun 8, 2014
    Ratings:
    +505
    Local Time:
    3:38 AM
    Just a friendly reminder to Centminmod users that starting December 1, if you used a certificate with a Symantec root certificate then Chrome's Inspector console shows the following warning on all of your pages:

    warning.jpg

    Here is the link referenced in this warning.

    I use RapidSSL, which used the Symantec root certificate, so this started happening on my site. To resolve, I just signed in to my GoGetSSL account and used their tools to re-issue my certificate. I then re-installed the certificate using my own SSL certificate re-installation guide (which now has over 2,100 views, I guess from Google searches, woo! :D).
     
  20. eva2000

    eva2000 Administrator Staff Member

    59,284
    12,509
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,141
    Local Time:
    5:38 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    thanks for heads up and yup your guide has some visitors :D