Wonder how long before COMODO revokes this cert?
If you have a test domain you can stick it on CloudFlare and get a certificate for free without the private part becoming public.
Wonder how long before COMODO revokes this cert?
If you have a test domain you can stick it on CloudFlare and get a certificate for free without the private part becoming public.
> If you have a test domain you can stick it on CloudFlare and get a certificate for free without the private part becoming public.
It all comes down to the fact that CA's don't want you to sign your own certificates, even when it's one of your subdomains unless you pay the big bucks. Best thing to do it still to create your own CA and sign certs for these kinds of things since it's meant for testing and development anyway. It's not that hard, anyone can use some command line can do it.
If the people behind the post used anchor, then the issues mentioned here would be absolved.
And check out SSLmate https://sslmate.com/
Secure Connection Failed An error occurred during a connection to 52-0-56-137.sslip.io.
Peer's Certificate has been revoked.
It'll be gone in Chrome when the next CRLSet is fetched: https://scotthelme.co.uk/certificate-revocation-google-chrom...
Doesn't the CA forum baseline require a revocation if the private key is published?
https://cabforum.org/wp-content/uploads/CAB-Forum-BR-1.3.0.p... on page 18:
The CA SHALL revoke a Certificate within 24 hours
if one or more of the following occurs:
(...)
3. The CA obtains evidence that the Subscriber’s
Private Key corresponding to the Public Key in the
Certificate suffered a Key Compromise or no longer
complies with the requirements of Appendix A;Comodo website is not that good apparently.
Edit: in the document posted by brohee: (about authentication for certs revocation) "OR the Subscriber must be able to send an S/MIME email signed with the private key associated with the Certificate". That's doable :)
4.9.2 Who can Request Revocation A Subscriber or another appropriately authorized party can request revocation of a Certificate. An authorized party includes an RA, regardless of whether on behalf of the Subscriber may request revocation through their account. Other parties may report suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates, in the first instance, by email to sslabuse@comodo.com.
https://www.comodo.com/repository/Comodo_CA_CPS_4.1.4.pdf
4.9.1 Circumstances for Revocation Comodo may revoke a digital Certificate if any of the following occur:
A personal identification number, Private Key or password has, or is likely to become known to someone not authorized to use it, or is being or is likely to be used in an unauthorized way
BTW we love CloudFlare. But the DNS limitations (no wildcards for SSL without $$$$/month, only top-level subdomains allowed) really hurt for developing things. The wildcard bit I understand (valuable service), the multi-level hostnames I don't get; sounds like some technical issue? I know you just get a wildcard for the root, but even paid I've been told there's no workaround. So I can't do [stuff].test.example.com.
*.example.com won't match foo.bar.example.com.
That's a technical limitation of the way name matching works (similar to DNS); not a CloudFlare restriction.Our free Universal SSL certificate includes a wildcard (so if you sign up example.com you get *.example.com).
DNS wildcards only work when * is the leftmost label of a domain name, so
*.example.com is a wildcard
foo.*.example.com is not a wildcard
*bar.example.com is not a wildcard
A DNS wildcard matches any non-zero number of labels, so *.example.com
foo.example.com matches
foo.bar.example.com matches
example.com does not match
RFC 4592 describes DNS wildcards.Unlike the DNS, the * in a TLS certificate can only match one label, so
*.example.com
foo.example.com matches
foo.bar.example.com does NOT match
example.com does not match
RFC 2818 also allows the * to appear within a domain name, not just as the leftmost label, and wildcards work even when they are part of a label. One of its examples says f*.com
foo.com matches
bar.com does not match
But nowadays sub-label wildcards like this are not supported.I've never seen the option in the panel for this, and as far as I know only a handful of users got accepted into the 'beta'.
I set up Cloudflare with their "Strict" SSL option, which requires that my origin servers use a valid TLS certificate. I paid the CA toll to get a cert for my site, and I use that cert to serve connections from Cloudflare's servers.
They also have a "Full" option, which allows you to use a self-signed cert (with no validation -- you might be able to require validation of self-signed certs if you're on a paid plan) on your origin servers, which is slightly more secure than the "Flexible" option, which uses HTTP (with no encryption) when connecting to the origin server, even though it then serves the content to end users over HTTPS with their own (valid) cert.