Know How To Roll Your SSL Certificates
petekeen.net
petekeen.net
Well if you're a large bank or a heavyweight payment processor where an outage means lost $$$$ and not only $, you could easily have a few SSL certs from various root certs ready and roll one of them out once the sh*t hits the fan.
2) indeed have a backup certificate ready (might be non EV), this is especially a must if you use HSTS [1] (which you should use BTW) it is actually a (low priority) government recommendation (B5-6) in The Netherlands [2], but that might have something to do with the government heavily using DigiNotar which got compromised and had it root certificates revoked by Microsoft which caused some communication issues..
[1] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
[2] https://www.ncsc.nl/binaries/nl/dienstverlening/expertise-ad... (in Dutch)
https://github.com/psypete/public-bin/tree/public-bin/src/ne...
Just make a monthly recurring entry in your calendar that says "Check SSL certificates".
If you rely on your calendar, it's simpler to create an entry in your calender for changing the certificate a few days prior to its expiration date. Monthly reminders will be ignored too easily.I was honestly expecting them to reference a monitoring service. It is possible to do for free with Nagios if you have a Linux box kicking around on your network. There are also paid services who will monitor your certificates and send you a nice email when there is 30 days left to renew (including several SSL registers).
openssl req -nodes -newkey rsa:2048 -keyout www.example.com.2014.key -out www.example.com.2014.csr -subj "/C=COUNTRY/ST=STATE/L=CITY/O=COMPANY/OU=/CN=www.example.com"
I have exactly this in an Ansible playbook https://github.com/tilsammans/playbook (for rails). Process
- Know where your key is
- Know how to generate a new CSR from that key
It's adviced to use a NEW private key, in case there was a private key compromise you didn't know about.Also see https://www.ssllabs.com/downloads/SSL_TLS_Deployment_Best_Pr... (point 1.2).
BTW there is NO reason to regenerate the CSR if you reuse the private key.
Thanks!
Edit: updated
this would degrade the annoying message to a simple warning and probably make lots of hobbyist websites use only ssl.
(if you have to choose between annoy your user or just using plain http i guess many choose the later.)
I can have a basic SSL certificate in 15 minutes at the outside for like $8. My time at work is worth a lot more than $8/hr.