<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ssl Archives - CritchCorp Computers Ltd</title>
	<atom:link href="https://www.cc-computers.com/tag/ssl/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.cc-computers.com</link>
	<description>Complete Computer Support</description>
	<lastBuildDate>Thu, 17 Aug 2023 06:50:46 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.cc-computers.com/wp-content/uploads/2020/07/favicon.ico</url>
	<title>ssl Archives - CritchCorp Computers Ltd</title>
	<link>https://www.cc-computers.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>3 million Let&#8217;s Encrypt certificates to be cancelled</title>
		<link>https://www.cc-computers.com/3-million-lets-encrypt-certificates-to-be-cancelled/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=3-million-lets-encrypt-certificates-to-be-cancelled</link>
					<comments>https://www.cc-computers.com/3-million-lets-encrypt-certificates-to-be-cancelled/#comments</comments>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Wed, 04 Mar 2020 10:04:29 +0000</pubDate>
				<category><![CDATA[Archive]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[CAA]]></category>
		<category><![CDATA[flaw]]></category>
		<category><![CDATA[Let's Encrypt]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[ssl]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=2207</guid>

					<description><![CDATA[<p>Let&#8217;s Encrypt revoked certificates Let&#8217;s Encrypt has announced that it is to revoke aroound 3 million TLS/SSL certificates because of a serious flaw found in the CAA (Certificate Authority Authorization). The certificates will be revokend on the 4th March 2020 from 00:00 UTC. Let&#8217;s Encrypt has around 116 million certificates issued at the moment which [&#8230;]</p>
The post <a href="https://www.cc-computers.com/3-million-lets-encrypt-certificates-to-be-cancelled/">3 million Let’s Encrypt certificates to be cancelled</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<h2>Let&#8217;s Encrypt revoked certificates</h2>
<p>Let&#8217;s Encrypt has announced that it is to revoke aroound 3 million TLS/SSL certificates because of a serious flaw found in the CAA (Certificate Authority Authorization). The certificates will be revokend on the 4th March 2020 from 00:00 UTC.<span id="more-2207"></span></p>
<p>Let&#8217;s Encrypt has around 116 million certificates issued at the moment which means that around 2.6% of them are to be revoked. Sites that have not reissued their certificates will find that users will be unlikely to visit them as they will be warned when trying to visit that the site is likely to be fake or compromised as the certificate has been revoked.</p>
<p>A revoked certificate is far worse from a security point of view for users as it shows that positive action has been taken to make users aware that the certificate has been tagged as &#8220;<strong>Not to be trusted</strong>&#8220;.</p>
<h2>How can you fix it?</h2>
<p>If you own a website that uses Let&#8217;s Encrypt, an automated free certificate system, then you should get your certificate changed ASAP. It is free and easy to do. There is a list of the affected certificate serial numbers which can be downloaded <a href="https://d4twhgtvn0ff5.cloudfront.net/caa-rechecking-incident-affected-serials.txt.gz">here</a> and there is a tool that you can use to check your site <a href="https://checkhost.unboundtest.com/">here</a>. Let&#8217;s Encrypt has sent an email notification to those that have registered an email address whith them but many are thought to be out of date and to be that of their hosting provider. If you are unsure please use the tools to check your site yourself.</p>
<h2>Our clients who use Let&#8217;s Encrypt</h2>
<p>CritchCorp Computers Ltd has already checked all of our clients sites that use Let&#8217;s Encrypt certificates; which come FREE with any of our Feature Rich Hosting accounts. Also anyone using a paid certificate from CritchCorp Computers Ltd is not affected by this latest issue.</p>
<p>If you are affected then you should contact your hosting company or webmaster urgently to get the issue resolved. If you have no-one to contact then we maybe able to help, please submit a support ticket from <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=3">our store ticket system</a>.</p>
<h2>Is Let&#8217;s Encrypt still good?</h2>
<p>We have been asked whether or not Let&#8217;s Encrypt certificates are safe given the latest bug. We are confident that they are a great starter certificate and are much better than having no certificate. Let&#8217;s Encrypt have been upfront and transparent about the issue and that is exactly what they should do, so we are confident that they ACME system is a good way to ensure that all sites have some form of security. If your site need better security or more gurentees about who you are and better protection then you should upgrade to a paid certificate whch come with different levels of security and guarentees.</p>
<p>Stay Safe</p>
<p>Support.</p>


<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<h2 class="wp-block-heading" id="h-don-t-forget-to-checkout-these-other-products-too">Don&#8217;t forget to check out these other Products too</h2>



<div class="wp-block-blockspare-blockspare-list aligncenter blockspare-393e5569-01e3-4 blockspare-block-iconlist-wrap" blockspare-animation=""><style>.blockspare-393e5569-01e3-4 .blockspare-list-wrap{border-radius:0px;margin-top:30px;margin-bottom:30px;padding-top:0px;padding-right:0px;padding-bottom:0px;padding-left:0px}.blockspare-393e5569-01e3-4 .blockspare-list-wrap .listDescription li{color:#404040;text-align:left;font-size:16px}.blockspare-393e5569-01e3-4 .blockspare-list-wrap .listDescription li:before{color:#404040}.blockspare-393e5569-01e3-4 .listDescription li:before{font-size:14px}@media screen and (max-width:1025px){.blockspare-393e5569-01e3-4 .blockspare-list-wrap .listDescription li{font-size:14px}.blockspare-393e5569-01e3-4 .listDescription li:before{font-size:14px}}@media screen and (max-width:768px){.blockspare-393e5569-01e3-4 .blockspare-list-wrap .listDescription li{font-size:14px}.blockspare-393e5569-01e3-4 .listDescription li:before{font-size:14px}}</style><div class="blockspare-blocks blockspare-list-wrap blockspare-hover-item"><ul class="blockspare-list-arrow-right listDescription"><li><a href="https://www.cc-computers.com/critchcorp-smart-light-bulb/">CritchCorp Smart™ Light Bulbs</a></li><li><a href="https://www.cc-computers.com/incense/">Resin Incense</a></li><li><a href="/subscribe-and-save/">NEW: Subscribe and Save</a></li><li><a href="https://store.cc-computers.com/collections/all-subscribe-and-save-items" target="_blank" rel="noreferrer noopener">NEW: Subscribe and Save Collections</a></li><li><a href="https://www.cc-computers.com/free-hosting/">Free Hosting</a></li><li><a href="https://www.cc-computers.com/feature-rich-hosting-cpanel/">Feature Rich Hosting</a></li><li><a href="https://www.cc-computers.com/wordpress/">WordPress Hosting</a></li><li><a href="https://www.cc-computers.com/website-security/">Website Security</a></li><li><a href="https://www.cc-computers.com/cloud-services/cloud-email/">Cloud eMail</a></li><li><a href="https://www.cc-computers.com/cloud-services/cloud-files-data-backup-and-collaboration/">Cloud Sharing &amp; backup</a></li><li><a href="https://www.cc-computers.com/cloud-services/cloud-sharepoint/">Cloud Share Point</a></li><li><a href="https://www.cc-computers.com/phone-and-internet/">Internet &amp; VoIP</a></li></ul></div></div>



<p>You can also read more <a href="https://www.cc-computers.com/about-critchcorp-computers-ltd/">about us</a> and the products and services we offer.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>The post <a href="https://www.cc-computers.com/3-million-lets-encrypt-certificates-to-be-cancelled/">3 million Let’s Encrypt certificates to be cancelled</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.cc-computers.com/3-million-lets-encrypt-certificates-to-be-cancelled/feed/</wfw:commentRss>
			<slash:comments>59</slash:comments>
		
		
			</item>
		<item>
		<title>Apple reduces SSL/TLS certificates accepted lifespan to 1 year</title>
		<link>https://www.cc-computers.com/apple-reduces-ssl-tls-certificates-accepted-lifespan-to-1-year/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=apple-reduces-ssl-tls-certificates-accepted-lifespan-to-1-year</link>
					<comments>https://www.cc-computers.com/apple-reduces-ssl-tls-certificates-accepted-lifespan-to-1-year/#comments</comments>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Thu, 20 Feb 2020 22:13:37 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[trust]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=2201</guid>

					<description><![CDATA[<p>What has Apple done Apple has decided that they will no longer support TLS/SSL certificates that have a valid period of more than 1 year (398 days to be exact) as of 1st September 2020. This means that if, after that date, you order a certificate for your website that has a longer valid period [&#8230;]</p>
The post <a href="https://www.cc-computers.com/apple-reduces-ssl-tls-certificates-accepted-lifespan-to-1-year/">Apple reduces SSL/TLS certificates accepted lifespan to 1 year</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<h2>What has Apple done</h2>
<p>Apple has decided that they will no longer support TLS/SSL certificates that have a valid period of more than 1 year (398 days to be exact) as of 1st September 2020. This means that if, after that date, you order a certificate for your website that has a longer valid period then it will not be trusted on any Apple system, including iPhones, iPads, Apple computers, Safari, etc.<br />
The policy that was unveiled at a Certificate Authority Browser Forum (CA/Browser) meeting on Wednesday (19/02/2020). Accordingly certificates issued after 1st September 2020 will not be trusted if they are longer than 1 year (398 days) but those that were issued before that date will still be honoured.<span id="more-2201"></span></p>
<h2>Why have they done this</h2>
<p>The move by Apple to not trust certificates longer than the 398 days is a move to make internet users safer on their platforms. This means that website admins will need to change their certificates on a yearly basis. This has it benefits and drawbacks as it means that technical expertise will be needed more frequently and that there is more chance for expiry dates to be forgotten but it does mean that old forgotten certificates will expire quicker and certificates will be using the latest up-to-date cryptographic standards.<br />
There has been a call for more moving to automated systems rather than manual certificates. Whilst we use automated systems or ACME (Automated Certificate Management Environment), specifically Let’s Encrypt and those systems are great for a certain type of site, it is still necessary to have the higher grade certificates for those who need them. In fact larger websites still use professional certificates with stronger encryption and authentication mechanisms in place. ACME certificates are great as a base level certificate in these days when a website will not be trusted at all if it doesn’t have a certificate, in fact if it doesn’t have a certificate most browsers will actively block access to it.</p>
<p>Digicert’s Dean Coclin issued a memo, here is an excerpt:</p>
<blockquote><p>“At one time, certificates were offered with a maximum validity of three years. A few years ago, they were reduced to two years. Fast forward to this week’s Apple announcement, which ultimately does what ballot SC22 failed to do: reduce certificate lifetimes to one year.<br />
Why did Apple unilaterally decide to enforce a shorter certificate lifetime? Their spokesperson said it was to “protect users.” We know from prior CA/B Forum discussions that longer certificate lifetimes proved to be challenging in replacing certificates, in the case of a major security incident. Apple clearly wants to avoid an ecosystem that cannot quickly respond to major certificate-related threats. Short-lived certificates improve security because they reduce the window of exposure if a TLS certificate is compromised. They also help remediate normal operational churn within organizations by ensuring yearly updates to identity such as company names, addresses and active domains. As with any improvement, shortening of lifetimes should be balanced against the hardship required of certificate users to implement these changes.&#8221;</p>
<p>&#8230; &#8220;DigiCert agrees that shorter lifetimes help enhance the security of the ecosystem and has the tools necessary to help our customers automate the certificate lifecycle process. We support short-lived certificates, with lifetimes as short as a few hours for customers with advanced automation capabilities. Additionally, our CertCentral platform includes the ability to schedule and automate replacement of EV, OV and DV certificates. Using CertCentral admins may take advantage of continuous discovery, renewal notices, thorough API integration and documentation, as well as support for orchestration layers. CertCentral also allows for multi-year purchases to smooth planning and 24/7 global support enabling the best experience in the industry.<br />
As certificate validity periods continue to decrease, automation will be a must for organizations’ ability to manage shorter lifetimes. DigiCert is prepared with the industry’s most advanced and reliable tools to help our customers take the necessary steps toward greater use of automation.”</p></blockquote>The post <a href="https://www.cc-computers.com/apple-reduces-ssl-tls-certificates-accepted-lifespan-to-1-year/">Apple reduces SSL/TLS certificates accepted lifespan to 1 year</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.cc-computers.com/apple-reduces-ssl-tls-certificates-accepted-lifespan-to-1-year/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
			</item>
		<item>
		<title>New TLDs added</title>
		<link>https://www.cc-computers.com/new-tlds-added/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-tlds-added</link>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Wed, 05 Sep 2018 18:00:35 +0000</pubDate>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Informational]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[black]]></category>
		<category><![CDATA[blue]]></category>
		<category><![CDATA[New]]></category>
		<category><![CDATA[pet]]></category>
		<category><![CDATA[pink]]></category>
		<category><![CDATA[pro]]></category>
		<category><![CDATA[promo]]></category>
		<category><![CDATA[red]]></category>
		<category><![CDATA[space]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[SSL certificates]]></category>
		<category><![CDATA[TLDs]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=988</guid>

					<description><![CDATA[<p>Just a quick note to let everyone know that we have added some new Top Level Domains to our shop. They are: .space .black .blue .pet .pink .pro .promo .red If there is a TLD that you want and it is not in our shop, let us know and we will see if we can [&#8230;]</p>
The post <a href="https://www.cc-computers.com/new-tlds-added/">New TLDs added</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p>Just a quick note to let everyone know that we have added some new Top Level Domains to our shop. They are:</p>
<ul>
<li>.space</li>
<li>.black</li>
<li>.blue</li>
<li>.pet</li>
<li>.pink</li>
<li>.pro</li>
<li>.promo</li>
<li>.red</li>
</ul>
<p>If there is a TLD that you want and it is not in our shop, let us know and we will see if we can add it, and maybe give you a discount on a new domain name on that TLD as a &#8220;thank you&#8221; recommending it.</p>
<p>Also there have been some price increases this month. You can see the current prices <a href="https://shop.cc-computers.com/cart.php?a=add&amp;domain=register">here</a>.</p>
<p>[ink-ad-creator ad=&#8221;981&#8243;][/ink-ad-creator]</p>The post <a href="https://www.cc-computers.com/new-tlds-added/">New TLDs added</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
