March 19, 2018 By Shane Schick 2 min read

The company that bought one of the largest certificate authorities (CAs) said it has nearly finished replacing the digital certificates most commonly used by popular websites as major browsers prepare to phase them out in upcoming releases.

DigiCert Inc. said it has been sending mass email messages, calling customers and running webinars to make sure website owners are aware that Google and Mozilla will no longer trust Symantec-backed digital certificates when they release Chrome 66 next month and Mozilla Firefox 60 in May. DigiCert, which bought the CA business from Symantec last fall, noted that more than 99 percent of the top 1 million websites have taken appropriate action.

Purging Outdated Digital Certificates

According to SecurityWeek, the browser-makers established deadlines to revoke trust in digital certificates in response to a series of errors in the way they were issued and managed. DigiCert set up a portal for customers to check their domain name to determine whether they need new or replacement certificates. Companies that used RapidSSL, GeoTrust and Thawte can also obtain replacements through DigiCert.

For all its progress, Enterprise Times raised questions about how DigiCert will manage to win over the remaining customers who had obtained digital certificates through Symantec and other providers. This includes not only the top websites, but also many small and medium-sized businesses (SMBs) that could be affected by the browsers’ deadlines.

A Bumpy Transition

The transition of the CA business from Symantec to DigiCert has not been entirely smooth. Earlier this month, CRN Australia reported that the website of Trustico, a Symantec reseller, temporarily went offline after DigiCert claimed it had emailed the private keys of more than 20,000 digital certificates, which were later revoked. According to TechTarget, DigiCert claimed that 23,000 certificates were compromised, although the number of individual organizations affected by the incident has not been publicly reported.

Recently, DigiCert set up a new reseller program to make it easier to obtain and deploy digital certificates within the enterprise. The program aims to help the CA’s partners take advantage of the opportunity offered by Secure Sockets Layer (SSL), public key infrastructure and Internet of Things (IoT) security.

More from

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

4 ways to bring cybersecurity into your community

4 min read - It’s easy to focus on technology when talking about cybersecurity. However, the best prevention measures rely on the education of those who use technology. Organizations training their employees is the first step. But the industry needs to expand the concept of a culture of cybersecurity and take it from where it currently stands as an organizational responsibility to a global perspective.When every person who uses technology — for work, personal use and school — views cybersecurity as their responsibility, it…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today