[Dshield] Digital certificates
afrayer at frayernet.com
Thu Oct 21 12:51:43 GMT 2004
On Thu, 2004-10-21 at 03:38, Stephane Grobety wrote:
> AF> What is the effect of an expired certificate, both on the hosting site
> AF> and on the browser that encounters it?
> Well, the question, as such, doesn't make a whole lot of sense. The
> only meaningful answer would be: it depends what you use the
> certificate for, why you sign with it. what software you used to
> sign and verify that signature and how you have setup these programs.
Yes, I could have been more specific. Our client uses a certificate to
provide security in an SSL credit card transaction. They are in the
process of building a new web site, using a different host and the
certificate on the current host may expire before the new site is ready.
Rather than recommend paying to renew a certificate which will only be
needed for a month or so, I'm contemplating a recommendation to leave
the expired certificate in place, and to notify anyone who inquires
about the upcoming site change. I just wanted to be sure such a
recommendation wouldn't "break" the site.
Alan Frayer, CNE, CNI, CIW CI, MCP, Net+ - afrayer at frayernet.com
Member: Independent Consultants Association (ICA)
Consultants - FREE Directory Listing - http://www.ica-assn.org
More information about the list