TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Quick non technical question about Heartbleed Bug

7 pointsby jsanromanabout 11 years ago
Do we have to pay to reissue our SSL certificates? If we do then this is the best thing that happened to the SSL certificate vendors and they have all the incentive to be vulnerable

2 comments

patio11about 11 years ago
No, you should not have to pay to get an SSL certificate <i>rekeyed</i>. Some providers may ask for money if you want to <i>revoke</i> the cert, if -- for example -- you believe your private keys may have been compromised and you want people&#x27;s browsers to go nuts if they see that cert in the future, at (for example) a site attempting to MITM you.
评论 #7573473 未加载
rdlabout 11 years ago
This depends on which CA you&#x27;re using. Some do not have a way to reissue&#x2F;rekey at arbitrary times (StartCom, in particular), and charge for revocation. Most allow free reissue, and often don&#x27;t charge for revocation and replacement issue.
评论 #7573475 未加载