TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Quick non technical question about Heartbleed Bug

7 点作者 jsanroman大约 11 年前
Do we have to pay to reissue our SSL certificates? If we do then this is the best thing that happened to the SSL certificate vendors and they have all the incentive to be vulnerable

2 条评论

patio11大约 11 年前
No, you should not have to pay to get an SSL certificate <i>rekeyed</i>. Some providers may ask for money if you want to <i>revoke</i> the cert, if -- for example -- you believe your private keys may have been compromised and you want people&#x27;s browsers to go nuts if they see that cert in the future, at (for example) a site attempting to MITM you.
评论 #7573473 未加载
rdl大约 11 年前
This depends on which CA you&#x27;re using. Some do not have a way to reissue&#x2F;rekey at arbitrary times (StartCom, in particular), and charge for revocation. Most allow free reissue, and often don&#x27;t charge for revocation and replacement issue.
评论 #7573475 未加载