<Return to the list of news announcements

Let's Encrypt will revoke some TLS certificates from March 4 due to vulnerability?

Published on: March 6, 2020 13:20:16 Source: Kufanyun



March 5 news: Yesterday, Let's Encrypt sent an email to customers saying that it would revoke about 3 million TLS/TTS certificates from March 4. In this regard, Let's Encrypt recommends that the user replace the certificate in time, otherwise the visitor will jump to the security warning of certificate invalidation.

 timg.png

Let's Encrypt said in the email that the renewal process of the new certificate can be found in the ACME document. You can also check whether the certificate needs to be updated through official tools.


 172645e403ce58.jpg

In February this year, Let's Encrypt said that a vulnerability was found in CAA, which resulted in some certificates failing CAA authentication.


It is reported that CAA can allow domain administrators to create DNS records, which enable website owners to only authorize designated CA organizations to issue certificates for their own domain names, in order to prevent incorrect issuance of HTTPS certificates.


Data shows that Let's Encrypt is a free, automated and open certification authority (CA) provided by the Internet Security Research Group (ISRG), a non-profit organization, which provides free TLS certificates for websites.


Related recommendations

[Spring Festival Carnival] Domestic BGP 2-core 2G5M 0.8/day >>Click to view details<<

[Seckill Cloud Juhui] Server Seckill South Korea, America, 1 core, 2G3M, 138/year >>Click to view details<<

[OEM] Recruitment plan of Kupanyun free OEM cooperation system >>Click to view details<<