به Nostr بپیوندید
2026-05-09 11:09:37 UTC

kravietz 🦇 on Nostr: #LetsEncrypt has suspended issuing certificates after it identified security issues ...

#LetsEncrypt has suspended issuing certificates after it identified security issues in one of its roots (!)[^1]

> We temporarily disabled certificate issuance, deployed a configuration change to prevent future issuance from the cross-signed Gen Y hierarchy, and then re-enabled issuance. Certificate revocation and CRL generation remains functional for Gen Y certificates.

A few days ago #DigiCert was hacked with a Windows (!) screensaver (!)[^2]

I cannot but remind that both organisations are part of the #WebTrust cartel who had last year unrolled a massive "grassroots" smear campaign against EU #QWAC certificates, presenting them as "security and privacy threat", whereas from both legal and technical point of view QWAC is much more secure:

https://krvtz.net/en/posts/the-real-story-behind-eu-qwac.html

[^1]: https://community.letsencrypt.org/t/2026-05-08-gen-y-cross-certified-subordinate-cas-missing-serverauth-eku/247105

[^2]: https://cybersecuritynews.com/digicert-hacked-screensaver/