fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

#ssl

16 posts16 participants2 posts today

Does anyone know how this new SSL cert expiry date thing is going to affect things like user authentication with SSL certs, i.e. for openvpn.

If we're running our own CA, can I get safari, chrome et al to accept longer cert expiry?

#Linux#SSL#OpenVPN

Nur noch 47 Tage:

#Gültigkeit von #TLS - #Zertifikaten wird drastisch verkürzt

Ab 2029 dürfen #TLS-Zertifikate statt 398 nur noch höchstens 47 Tage lang gültig sein. Der von #Apple eingereichte Vorschlag hat breite Zustimmung erhalten.

Das #CA / #Browser #Forum hat beschlossen, die maximale Gültigkeitsdauer digitaler Zertifikate für den verschlüsselten Datenaustausch via #SSL / #TLS von aktuell 398 auf deutlich geringere 47 Tage zu reduzieren.

golem.de/news/nur-noch-47-tage

Golem.de · Nur noch 47 Tage: Gültigkeit von TLS-Zertifikaten wird drastisch verkürzt - Golem.deBy Marc Stöckel

Состав TLS-сертификата на примере «шестидневного» варианта от Let's Encrypt

Посмотрим, как устроен современный TLS-сертификат со "сверхкоротким" сроком действия. В статье описано значение основных полей и ряд неочевидных особенностей, с этими полями связанных - формат серийного номера, SCT-метки и другие занимательные элементы.

habr.com/ru/articles/901312/

ХабрСостав TLS-сертификата на примере «шестидневного» варианта от Let's EncryptПомимо перехода на "сверхкороткие" сертификаты, который быстро приближается, есть ещё несколько интересных новых моментов, связанных с TLS-сертификатами для веба. В феврале 2025 года Let's Encrypt...
Continued thread

Specific schedule:

March 15, 2026 - Cert validity (and Domain Control Validation) limited to 200 days.
March 15, 2027 - Cert validity (and Domain Control Validation) limited to 100 days.
March 15, 2029 - Cert validity limited to 47 days and Domain Control Validation limited to 10 days.

There's gonna be a lot of complaints about this in change control meetings over the next year200 days.

縮短 TLS certificate 的最長效期的投票 SC-081

在 Lobsters 上看到縮短 TLS certificate 最長效期的投票消息:「Mandatory short duration TLS certificates are probably coming soon」。 文章裡面有提到 mailing list 上的投票:「Voting Period Begins: SC-081v3: Introduce Schedule of Reducing Validity and Data Reuse Periods」,投票期間已經結束了,所以剛好可以算一下票數。 Certificate Consumers 端: YES (4):Google、Apple、Mozilla、Microsoft Certificate Issuer 端: YES…

blog.gslin.org/archives/2025/0

Gea-Suan Lin's BLOG · 縮短 TLS certificate 的最長效期的投票 SC-081在 Lobsters 上看到縮短 TLS certificate 最長效期的投票消息:「Mandatory short duration TLS certificates are probably coming soon」。 文章裡面有提到 mailing list 上的投票:「Voting Period Begins: SC-081v3: Introduce Schedule of Reducing Validity and Data Reuse Periods」,投票期間已經結束了,所以剛好可以算一下票數。 Certificate Consumers 端: YES (4):Google、Apple、Mozilla、Microsoft Cer...

Fortinet Response Addressing Post-Exploitation in FortiGate Devices via Symbolic Links

Fortinet FortiGate devices often run SSL - VPN services to allow remote access, especially in work from home environments or critical infrastructure. Recently, a new post exploitation method was discovered by Fortinet where attackers were able to maintain read only access to FortiGate devices even after organizations have applied official security patches. This is done using a symbolic link, which acts as a hidden shortcut between folders in the system which allowing the attacker to read sensitive files.

The attack begins with the exploitation of previously known vulnerabilities in Fortinet devices, including CVE-2022-42475, CVE-2023-27997, and possibly CVE-2024-21762. Once attackers gain access, they create a symbolic link between the user and root file systems. This symbolic link is hidden inside a directory that serves language files for SSL-VPN letting the attacker retain read only access to configuration files and other sensitive data even after patches are installed.

Pulse ID: 67fbba9f1b420d0f6d322448
Pulse Link: otx.alienvault.com/pulse/67fbb
Pulse Author: cryptocti
Created: 2025-04-13 13:22:39

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.