Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Reminder that halting issuance is a recommended action during an incident & trustworthy CAs will do it early, until the problem is conclusively identified and remediated.

Reminder that halting issuance is a recommended action during an incident & trustworthy CAs will do it early, until the problem is conclusively identified and remediated.

Scheduled Pinned Locked Moved Uncategorized
3 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • cpu@hachyderm.ioC This user is from outside of this forum
    cpu@hachyderm.ioC This user is from outside of this forum
    cpu@hachyderm.io
    wrote last edited by
    #1

    Reminder that halting issuance is a recommended action during an incident & trustworthy CAs will do it early, until the problem is conclusively identified and remediated.

    This happens for both for true "oh-shit" events, and "cross your t's dot your i's" compliance issues and you can't infer which bucket the incident is in just because issuance has stopped.

    See
    https://wiki.mozilla.org/CA/Responding_To_An_Incident#Immediate_Actions

    cpu@hachyderm.ioC 1 Reply Last reply
    1
    0
    • cpu@hachyderm.ioC cpu@hachyderm.io

      Reminder that halting issuance is a recommended action during an incident & trustworthy CAs will do it early, until the problem is conclusively identified and remediated.

      This happens for both for true "oh-shit" events, and "cross your t's dot your i's" compliance issues and you can't infer which bucket the incident is in just because issuance has stopped.

      See
      https://wiki.mozilla.org/CA/Responding_To_An_Incident#Immediate_Actions

      cpu@hachyderm.ioC This user is from outside of this forum
      cpu@hachyderm.ioC This user is from outside of this forum
      cpu@hachyderm.io
      wrote last edited by
      #2

      Also you're renewing your certs early, based on some proportion of their total validity period right?

      And using ACME, so it's automated and easy to fail-over to a standard's compliant alternative CA, right??

      And using ARI so you're informed when you need to re-issue sooner than expected because of a compliance issue, right???

      And back-stopping all of the above with monitoring, right????

      tay@tech.lgbtT 1 Reply Last reply
      0
      • cpu@hachyderm.ioC cpu@hachyderm.io

        Also you're renewing your certs early, based on some proportion of their total validity period right?

        And using ACME, so it's automated and easy to fail-over to a standard's compliant alternative CA, right??

        And using ARI so you're informed when you need to re-issue sooner than expected because of a compliance issue, right???

        And back-stopping all of the above with monitoring, right????

        tay@tech.lgbtT This user is from outside of this forum
        tay@tech.lgbtT This user is from outside of this forum
        tay@tech.lgbt
        wrote last edited by
        #3

        @cpu i put certbot in the crontab and hope it doesn't blow up 🙂

        1 Reply Last reply
        0
        • R relay@relay.publicsquare.global shared this topic
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • World
        • Users
        • Groups