ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Expired VeriSign certificates cause confusion

Matt Loney ZDNet.co.uk

Published: 09 Jan 2004 13:59 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

VeriSign moved to allay confusion on Thursday after some of its certificates that verified it as a certificate-issuing authority expired.

Users have experienced problems when accessing SSL-encrypted pages on sites whose certification depended on VeriSign's own expired certificates.

The company said that older versions of its Intermediate Certificate Authority (CA) expired on 7 January. "As a result, users attempting to establish SSL session with sites that had not updated their CA certificates may start encountering error messages," said VeriSign in a statement. "There is no security danger, and users who ignore these error messages can successfully establish secure SSL connections. However, sites should update their CA certificates if they have not already done so, to avoid user confusion. No action is required on the part of end users."

VeriSign posted instructions on how to update certificates on its Web site.

Explaining the problem, VeriSign said that CA certificate expiration is a normal event that is considered best practice when issuing and managing certificates. "In anticipation of this expiration event, VeriSign changed to a new version of CA certificates in December of 2001. All SSL certificates issued by VeriSign since that date have been issued in conjunction with the newer CA certificates."

The company said that since 2001, it had taken steps to notify its customers of the situation and, with each communication, alert them to the expiration date and steps necessary to obtain a new Intermediate CA. However, some companies missed or ignored the warnings, resulting in error messages for users trying to access secure areas. VeriSign said it was taking additional actions to help those still experiencing difficulties. All employees in its client-services team have been made available to answer questions and walk customers through the process which, it said, will take only a short time and will not result in any disruption of service.

The issue is global, but UK customers can contact VeriSign's recently opened offices here, on 0800 032 2101 or by sending an e-mail to support@verisign.co.uk

Customers using VeriSign certificates have previously dealt with BT in the UK, but after setting up a UK presence at the end of 2003, VeriSign started to operate its certificate business directly. BT continues to issue VeriSign certificates for its hosting customers along with other services, said Francois Steiger, senior vice president for Europe, when speaking to ZDNet UK in December. Steiger said VeriSign issues 25 percent of SSL certificates in Western Europe, and has 370,000 digital certificates installed in the region.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
63 out of 130 people found this useful



Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Product Development Manager/APACS,EMV,payment/Hertfordshire

In this role you will be responsible for -working as leadership team in defining business strategy -Managing Development/RD team and project managing ...

Wanted: Talented Business Graduates

Pathways available: Data Analysis involves assisting in the implementation and maintenance of data models, and applying data analysis and logical ...

SSIS, SQL Server, East Midlands, 6 Month Contract, Immediate Start

At interview stage the right candidate should be prepared to discuss event handling and error handling. My Client urgently requires a candidate with ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment