iTnews
  • Home
  • News
  • Technology
  • Security

GlobalSign cert error sees browsers block top websites

By Staff Writers on Oct 14, 2016 2:17PM
GlobalSign cert error sees browsers block top websites

Many sites affected.

A revocation error at security certificate provider GlobalSign has sent parts of the internet into meltdown after web browsers refused to load websites incorrectly labelled unsafe.

Whilst attempting to clean up some of its root certificate links, GlobalSign revoked a cross certificate that had linked together two root certifications, which should not have been removed. GlobalSign manages a number of root secure sockets layer (SSL) certificates that authenticate the identity of internet hosts.

This revocation request caused browsers to infer that all certifications downstream of the cross-signed root had also been revoked.

It meant that some of the world's top websites - like Dropbox and The Guardian among many others, small and large - were labelled as 'insecure' by web browsers, preventing access for security reasons.

While the provider quickly removed the affected cross-certificate and cleared its caches, the onus is now on GlobalSign customers to replace their SSL certificates to restore access to their sites.

Additionally, the "global nature of CDN [content delivery networks] and the effectiveness of caching" meant that some of the corrupt certificates made their way to end user systems, GlobalSign said.

Affected sites could remain blocked by browsers for four days until the cached responses expire, given end users "cannot always eaily clear their caches, either through lack of knowledge or lack of permission", the certificate authority said.

The firm admitted the situation was "not ideal", and said in the meantime it would provide an alternative issuing certificate authority for customers that has been issued by a root not affected by the revoked cross.

"We are currently working on the detailed instructions to help you resolve the issue and will communicate those instructions to you shortly," GlobalSign chief product offier Lila Kee told customers.

GlobalSign has set up a support page for IT administrators.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
certificatecybersecurityglobalsignsecurity

Partner Content

The Great Resignation has intensified insider security threats
Promoted Content The Great Resignation has intensified insider security threats
Avoiding CAPEX by making on-premise IT more cloud-like
Promoted Content Avoiding CAPEX by making on-premise IT more cloud-like
How to turn digital complexity into competitive advantage
Promoted Content How to turn digital complexity into competitive advantage
Security: Understanding the fundamentals of governance, risk & compliance
Promoted Content Security: Understanding the fundamentals of governance, risk & compliance

Sponsored Whitepapers

Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership

Events

  • CRN Channel Meets: CyberSecurity Live Event
  • IoT Insights: Secure By Design for manufacturing
  • Cyber Security for Government Summit
By Staff Writers
Oct 14 2016
2:17PM
0 Comments

Related Articles

  • 5 essential digital transformation ideas
  • Cover-More Group lands new head of cyber security
  • Google to buy Mandiant for US$5.4 billion
  • Ukrainian cyber resistance group targets Russian power grid, railways
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Qantas calls time on IBM, Fujitsu in tech modernisation

Qantas calls time on IBM, Fujitsu in tech modernisation

Service NSW hits digital services goal two years early

Service NSW hits digital services goal two years early

SA Police ignores Adelaide council plea for facial recognition ban on CCTV

SA Police ignores Adelaide council plea for facial recognition ban on CCTV

NBN Co says TPG tie-up could help Telstra sidestep spectrum limits

NBN Co says TPG tie-up could help Telstra sidestep spectrum limits

Digital Nation

IBM global chief data officer on the rise of the number crunchers
IBM global chief data officer on the rise of the number crunchers
Integrity, ethics and board decisions in the digital age
Integrity, ethics and board decisions in the digital age
COVER STORY: Operationalising net zero through the power of IoT
COVER STORY: Operationalising net zero through the power of IoT
Crypto experts optimistic about future of Bitcoin: Block
Crypto experts optimistic about future of Bitcoin: Block
The security threat of quantum computing
The security threat of quantum computing
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.