<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: I don&#x27;t use Verisign in </title>
<link>http://www.dslreports.com/forum/r9023438</link>
<description></description>
<language>en</language>
<pubDate>Tue, 24 Nov 2009 04:01:01 EDT</pubDate>
<lastBuildDate>Tue, 24 Nov 2009 04:01:01 EDT</lastBuildDate>

<item>
<title>Re: I don&#x27;t use Verisign</title>
<link>http://www.dslreports.com/forum/remark,9024875</link>
<description><![CDATA[<A HREF="/useremail/u/429566"><b>Jason Levine</b></A> :  <BLOCKQUOTE><SMALL>said by  nixen <A HREF="/useremail/u/698757"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>If you use any kind of certificates that make use of intermediate certificate authorities, you will potentially be effected some day. Using different company's certs won't insulate you from that. Eventually, <I>all</I> certificate authority certificates expire - even GeoTrust's.<HR></BLOCKQUOTE><br><br>Ah, thanks for the clarification.  I just checked and it seems that GeoTrust's cert expires in 2018.  So I'll have to worry about this in 14 years (if I'm using the same server and haven't updated the cert).<br><SMALL>--<br>-Jason Levine<BR><A HREF="http://www.jasons-toolbox.com/">http://www.jasons-toolbox.com/</A><BR><A HREF="http://www.PCQandA.com/">http://www.PCQandA.com/</A><BR><A HREF="http://www.urateit.com/">http://www.urateit.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9024875</guid>
<pubDate>Fri, 09 Jan 2004 08:44:37 EDT</pubDate>
</item>

<item>
<title>Re: I don&#x27;t use Verisign</title>
<link>http://www.dslreports.com/forum/remark,9023438</link>
<description><![CDATA[<A HREF="/useremail/u/698757"><b>nixen</b></A> :  <BLOCKQUOTE><SMALL>said by  Jason Levine <A HREF="/useremail/u/429566"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>Luckily, I don't use Verisign for SSL certs for my company's sites so users shouldn't experience any of the problems while browsing with us.  We use GeoTrust instead.  They are much less expensive.<br> <HR></BLOCKQUOTE><br>If you use any kind of certificates that make use of intermediate certificate authorities, you will potentially be effected some day. Using different company's certs won't insulate you from that. Eventually, <I>all</I> certificate authority certificates expire - even GeoTrust's. <br><br>The major benefit of buying each providers' top-end certificates is that they are signed against the root certificate authority rather than an intermediate authority. Root certificate authorities typically have a lifetime of up to twenty years. So, you'll likely never see the CA expiration problem within the lifetime of your server. Intermediate authorities typically have a maximum lifetime of seven years. So, if you've had a site for a while and have been getting your certificates issued against the same intermediate CA, you end up having this week's problem.<br><br>It's the nature of PKI. To have truly trustworthy sites, you need to set expirations on the trust devices (certificates). Root CA's about 20 years; intermediate CA's about 7 years; server certificates typically 1-2 years; and client certificates typically no longer than 1 year.<br><br>-tom<br><SMALL>--<br>"There are 10 types of people in the world... those who understand binary and those who don't."<BR>"That's only 2 types of people, moron"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9023438</guid>
<pubDate>Fri, 09 Jan 2004 01:10:30 EDT</pubDate>
</item>

<item>
<title>I don&#x27;t use Verisign</title>
<link>http://www.dslreports.com/forum/remark,9018797</link>
<description><![CDATA[<A HREF="/useremail/u/429566"><b>Jason Levine</b></A> : Luckily, I don't use Verisign for SSL certs for my company's sites so users shouldn't experience any of the problems while browsing with us.  We use GeoTrust instead.  They are much less expensive.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9018797</guid>
<pubDate>Thu, 08 Jan 2004 17:24:33 EDT</pubDate>
</item>

</channel>
</rss>
