Future Tech

Let’s Encrypt Root CA Certificate Expires | Fortinet, Cisco Umbrella, Shopify and Dozens of Other Users Suffer Outages

On Thursday, around 10 AM (EST), the root certificate provided by Let’s Encrypt expired, and the internet flooded with issues reported by several services and websites worldwide.

Security researcher, Scott Helme, had already warned about the expiration of Let’s Encrypt’s IdentTrust DST Root CA X3. He predicted the expiration will take place on September 30 and post expiry, the devices, web clients, and computers will no longer be able to verify certificates issued by the Certificate Authority (CA).

Despite the warning, Helme confirmed issues with InstaPage, Netify, Ledger, Cisco Umbrella, QuickBooks, Shopify, Fortinet, Google Cloud Monitoring, Azure Application Gateway, Xero, RocketLeague, OVH, PFSense, Monday.com, Palo Alto, Heroku, Auth0, Cloudflare Pages and BlueCoat.

The business will be smooth for the majority of the users on September 30 and post that. However, devices like embedded systems (that don't auto-update regularly) and smartphones with outdated software versions will get affected. Possibly, devices with macOS 2016, Windows XP (Service Pack 3), older PlayStations, and OpenSSL 1.0.2 or earlier will also face issues.

"IT systems that enforce or monitor security policies can stop working. Alerting and reporting systems can fail. Or, if the processes that humans depend on to do our work stop functioning, often those people will find "workarounds"

Tim Callan, Digital Certificate Expert

One of the Windows IIS users reported his issue on Let’s Encrypt’s community forum. His cert chain looked like this: (my cert) -> (R3 ISRG Root X1 expiry 2025) -> (ISRG Root X1 expiry 2035). Many of his users, however, experience SSL failures (most on iPhones). When he used an SSL checker tool to verify the current status of his SSL, he found: (My cert) -> (DST Root CA X3 expires tomorrow) -> (R3 DST Root CA X3 expired 3 hours ago).

If this is what you also see, he suggested this quick fix:
  • Delete the old certs that were incorrectly picked by IIS in the chain.
  • Remove Intermediate Cert Auth.
  • Reboot the server (restarting ISS is not recommended)
  • If you use CDN, re-export the SSLs and install them.

Digital Shadows senior cyber threat analyst Sean Nikkel told ZDNet, “Some users have recommended settings allowing for expired certificates from trusted issuers; however, these can also have malicious uses. In any case, administrators should examine the best solution for them but also understand the risks to any workarounds. Alternatively, administrators can look at alternate trust paths by using the intermediate certificate that Let's Encrypt has set up or following suggested configurations from their May bulletin.”

Let’s Encrypt
Let’s Encrypt is a free, non-profit, open Certificate Authority (CA). It is one of the biggest providers of HTTP certificates. The company ensures the proper encryption and security between the internet and your device. It encourages a more secure and privacy-respecting Web and thus, provides free digital certificates that enable HTTPS (SSL/TLS) for websites.

Written by Aditya Chakurkar for The Infotech Report

Spotlight

Other News
AI Tech

AI and Big Data Expo North America announces leading Speaker Lineup

TechEx Events | March 07, 2024

AI and Big Data Expo North America announces new speakers! SANTA CLARA, CALIFORNIA, UNITED STATES, February 26, 2024 /EINPresswire.com/ -- TheAI and Big Expo North America, the leading event for Enterprise AI, Machine Learning, Security, Ethical AI, Deep Learning, Data Ecosystems, and NLP, has announced a fresh cohort of distinguishedspeakersfor its upcoming conference at the Santa Clara Convention Center on June 5-6, 2024. Some of the top industry speakers set to take the stage are: - Sam Hamilton - Head of Data & AI – Visa - Dr Astha Purohit - Director - Product (Tech) Ops – Walmart - Noorddin Taj - Head of Architecture and Design of Intelligent Operations - BP - Temi Odesanya - Director - AI Governance Automation - Thomson Reuters - Katie Sanders - Assistant Vice President – Tech - Union Pacific Railroad - Prasanth Nandanuru – SVP - Wells Fargo - Rodney Brooks - Professor Emeritus - MIT These esteemed speakers bring a wealth of knowledge and expertise to an already impressive lineup, promising attendees a truly enlightening experience. In addition to the speakers, theAI and Big Data Expo North Americawill feature a series of presentations covering a diverse range of topics in AI and Big Data exploring the latest innovations, implementations and strategies across a range of industries. Attendees can expect to gain valuable insights and practical strategies from presentations such as: How Gen AI Positively Augments Workforce Capabilities Trends in Computer Vision: Applications, Datasets, and Models Getting to Production-Ready: Challenges and Best Practices for Deploying AI Ensuring Your AI is Responsible and Ethical Mitigating Bias and Promoting Fairness in AI Systems Security Challenges in the Era of Gen AI and Data Science AI for Good: Social Impact and Ethics Selling Data Democratization to Executives Spreading Data Insights across the Business Barriers to Overcome: People, Processes, and Technology Optimizing the Customer Experience with AI Using AI to Drive Growth in a Regulated Industry Building an MLOps Foundation for AI at Scale The Expo offers a platform for exploration and discovery, showcasing how cutting-edge technologies are reshaping a myriad of industries, including manufacturing, transport, supply chain, government, legal sectors, financial services, energy, utilities, insurance, healthcare, retail, and more. Attendees will have the chance to witness firsthand the transformative power of AI and Big Data across various sectors, gaining insights that are crucial for staying ahead in today's rapidly evolving technological landscape. Anticipating a turnout of over 7000 attendees and featuring 200 speakers across various tracks, AI and Big Data Expo North America offers a unique opportunity for CTO’s, CDO’s, CIO’s , Heads of IOT, AI /ML, IT Directors and tech enthusiasts to stay abreast of the latest trends and innovations in AI, Big Data and related technologies. Organized by TechEx Events, the conference will also feature six co-located events, including the IoT Tech Expo, Intelligent Automation Conference, Cyber Security & Cloud Congress, Digital Transformation Week, and Edge Computing Expo, ensuring a comprehensive exploration of the technological landscape. Attendees can choose from various ticket options, providing access to engaging sessions, the bustling expo floor, premium tracks featuring industry leaders, a VIP networking party, and a sophisticated networking app facilitating connections ahead of the event. Secure your ticket with a 25% discount on tickets, available until March 31st, 2024. Save up to $300 on your ticket and be part of the conversation shaping the future of AI and Big Data technologies. For more information and to secure your place at AI and Big Data Expo North America, please visit https://www.ai-expo.net/northamerica/. About AI and Big Data Expo North America: The AI and Big Data Expo North America is a leading event in the AI and Big Data landscape, serving as a nexus for professionals, industry experts, and enthusiasts to explore and navigate the ever-evolving technological frontier. Through its focus on education, networking, and collaboration, the Expo continues to be a beacon for those eager to stay at the forefront of technological innovation. “AI and Big Data Expo North Americais a part ofTechEx. For more information regardingTechExplease see onlinehere.”

Read More