Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I updated the server certificate to one signed with RSA+SHA256 to make chrome happy, but the new one has the same thing done to it.


Is the private key from the blog post valid to impersonate your server?


Depends on whether he revoked it or not.


The private key in the article was generated specifically for the article as an example - there's no CA-signed certificate that used it.

Also, certificate revocation is very unreliable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: