Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> This step was announced some time ago, and since certificates usually need to be replaced frequently

Most people will buy certs valid for a few years, or around a couple of dozen Chrome-releases, and forget about them until they expire.

From my experience, among the things deployed in the world of IT, I would argue they are among the things replaced most infrequently.

So I'm curious... What makes you say certificates needs to be replaced frequently? What's the use-cases you are referring to?



Yeah, *.ycombinator.com is using a 5-year certificate which was issued in 2014.


That being said. How can I check our cert? The current cert predates my employment with the county and this is something I have never had to deal with.


This is a quick check site I've used previously: https://shaaaaaaaaaaaaa.com/

However the proper test should be done using https://www.ssllabs.com/ssltest/


If you view your website in chrome, you can click on the lock icon in the address bar. Go to the connection tab -> Click certificate information -> Details Tab. You should see one of the entries should be signature algorithm. SHA-1 is a problem. SHA-224 or higher means the cert is on SHA-2 which is okay.


If you are in Firefox, you can also click the padlock icon, and click on the more information button.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: