Hacker News new | past | comments | ask | show | jobs | submit login

What I don’t see mentioned anywhere is why the heck was this a last minute scramble? Don’t they know when their certificates are going to expire!?



Probably not. They probably know when most of their certs schedule but likely weren't monitoring this intermediate code signing cert (which is different than a TLS/webserver leaf/intermediate cert).

It seems super simple to do, but in practice IMO is harder than it seems. Most major cloud providers have been hit by at least one cert expiry causing an outage in the past year... Hell, likely in the past month.

This doesn't surprise me at all, certs are hard.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: