Hacker News new | past | comments | ask | show | jobs | submit login

Take your website offline, temporarily. Upload your privkey to pastebin. Show cloudflare that it's compromised.... ?



They probably don't have the private key. Cloudflare has it since they are the one managing the certificate.


CloudFlare's Universal SSL certificates used to be shared between multiple unrelated accounts by SAN stuffing, so back then they definitely wouldn't have given out the private key. I think this may have changed since I last saw a CloudFlare certificate with >100 SANs for various unrelated sites on a client's certificate around 3 years ago. The certificate from the post is not shared, and I can't find any other Universal SSL certificates that are shared now. This support article still suggests they're shared, however [0].

They likely didn't give clients the private keys before simply to save costs by reducing the number of certificates they had to issue. Now that they're not sharing certificates, it's probably just a way to extract a little more money from customers.

[0] https://support.cloudflare.com/hc/en-us/articles/204144518-S...


I checked and the Universal SSL certificates are normally not being shared nowadays.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: