Seems that Symantec/Thawte have changed their SSL certificate requirements
again.

https://search.thawte.com/support/ssl-digital-certificates/index?page=content&id=INFO4614&elqTrackId=60a3a1562ac34bd49e1ad98415a3361a&elq=847d7acfc4474e1d9cfabbb097f2dd9e&elqaid=4271&elqat=1&elqCampaignId=2002

"Symantec???s next generation Web PKI hierarchy aims to modernize and 
streamline our TLS certificate offerings.
 
At the highest level, we are creating two new Symantec-branded root 
certificates, one RSA and one ECC. These reflect industry-standard best 
practices for algorithms and key sizes: 4096-bit RSA key, P-384 ECC key, and 
SHA-256 used in the signing algorithm. With this new hierarchy all public TLS 
certificates will be issued from these roots; this includes the Symantec, 
Thawte, GeoTrust and RapidSSL branded certificates.
 
>From these two root certificates, we are signing intermediate CA certificates 
>for Symantec, Thawte, and GeoTrust brands. Within each brand, we???ll have 
>separate RSA and ECC intermediate CA certificates for Domain Validation (DV), 
>Organization Validation (OV) and Extended Validation (EV) certificates. Under 
>the RapidSSL brand, we???ll have OV and DV intermediate CA certificates, but 
>no EV intermediate CA certificate.
 
In addition, we plan to cross-sign the new roots from several of our existing 
root certificates, to allow certificates in the new hierarchy to be trusted by 
clients that are not yet aware of the new roots.
 
Symantec expects to issue all new public TLS certificates from the new roots by 
1 December, 2017. Note that we will evaluate customer requests for new public 
TLS certificates from our existing roots after that time. Any certificates 
issued from the old roots after that time will not be trusted by all browsers, 
but will operate properly for non-browser
applications."


Are the keys generated by BlueOnyx campatible with this 4096-bit RSA key
format?


- Ernie.

 

_______________________________________________
Blueonyx mailing list
Blueonyx@mail.blueonyx.it
http://mail.blueonyx.it/mailman/listinfo/blueonyx

Reply via email to