{"id":12664,"date":"2026-05-07T04:03:42","date_gmt":"2026-05-07T04:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/07\/32956\/"},"modified":"2026-05-07T04:03:42","modified_gmt":"2026-05-07T04:03:42","slug":"32956","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/07\/32956\/","title":{"rendered":"SSL.com rotates their root certificate today, (Tue, May 5th)"},"content":{"rendered":"<p>    SSL.com rotates their root certificate today, (Tue, May 5th)<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>I just got an email from SSL.com last night, they are rotating \u00a0out their root certificate today (May 5,2026). \u00a0This is normal, business as usual stuff for a CA, but certificates get used for all kinds of things, and sometimes they aren&#8217;t used like they should be, so sometimes hiccups happen.<\/p>\n<p>If you are using them for basic cert+website stuff, there&#8217;s no need to worry.\u00a0 But if you go past that basic implementation, you should read their note to make sure that this change won&#8217;t be affecting any of your services.\u00a0 Even if you don&#8217;t use ssl.com, it&#8217;s a good read, as every certificate expires, which means that everyone&#8217;s root cert rotates out eventually &#8211; so forewarned if forearmed and all that ..<\/p>\n<p>In particular (from the email):<\/p>\n<ul>\n<li><em>If you have pinned trust anchors, custom trust stores, or certificate validation logic tied to the 2016 roots, please audit those configurations promptly to avoid disruptions.<\/em><\/li>\n<li><em>Use cross-certificates. If you need backward compatibility with the 2016 root hierarchy during the transition, cross-certificates can bridge the gap.<\/em><\/li>\n<li><em>Migrate to dedicated Client Certificates. These are purpose-built for client authentication and are unaffected by Google Chrome&#8217;s upcoming server authentication requirements, which impact SSL\/TLS certificates with the ClientAuth EKU.<\/em><\/li>\n<\/ul>\n<p>Their full post is here:<\/p>\n<p style=\"margin-left: 40px;\">https:\/\/www.ssl.com\/article\/what-ssls-root-migration-means-for-you\u00a0\u00a0 \u00a0<\/p>\n<p>===============<br \/>\nRob VandenBrink<br \/>\nrob@coherentsecurity.com<\/p>\n<p> (c) SANS Internet Storm Center. https:\/\/isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.<\/p><\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><\/p>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/isc.sans.edu\/diary\/rss\/32956\">Go to isc.sans.edu<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SSL.com rotates their root certificate today, (Tue, May 5th) I just got an email from SSL.com last night, they are rotating \u00a0out their root certificate today (May 5,2026). \u00a0This is normal, business as usual stuff for a CA, but certificates get used for all kinds of things, and sometimes they aren&#8217;t used like they should [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[69],"class_list":["post-12664","post","type-post","status-publish","format-standard","hentry","category-isc-sans-edu","tag-isc-sans-edu"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12664"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12664"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12664\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12664"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12664"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12664"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}