The company that bought one of the largest certificate authorities (CAs) said it has nearly finished replacing the digital certificates most commonly used by popular websites as major browsers prepare to phase them out in upcoming releases.

DigiCert Inc. said it has been sending mass email messages, calling customers and running webinars to make sure website owners are aware that Google and Mozilla will no longer trust Symantec-backed digital certificates when they release Chrome 66 next month and Mozilla Firefox 60 in May. DigiCert, which bought the CA business from Symantec last fall, noted that more than 99 percent of the top 1 million websites have taken appropriate action.

Purging Outdated Digital Certificates

According to SecurityWeek, the browser-makers established deadlines to revoke trust in digital certificates in response to a series of errors in the way they were issued and managed. DigiCert set up a portal for customers to check their domain name to determine whether they need new or replacement certificates. Companies that used RapidSSL, GeoTrust and Thawte can also obtain replacements through DigiCert.

For all its progress, Enterprise Times raised questions about how DigiCert will manage to win over the remaining customers who had obtained digital certificates through Symantec and other providers. This includes not only the top websites, but also many small and medium-sized businesses (SMBs) that could be affected by the browsers’ deadlines.

A Bumpy Transition

The transition of the CA business from Symantec to DigiCert has not been entirely smooth. Earlier this month, CRN Australia reported that the website of Trustico, a Symantec reseller, temporarily went offline after DigiCert claimed it had emailed the private keys of more than 20,000 digital certificates, which were later revoked. According to TechTarget, DigiCert claimed that 23,000 certificates were compromised, although the number of individual organizations affected by the incident has not been publicly reported.

Recently, DigiCert set up a new reseller program to make it easier to obtain and deploy digital certificates within the enterprise. The program aims to help the CA’s partners take advantage of the opportunity offered by Secure Sockets Layer (SSL), public key infrastructure and Internet of Things (IoT) security.

More from

The importance of Infrastructure as Code (IaC) when Securing cloud environments

4 min read - According to the 2023 Thales Data Threat Report, 55% of organizations experiencing a data breach have reported “human error” as the primary cause. This is further compounded by organizations now facing attacks from increasingly sophisticated cyber criminals with a wide range of automated tools. As organizations move more of their operations to the cloud, they must also become increasingly aware of the security risks and threats that come with it. It’s not enough anymore to simply have a set of…

Data never dies: The immortal battle of data privacy

4 min read - More than two hundred years ago, Benjamin Franklin said there is nothing certain but death and taxes. If Franklin were alive today, he would add one more certainty to his list: your digital profile. Between the data compiled and stored by employers, private businesses, government agencies and social media sites, the personal information of nearly every single individual is anywhere and everywhere. When someone dies, that data becomes the responsibility of the estate; but what happens to the privacy rights…

Vulnerability resolution enhanced by integrations

2 min read - Why speed is of the essence in today's cybersecurity landscape? How are you quickly achieving vulnerability resolution? Identifying vulnerabilities should be part of the daily process within an organization. It's an important piece of maintaining an organization’s security posture. However, the complicated nature of modern technologies — and the pace of change — often make vulnerability management a challenging task. In the past, many organizations had to support manual integration work to get different security systems to ‘talk’ to each…

How I got started: SIEM engineer

3 min read - As careers in cybersecurity become increasingly more specialized, Security Information and Event Management (SIEM) engineers are playing a more prominent role. These professionals are like forensic specialists but are also on the front lines protecting sensitive information from the relentless onslaught of cyber threats. SIEM engineers meticulously monitor, analyze and manage security events and incidents within an organization. They leverage SIEM tools to aggregate and correlate data, enabling them to detect anomalies, identify potential threats and respond swiftly to security…