Certificates expired

Marije Politiek • 21 juli 2020

On Saturday 30th May, two certificates expired: the 'AddTrust External CA Root' and the 'COMODO RSA Certification Authority'. Both are intermediate certificates that are used worldwide. According to the CA authority's preliminary announcement, 'modern clients', such as up-to-date browsers and Java clients, should remain unaffected. Unfortunately, the connection between systems did suffer from this.


It turned out that the software configuration that validates these certificates had not been updated in time. MCX have since adjusted this configuration to ensure all connections operate as normal.


Expired certificates do usually not cause problems, however, in this case, the problem resided in the 'certificate chain'. Certificates, just like passports, are issued by organisations that are authorized to do so. Due to the growth of the Internet, it had been decided to subcontract part of the issuance of certificates to 'intermediaries'. The picture below shows, at a high level, the relationship between the various types of certificates, including their average lifespan.



certificaten mcx

As indicated above, the problem could be traced back to the server software, which had been insufficiently updated. As a result, connection errors occurred between servers.


For further information, please visit https://nakedsecurity.sophos.com/2020/06/02/the-mystery-of-the-expiring-sectigo-web-certificate (Note: Sectigo is Comodo's new name).

Recent news

a real deep dive into the practicalities of working as an IT Service Provider
door Marije Politiek 27 mei 2026
From the classroom to cloud-based practice
MCX log4shell
door Marije Politiek 4 december 2025
MCX updates customers on the Log4Shell vulnerability affecting Oracle products. Patches are pending; mitigation steps and monitoring are already in place.
MCX’s Mark Kempers Named Oracle ACE Associate
door Marije Politiek 28 augustus 2025
MCX’s Mark Kempers is appointed Oracle ACE Associate for his expertise in Oracle Cloud Infrastructure and active contributions to the Oracle community.