This is in continuation to our e-mail on June 25th(above), 2010 about Thawte's ROOT CA Certificate upgrade.
On June 27th, 2010, Thawte upgraded SSL123, Web Server and Wild Card Certificates to the 2048-bit Thawte Primary ROOT CA. This root uses SHA-1 hashing algorithm and 2048-bit RSA keys. The upgrade of Thawte SGC SuperCert Certificates has been deferred to later this year. There is no action necessary on your part for your existing certificates. Your certificates issued from our current MD5, 1024-bit RSA keys will continue to operate correctly.
This upgrade was done in order to ensure the highest level of security. This change is an industry wide initiative. Also, the US National Institute of Standards and Technology (NIST) has recommended transitioning over to 2048-bit keys. Browser vendors require the use of SHA-1 and 2048 keys. Microsoft has stipulated requirements that require that all new Root Certificates be 2048-bit and not use MD5 as the hashing algorithm.
So what has changed?
For any certificate you enroll, renew or reissue now onwards, you need to use a 2048-bit Certificate Signing Request. Also, along with the certificate issued you will also need to install the Thawte Intermediate CA certificate bundle (Intermediate CA and Cross Root CA) on your web hosting server. This will not involve any additional costs. The Thawte Intermediate CA certificate bundle, based on the type of certificate purchased, is available here - http://47530.myorderbox.com/kb/servlet/KBServlet/faq1099.html
For digital certificates purchased with us and web hosting with some other service provider, kindly make sure that the web server has the appropriate CA certificate installed.
For sites hosted on our servers :
cPanel Linux Hosting - Please refer to http://47530.myorderbox.com/kb/servlet/KBServlet/faq1582.html for detailed instructions on installing the certificates.
Other Linux and Windows Hosting - You can install the thawte Intermediate CA Certificate from within your own Control Panel. Please refer to http://47530.myorderbox.com/kb/servlet/KBServlet/faq1163.html for detailed instructions.
In case you have certificates issued post June 27, 2010 installed on the hosting server and are facing any kind of exceptions while resolving your websites on HTTPS, kindly install the Intermediate CA certificate bundle on your web server for the smooth functioning of your Digital Certificate
Regards,
NeoWebSpace.com