{"id":10870,"date":"2019-05-24T10:31:27","date_gmt":"2019-05-24T14:31:27","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=10870"},"modified":"2023-03-20T18:06:09","modified_gmt":"2023-03-20T22:06:09","slug":"linkedin-suffers-ssl-tls-certificate-expiration-again","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/linkedin-suffers-ssl-tls-certificate-expiration-again\/","title":{"rendered":"LinkedIn suffers SSL\/TLS certificate expiration. Again."},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-for-the-second-time-in-two-years-certificate-expiry-bites-linkedin\">For the second time in two years certificate expiry bites LinkedIn.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Once again, LinkedIn has underscored the importance of good certificate management. <a href=\"https:\/\/www.thesslstore.com\/blog\/linkedin-ssl-certificate-expired\/\">For the second time in two years<\/a> an SSL\/TLS certificate expired and caused downtime for the social media site. This time it was LinkedIn\u2019s link shortener, lnkd.in, that was the culprit. On Tuesday, May 21, desktop users started to see <a href=\"https:\/\/www.thesslstore.com\/blog\/fix-err-ssl-protocol-error\/\">those dreaded SSL connection error messages<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Obviously, LinkedIn scrambled to fix the issue and had a new SSL\/TLS certificate installed quickly, but it also provided us with yet another teachable moment in the process, too. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, today we\u2019re going to talk about what exactly happened,\nwhy it happened again and what could have been done to prevent it. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-certificate-expiration-strikes-again\">Certificate Expiration Strikes Again!<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.thesslstore.com\/blog\/what-happens-when-your-ssl-certificate-expires\/\">This is what happens when your SSL certificate expires<\/a>. We write articles about you and use you as a cautionary tale to reaffirm the value of <a href=\"https:\/\/www.thesslstore.com\/enterprise\/ssl-certificate-management.aspx\">a proper certificate management solution<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And given this is the second time this has happened in two years, you have to wonder whether LinkedIn learned its lesson the first time. Certificate expirations are easily the second worst thing that\u2019s happened to LinkedIn lately. The worst is its addition of video. Now everyone is a motivational speaker and\u2026 anyway, certificate expiration can cause a lot more trouble than just downtime, too. <a href=\"https:\/\/www.thesslstore.com\/blog\/71-of-organizations-dont-know-how-many-certificates-keys-they-have\/\">It can end up costing money<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">How much this actually cost LinkedIn is difficult to quantify. The outage only affected desktop users trying to use the company\u2019s link shortener. LinkedIn is now owned by Microsoft, and Microsoft is unlikely to give specifics about how many users couldn\u2019t connect or exactly how long the outage lasted, but <a href=\"http:\/\/www.businessofapps.com\/data\/linkedin-statistics\/#3\">in 2018 LinkedIn\u2019s revenues stood at a whopping $5.3 billion<\/a>, so it wouldn&#8217;t be surprising if the actual cost from downtime alone was in the millions.<\/p>\n\n\n\n<h3 class=\"has-text-align-center wp-block-heading\" id=\"h-certificate-expiration-by-the-numbers\">Certificate Expiration by the Numbers<\/h3>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"288\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Certificate-Expiry-1024x288.png\" alt=\"Certificate expiration can be fatal, costing organizations millions of dollars every year\" class=\"wp-image-10106\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Certificate-Expiry-1024x288.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Certificate-Expiry-300x84.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Certificate-Expiry-768x216.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Certificate-Expiry.png 1564w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Downtime is a much bigger issue for smaller companies, LinkedIn will weather the outage costs easily. The bigger issue for a company the size of LinkedIn is the brand damage it incurs. While, admittedly, some users will never know, or will see and not know, what to make of it \u2013 more tech savvy users may start to form critical opinions about how seriously LinkedIn takes security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Again, this is a very preventable problem provided you\u2019re using the right tools. But this is now twice in just a couple of years. It\u2019s also <a href=\"https:\/\/cmitsolutions.com\/blog\/linkedin-revelations-highlight-need-stronger-network-security\/\">not the only security-related issue LinkedIn has encountered<\/a>. It all starts to add up after a while and given some the rather sensitive nature of some of the information people share with LinkedIn \u2013 losing trust could prove disastrous. <\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-exactly-happened\">What Exactly Happened?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To understand what happened you need to start with a quick explanation of link shortening and the real reason companies actually do it. It\u2019s easy to view it as just a clever way to slip links into character-capped social media posts, like back before Twitter didn\u2019t count URLs \u2013 but the real reason it\u2019s done is for analytics. Companies need to be able to track who clicks on their content, whether it\u2019s people or bots, where they came from, etc. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, when you use a link shortener it\u2019s kind of like putting a proxy in the middle of the connection. The link connects with the link shortening domain, which inspects the traffic and redirects it along to its intended destination. In order for this to work, there actually needs to be two different connections that occur, so there need to be two different SSL certificates. The link shorterning domain needs one and then the actual website itself needs one, too. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this case, the SSL\/TLS certificate securing the link shortening domain, lnkd.in, expired and anyone attempting to click on shortened links was unable to connect. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-this-seems-preventable\">This Seems Preventable\u2026<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Oftentimes, when an expiration occurs this is how it happens. It\u2019s not unusual, but it\u2019s also not common that companies let the certificate on their flagship website expire. It\u2019s usually a certificate on an application server or even a machine identity that expires and causes the service outage. These can be a lot harder to find and replace.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"195\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Not-Secure-Connection-300x195.png\" alt=\"\" class=\"wp-image-10873\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Not-Secure-Connection-300x195.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Not-Secure-Connection-768x498.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Not-Secure-Connection-1024x664.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Not-Secure-Connection.png 1147w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Shadow IT is any kind of IT product or service that was\nacquired via non-standard channels. SSL certificates and digital certificates\nin general are one of the most common Shadow IT items. The cause for this isn\u2019t\nmalicious \u2013 it\u2019s typically not someone knowingly circumventing the systems \u2013 it\njust stems from the fact that everything needs to have a certificate nowadays\nand they are oftentimes requisitioned outside of standard channels. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This creates a considerable risk though, because certificate management is a major compliance and security concern \u2013 and when things go sideways it costs companies money and people jobs. And once again LinkedIn has demonstrated that just a single certificate expiration can shut down operations for a great many customers if it happens in a sensitive enough place. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">LinkedIn was fortunate that the certificate was visible enough\nto find quickly, normally your IT or security team has to scramble to find\nwhere the certificate was deployed, who issued it, where the keys are stored,\netc. And that\u2019s assuming you even notice right away. There\u2019s no shortage of\nexamples of this happening, perhaps the most well-known being the fact\nEquifax\u2019s breach went undetected for 76 days because of an expired certificate\nthat went unaddressed. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The solution is to have an organized approach to certificate\nmanagement. You need to be able to scan all of your networks for certificates,\nyou need an interface to manage them all and maintain visibility with. And then\nyou need to establish policies and procedures for managing every stage of the\nlifecycle: issuance, rotation, renewal, revocation, etc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If it\u2019s possible \u2013 automate everything. Remove as much of\nthe human element as possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Too often digital certificates are an afterthought until\nit\u2019s too late, and when that happens it can shine a light on your company for\nall the wrong reasons.<\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<p class=\"wp-block-paragraph\"><em>As usual leave any comments or questions below\u2026<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"267\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg\" alt=\"Hashed Out by The SSL Store is the voice of record in the SSL\/TLS industry.\" class=\"wp-image-7276\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-300x78.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-768x200.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg 1559w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>For the second time in two years certificate expiry bites LinkedIn. Once again, LinkedIn has underscored the importance of good certificate management. For the second time in two years an&#8230;<\/p>\n","protected":false},"author":6,"featured_media":10871,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[315,5409],"class_list":["post-10870","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-certificate-expired","tag-linkedin","post-with-tags"],"views":21878,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/LinkedIN-Expiry-Feature.png","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/10870","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=10870"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/10870\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/10871"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=10870"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=10870"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=10870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}