Nigerian Government Goes Open Source

#Defense #Education and tonnes of others currently use #Roundcube for email, needless to say, they all embrace #Linux or #BSD.

And for their SSL certificate, a Nigerian agency is closer to being a CA provider and cert issuer. Currently leaning on #Sectigo for their wildcard multidomain certificate, she has taken a step toward reducing eavesdropping on interministerial communications and assuming digital sovereignty.

*
The site is set up to allow only secure connections, but there’s a problem with the site’s certificate. It’s possible that a bad actor is trying to impersonate the site. Sites use certificates issued by a certificate authority to prove they’re really who they say they are. Firefox doesn’t trust this site because its certificate isn’t valid for mail.icpc.gov.ng. The certificate is only valid for: mail.govmail.gbb.com.ng, cp.lbrbda.gov.ng, cp.education.gov.ng, cp.3mtt.fmcide.gov.ng, cp.cdcfib.gov.ng, cp.nscc.gov.ng, cp.foreignaffairs.gov.ng, cp.fmld.gov.ng, cp.bnp.gov.ng, cp.fcda.gov.ng, cp.osgf.gov.ng, cp.msd.gov.ng, cp.fcta.gov.ng, cp.justice.gov.ng, cp.nsiwc.gov.ng, cp.fmhds.gov.ng, cp.academy.ohcsf.gov.ng, cp.litfcmb.gov.ng, cp.specialduties.gov.ng, cp.health.gov.ng, cp.youthdev.gov.ng, cp.ohcsf.gov.ng, cp.mpb.mil.ng, cp.cct.gov.ng, cp.nama.gov.ng, cp.nasrda.gov.ng, cp.boundarycommission.gov.ng, cp.ngsa.gov.ng, cp.pfscu.gov.ng, cp.nta.gov.ng, cp.govmail.gbb.com.ng, cp.crbda.gov.ng, cp.naic.gov.ng, cp.surcon.gov.ng, cp.precefi.gov.ng, cp.budgetoffice.gov.ng, cp.fmhud.gov.ng, cp.eyecenter.gov.ng, cp.ccpt.gov.ng, cp.fmactce.gov.ng, cp.oagf.gov.ng, cp.nigerdelta.gov.ng, cp.fedcivilservice.gov.ng, cp.nimasa.gov.ng, cp.chadrbda.gov.ng, cp.maritimeacademy.edu.ng, cp.von.gov.ng, cp.leep.gov.ng, cp.regionaldev.gov.ng, cp.scienceandtech.gov.ng, cp.nemsa.gov.ng, cp.fmsdiga.gov.ng, cp.ncaa.gov.ng, cp.worksandhousing.gov.ng, cp.womenaffairs.gov.ng, cp.maritimeacademy.gov.ng, cp.psc.gov.ng, cp.fmmsd.gov.ng, cp.steel.gov.ng, cp.icsc.ohcsf.gov.ng, cp.osgof.gov.ng, cp.fmacce.gov.ng, cp.neiti.gov.ng, cp.fedcs.gov.ng, cp.labour.gov.ng, cp.nationalplanning.gov.ng, cp.lawschool.gov.ng, cp.informationandculture.gov.ng, cp.agriculture.gov.ng, cp.waterresources.gov.ng, cp.cdarm.justice.gov.ng, cp.fmcide.gov.ng, cp.policeaffairs.gov.ng, cp.corrections.gov.ng, cp.defence.gov.ng, cp.nphcda.gov.ng, cp.sports.gov.ng, cp.finance.gov.ng, cp.transportation.gov.ng, cp.youthandsport.gov.ng, cp.swdc.gov.ng, cp.fmiti.gov.ng, cp.bpsr.gov.ng, cp.dufuth.gov.ng, cp.environment.gov.ng, cp.power.gov.ng, cp.aviation.gov.ng, cp.nigcomsat.gov.ng, cp.umth.gov.ng, cp.fgshlb.gov.ng, cp.fmw.gov.ng, cp.navy.mil.ng, cp.petroleumresources.gov.ng, cp.nadf.gov.ng, cp.interior.gov.ng, cp.tetfund.gov.ng, cp.nepza.gov.ng, cp.fmmbe.gov.ng, cp.pwh.gov.ng, cp.ntda.gov.ng, cp.msmd.gov.ng, cp.icpc.gov.ng, cp.fmino.gov.ng, cp.riversstate.gov.ng, cp.tawadang.com, cp.maritimeacademyofnigeria.org, govmail.gbb.com.ng, cp.nsib.gov.ng, cp.energy.gov.ng, cp.naddc.gov.ng, cp.shestco.gov.ng, cp.son.gov.ng, cp.nan.gov.ng, cp.federalcharacter.gov.ng, cp.nesrea.gov.ng, cp.nacgrab.gov.ng, cp.notn.gov.ng, cp.cltc.gov.ng, cp.nahcon.gov.ng, cp.airforce.mil.ng, cp.bcda.gov.ng, cp.cstp.nasrda.gov.ng, cp.nbma.gov.ng, cp.defencehq.mil.ng, cp.drdb.mil.ng, cp.nepc.gov.ng, cp.nema.gov.ng, cp.ncpc.gov.ng, cp.population.gov.ng, cp.nmec.gov.ng, cp.pidaccnb.gov.ng, cp.nils.gov.ng, cp.rrbn.gov.ng, cp.nasc.gov.ng, cp.nerdc.gov.ng, cp.naqs.gov.ng, cp.pebec.gov.ng, cp.ncmm.gov.ng, cp.aiic.fcta.gov.ng, cp.copyright.gov.ng, cp.dtca.gov.ng, cp.nwsrp.gov.ng, cp.nbc.gov.ng, cp.arcn.gov.ng, cp.dtechboard.gov.ng, cp.ubrbda.gov.ng, cp.npf.gov.ng, cp.nelmco.gov.ng, cp.comeg.gov.ng, cp.immigration.gov.ng, cp.nimet.gov.ng, cp.frin.gov.ng, cp.dmo.gov.ng, cp.paf.gov.ng, cp.ncfrmi.gov.ng, cp.nfvcb.gov.ng, cp.nnra.gov.ng, cp.frc.gov.ng, cp.narict.gov.ng, cp.fedfire.gov.ng, cp.pcc.gov.ng, cp.nrc.gov.ng, cp.niprd.gov.ng, cp.nmcp.gov.ng, cp.ccb.gov.ng, cp.cmd.gov.ng, cp.smdf.gov.ng, cp.niffr.gov.ng, cp.ehcon.gov.ng, cp.grid3.gov.ng, cp.ggwnigeria.gov.ng, cp.sdgs.gov.ng, cp.nln.gov.ng, cp.prisons.gov.ng, cp.cybersecurity.gov.ng, cp.nosdra.gov.ng, cp.police.gov.ng, cp.ebes.gov.ng, cp.fib.gov.ng, cp.dodc.fcta.gov.ng, cp.n-sip.gov.ng, cp.pci.gov.ng, cp.hrorbn.gov.ng, cp.nigeriaimmigration.gov.ng, cp.cbss.nasrda.gov.ng, cp.ammc.fcta.gov.ng, cp.advertcouncil.gov.ng, cp.uath.gov.ng, cp.nji.gov.ng, cp.nbti.gov.ng, cp.aacelab.nasrda.gov.ng, cp.iccon.gov.ng, cp.frcnigeria.gov.ng, cp.nmep.gov.ng, cp.npf.cybersecurity.gov.ng, cp.nascp.gov.ng, cp.ipan.gov.ng, cp.dsa.mil.ng, cp.nislt.gov.ng, cp.nicfost.gov.ng, cp.fccpc.gov.ng, cp.cstd.nasrda.gov.ng, cp.ictinnovation.gov.ng, cp.bhcpf.gov.ng, cp.jamb.gov.ng, cp.proda.gov.ng, cp.fjsc.gov.ng, cp.nde.gov.ng, cp.nohazarehawul.gov.ng, cp.niwrmc.gov.ng, cp.ncwd.gov.ng, cp.cpc.gov.ng, cp.notary.gov.ng, cp.nepad.gov.ng, cp.fmf.gov.ng, cp.abiastate.gov.ng, cp.nipc.gov.ng, cp.fmcabuja.gov.ng, cp.dtac.gov.ng, cp.fmtourism.gov.ng, cp.nlrc.gov.ng, cp.modhip.gov.ng, cp.nfc.gov.ng, cp.nnma.gov.ng, cp.productivity.gov.ng, cp.afcsc.mil.ng.
*



The site/domain-wide verification and native name in her certificate are commendable. They can engage several open source communities for improved security (2FA/OTP), content/software localisation, IPS/IDS, AI-productivity tools and many more.

Their servers are currently on AWS and other cloud providers. In no time, they would embrace in-house hosting with these open-source packages as their banks do with proprietary software.


#Nigeria #Africa #OpenSource #Engineering

#Sectigo maliciously revoked #RustDesk 's code signing certificate because #VirusTotal says two engines are marking it as malware. Sectigo only give them 24 hours to resolve the issue, but most antivirus companies needs few days to resolve the false positives.

Now, all of the false positives are resolved, but Sectigo still no response for this incident for a week.

https://x.com/rustdesk/status/1998235183385026578

https://github.com/rustdesk/rustdesk/discussions/1375

https://www.virustotal.com/gui/file/4a3185b9282dbc85070dea4857de49003a709531e71c6e1207290d23da793067

🛡️ Sectigo’s Tim Callan warns:
- Harvest-now-decrypt-later attacks
- Trust-now-forge-later attacks
👉 PQC migration won’t be “flip the switch” — 98% of orgs expect big hurdles.

Full interview: https://www.technadu.com/quantum-era-threats-harvest-now-decrypt-later-and-trust-now-forge-later-attacks-challenge-digital-trust/606844/

#PQC #CyberSecurity #Sectigo #PostQuantum

#Sectigo wirft @geant in marketing mails eine unfaire Darstellung der Situation vor, die zur einseitigen und vorzeitigen Kündigung der Verträge seitens Sectigo geführt hatte. Sie führen einerseits finanzielle Gründe auf, was sicher auch stimmen kann, behaubten aber in einem verlinkten PDF später folgendes:

"Our decision to step away from GÉANT was guided by our responsibility to remain in full compliance with the CA/Browser Forum Baseline Requirements, as well as the
root program policies established by major browser and operating system vendors, [...]"

Spannende Formulierung. #GÉANT hätte also, laut Sectigos Darstellung hier, mit ihrer fortlaufenden Nutzung der Sectigo Dienstleistungen gegen CA Richtlinien verstoßen? Oder Sectigo dazu genötigt, das zu tun? Da wäre ich wirklich mal an den Details interessiert. Anyone?

Let's #Encrypt rolls out free IP address #certificates • The Register

Let's Encrypt, a #CertificateAuthority (CA) known for its free TLS/SSL certificates, has begun issuing digital certificates for IP addresses.

It's not the first CA to do so. #PositiveSSL , #Sectigo, and #GeoTrust all offer TLS/SSL certificates for use with IP addresses, at prices ranging from $40 to $90 or so annually. But Let's Encrypt does so at no cost.
#security #tls #ssl #privacy

https://www.theregister.com/2025/07/03/lets_encrypt_rolls_out_free/

Let's Encrypt rolls out free security certs for IP addresses

: You probably don't need one, but it's nice to have the option

The Register
Let's Encrypt, a #certificate authority (CA) known for its free #TLS/SSL certificates, has begun issuing digital certificates for #IP addresses.
It's not the first #CA to do so. #PositiveSSL, #Sectigo, and #GeoTrust all offer TLS/SSL certificates for use with IP addresses, at prices ranging from $40 to $90 or so annually. But Let's Encrypt does so at no cost.
https://www.theregister.com/2025/07/03/lets_encrypt_rolls_out_free/
Let's Encrypt rolls out free security certs for IP addresses

: You probably don't need one, but it's nice to have the option

The Register

After Google stops trusting #TLS certificates from #Entrust they finally sell their public certificate business to #Sectigo

https://www.entrust.com/company/newsroom/entrust-sells-public-certificate-business-to-sectigo

So, issuing a #Sectigo Business #SSL certificate via #IONOS requires you to lie about your country of residence because the order form has a mandatory "German Bundesland" field no matter which country you select. I'm sure that's fine. 🤷‍♂️

@geant what a mess with #sectigo certificates

How could a european research institute like #geant ever even think about signing a contract with a non EU provider?

Aus gegebenem Anlass:

Das könnte für einige von euch eine gewisse Relevanz aufweisen: solltet ihr GÉANT-Zertifikate für für euch wichtige Dienste nutzen, solltet Ihr die unbedingt jetzt noch einmal erneuern, um mehr Spielraum zu haben. Es ist nämlich im Moment davon auszugehen, dass #Sectigo ab dem 10. Januar keine mehr ausstellen wird. Die #DFN-PKI Global ist aber nicht mehr und wird auch nicht wiederkommen.

https://doku.tid.dfn.de/de:dfnpki:tcsfaq:aktuellesituation

de:dfnpki:tcsfaq:aktuellesituation [Dokumentation DFN-AAI, DFN-PKI und eduroam]