Hacker News new | ask | show | jobs
by pagekalisedown 5493 days ago
(1) Yes, the key is encrypted.

(2) This is not necessarily the private key used to sign other certificates.

(3) If they're lucky, this is a private key only used for their web server. OR, this key is an intermediate key. In which case they can invalidate it, create a new one, and reissue certificates for all the affected customers.