Heartbleed Bug - How to make your SSL encrypted site secure again.


As you may know, a recent vulnerability known as "heartbleed" has been discovered in OpenSSL through which an attacker could theoretically gain access to the private keys of SSL certificates.

We recommend a timely check of the web server

Please make sure that the OpenSSL version used there needs to be updated. The exchange ("REPLACE") of the SSL certificates set up on the servers is advisable in any case, since the server does not have to be affected by this security gap, but the keys of the "old" certificates and other data could be read from the memory if the certificates are not exchanged.


Please note that the security hole in the web server tool OpenSSL occurs, the used EuropeanSSL certificates are of course still absolutely trustworthy.

Of course, you can exchange your current SSL certificates free of charge. Proceed as follows to do this.

  1. Update OpenSSL and make sure that the vulnerability no longer exists.
  2. Remove the certificate completely from your server.
  3. Create a new CSR
  4. Log in to your EuropeanSSL account and call up the certificate.
  5. Click on the button "Modify".
  6. A small popup window opens in which the currently stored CSR is displayed. Please overwrite the existing CSR with the newly generated one and confirm the changes by clicking the "Change" button.


Please note that the validation of the certificate becomes necessary again in case of a REPLACE. After you have confirmed the approvermail, the certificate will be reissued to you. We are happy to assist you with this. To do this, please send us the CSR unformatted by email to our support address info@eunetic.com. We will be happy to reissue your certificate.

You will find further information about this security gap at: https://en.wikipedia.org/wiki/Heartbleed


With the following information you can quickly and reliably check whether your server is affected.

Affected OpenSSL versions:

  • 1.0.1 up to and including 1.0.1f.

Not affected OpenSSL versions:

  • 1.0.1g
  • 1.0.0
  • 0.9.8

The release of OpenSSL 1.0.1g on April 7, 2014 closes this bug.

Is my site affected?

You can test whether your site is affected using various reliable tools, such as https://filippo.io/Heartbleed/.

How do I fix the problem?

Every system that uses one of the above mentioned affected OpenSSL versions needs to be updated with a patch. OpenSSL itself has released a patch which you can find on the official website : https://www.openssl.org/


It is mandatory to update the OpenSSL software before you exchange the EuropeanSSL certificates on the server.


You may also be interested in...
A short introduction to the world of SSL certificates (Secure Sockets Layer)

From personal information to financial information, SSL certificates ensure that data transmitted between a user's browser and a web server remains encrypted and secure. In our article, we give you an overview of the technology, show you how SSL works and what types of certificates there are.

Shorter SSL Lifespan – What You Need to Know

Discover why SSL/TLS certificates are now expiring faster than ever—transforming from years to just 47 days! Learn how this shift boosts security, mandates automation, and what it means for web users and developers alike.

Future-Proofing Your Website with Post-Quantum SSL

Discover how post-quantum SSL can shield your website from future cyber threats and keep your data safe against quantum computing attacks. Learn to implement and benefit from this advanced security measure today!

LEI Numbers: The Key to Transparency and Security in the Financial Sector and Their Connection to the IT Security Field

LEI numbers are critical for trading and security in the financial sector. Learn how they are used, how to apply for them, and the consequences of not having a number. Read more about the future development of LEI numbers and how they can improve IT security. Register with EuropeanLEI to get your own LEI number.

The importance of SSL certificates for small and medium-sized enterprises

Discover the importance of SSL certificates for small and medium-sized enterprises (SMBs) in protecting against cyberattacks and building customer trust. Learn how SSL certificates work and their impact on search engine rankings and reputational damage.