| Version | Supported |
|---|---|
| 2.x.x | ✅ |
| 1.x.x | ❌ |
If you discover a security vulnerability within CertDeliver, please send an email to the maintainer. All security vulnerabilities will be promptly addressed.
Please do not disclose security vulnerabilities publicly until they have been handled by the maintainers.
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Suggested fix (if any)
- Initial Response: Within 48 hours
- Status Update: Within 7 days
- Fix Release: Depending on severity, typically within 14-30 days
When deploying CertDeliver:
- Use strong tokens: Generate random tokens with at least 32 characters
- Restrict network access: Use firewall rules to limit access to the server
- Enable HTTPS: Always use TLS for server communication
- Keep updated: Regularly update to the latest version
- Monitor logs: Review server logs for suspicious activity