Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
51–60 of 118 posts
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#52You know, the main job for a web CA is to verify the owner of a domain. What if... domain registrars had that job instead? They definitively know the domain registrant, no need to play games with email verification tokens or http challenges.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#53Earlier quoted context omitted.
They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?
Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…
If they have clients on their network they want to MITM then that's not a legitimate use case for a CA at all. It doesn't matter if everything is on their network, it's unacceptable that my browser accepts their signature.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#54Isn't the dead-line for Google removing Symantec from Chrome supposed to be this June? (if they don't adopt CT for all of their certificates by then, that is)
[1]: https://groups.google.com/a/chromium.org/forum/#!topic/ct-po...
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#55Earlier quoted context omitted.
Ok, so if your adversary is your employer or your school, you are presumably using a network not controlled by you, in which case your endpoint ought to already be a VPN. A good number of employer or school-provider devices will have their own certificates preinstalled anyway. Nobody ever said privacy was convenient.
I'm good with my work or school owned/issued device trusting a root cert installed by that device's owner. I'm _not good with a school or employer's network being able to generate arbitrary certs for my email, bank, social networks, etc - WITHOUT ME KNOWING ABOUT IT ON MY PERSONAL DEVICES... Sure, MitM me if it's your network - but I 100% should be able to rely on my browser on my device reliably being able to tell m…
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#56You know, the main job for a web CA is to verify the owner of a domain. What if... domain registrars had that job instead? They definitively know the domain registrant, no need to play games with email verification tokens or http challenges.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#57Earlier quoted context omitted.
They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?
Even Cloudflare doesn't use their own CA, but they have a relationship with Comodo; at least, from what I can tell on services I use with Cloudflare. If they just need to issue lots of certificates, or make it easy for client devices to get certificates, or even for their own cloud services, they could use LetsEncrypt. There are very few use cases where having your own CA is necessary, and for a company like Blue Coa…
The most important thing to pay attention to here, with respect to Blue Coat, is the subscriber agreement they have signed with the CA AND the CPS that they write for their auditors. It'll dictate what they are and are not allowed to do with this subCA. If these are publicly trusted certificates, they will still need to pass—at minimum—domain control validation, e.g., can BC/their customers add an arbitrary DNS record or HTTP-accessible file for the zone being issued? If not, CA/B prohibits their issuance, so Symantec would get in huge trouble for allowing this. When you run your own subCA you are supposed to perform these checks yourself; it's up to their auditors (more in a sec) and Symantec to make sure they are performing these each and every time.
Additionally, Blue Coat will need to pass a WebTrust audit as mandated by the CA/B Forum. The thoroughness of this audit depends on how much Blue Coat is taking over from Symantec. If they're, e.g., handling key material, the audit will be much the same the CAs themselves must do. If doing considerably less, the scope of the audit is considerably more constrained. I think these audits are released to the public as I remember Let's Encrypt doing so, but that may just be because i) they aren't a full blown directly browser trusted CA or ii) LE just decided to do so as it fits their ethos.
You can find the relevant regulations that are imposed on public CAs here (look specifically for references to Subscriber Agreements): https://github.com/cabforum/documents/tree/master/docs. I'd start with the "BRs" (Baseline Requirements) doc; the other, EV Guidelines are irrelevant here, and Bylaws apply to CA/B itself.
Source: I manage CloudFlare's relationship with CAs and product manage our SSL/TLS related offerings.
EDIT: Added reference to CPS, the Certification Practice Statement. This document is written and provided to the auditors, and includes controls to test, etc. Here's Symantec's for example (as linked within X509v3 in crt.sh): https://www.symauth.com/cps.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#58Earlier quoted context omitted.
> Symantec would get destroyed if they issued a CA cert that was misused, right? Assuming browsers are willing to actually follow through and do so, yes.
The big question is does the emperor have any clothes? My guess is they'd settle for blocking certs issued after a specific date, at least for a transition period. The alternative would block too much of the internet.
1. https://security.googleblog.com/2015/10/sustaining-digital-c...
2. https://security.googleblog.com/2015/12/proactive-measures-i...
Ryan takes egregious violations of the BRs quite seriously. The CAs cross Google at their own risk. One day you find you're not trusted in Chrome anymore and their goes your business.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#59Earlier quoted context omitted.
Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…
I'm unclear about what you're saying. Are you saying it is OK for them to MITM traffic to https://google.com on their network by issuing a google.com cert? That is definitely not OK. If they only issue certs for domains that belong to themselves or their customers, that is OK.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#60https://archive.is/FEZfj just in case this goes down. How to untrust this certificate: https://blog.filippo.io/untrusting-an-intermediate-ca-on-os-...
Its funny how reluctant I am to install the certificate in the first step. I know it works as a vaccine of sorts, but still. It feels wrong.