You know, the main job for a web CA is to verify the owner of a domain. What if... domain registrars had that job instead? They definitively know the domain registrant, no need to play games with email verification tokens or http challenges.
and then hope that every registrar out there is honest...
Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
81–90 of 118 posts
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#82Earlier quoted context omitted.
Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…
It's acceptable (albeit a terrible practice) to MITM traffic on your own network. It's not at all acceptable for any CA certificate accepted by default in all browsers (not just those on your network), no matter whether root or intermediate, to ever issue a certificate for a domain to anyone other than the owner of that domain. Issuing such a certificate is grounds for immediate revocation of browser trust. If you wa…
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#83So, how much of my internet will break if I distrust the Symantec cert on my machine?
~30%
Comodo and Synantec are 32% each, then goes others. StartSSl is significant but 2%, Let'sEncrypt tiny for now: https://w3techs.com/technologies/history_overview/ssl_certif...
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#84Earlier quoted context omitted.
It's acceptable (albeit a terrible practice) to MITM traffic on your own network. It's not at all acceptable for any CA certificate accepted by default in all browsers (not just those on your network), no matter whether root or intermediate, to ever issue a certificate for a domain to anyone other than the owner of that domain. Issuing such a certificate is grounds for immediate revocation of browser trust. If you wa…
May Symantec's authority can be revoked completely, if proof of misuse is found?
The last time Symantec made a "mistake" with their CA (https://security.googleblog.com/2015/10/sustaining-digital-c...), Google said "Therefore we are firstly going to require that as of June 1st, 2016, all certificates issued by Symantec itself will be required to support Certificate Transparency." Interesting wording, "by Symantec itself". And now, a few days before June 1st, Symantec issues an intermediate CA certificate to a known vendor of MITM systems, so that Bluecoat can issue certificates themselves rather than having their "certificates issued by Symantec itself".
I wonder if Bluecoat will support Certificate Transparency?
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#85Earlier quoted context omitted.
Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…
It's acceptable (albeit a terrible practice) to MITM traffic on your own network. It's not at all acceptable for any CA certificate accepted by default in all browsers (not just those on your network), no matter whether root or intermediate, to ever issue a certificate for a domain to anyone other than the owner of that domain. Issuing such a certificate is grounds for immediate revocation of browser trust. If you wa…
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#86Earlier quoted context omitted.
I'm good with my work or school owned/issued device trusting a root cert installed by that device's owner. I'm _not good with a school or employer's network being able to generate arbitrary certs for my email, bank, social networks, etc - WITHOUT ME KNOWING ABOUT IT ON MY PERSONAL DEVICES... Sure, MitM me if it's your network - but I 100% should be able to rely on my browser on my device reliably being able to tell m…
If you have a problem with that, use your own network.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#87Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#88I think it's been a little bit inactive of late, due to poor takeup - but it would certainly benefit from more users and more people contributing to the project.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#89Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#90Earlier quoted context omitted.
It's acceptable (albeit a terrible practice) to MITM traffic on your own network. It's not at all acceptable for any CA certificate accepted by default in all browsers (not just those on your network), no matter whether root or intermediate, to ever issue a certificate for a domain to anyone other than the owner of that domain. Issuing such a certificate is grounds for immediate revocation of browser trust. If you wa…
It may be acceptable in certain states and jurisdictions, but it is throughly illegal in others. Remember you aren't just MITMing your own network, if someone from your network connects to my server you are MITMing me too and you have not obtained my consent for that. Even if your state is a one party consent state, mine may not be or have laws that heavily restrict interception.