What is the best alternative CA that also offers wildcard certificates (preferably with a similar business model)?
WoSign and StartCom: Mozilla’s proposed conclusion
61–70 of 252 posts
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#62Earlier quoted context omitted.
Mozilla is killing StartCom. Chrome has not announced a decision yet, although I predict that they will also distrust.
It's pertinent in this matter that one of the authors of the report works on the Chromium TLS stack. But it's not clear to me whether Chrome has an independent CA program. They use the Microsoft CA store on Windows, and at some point were using NSS (and hence the Mozilla certs) on Unixes. I presume they can always just additionally block this CA in Chrome, though.
Chrome does indeed use the platform CA store, but they can and do impose additional logic on top of it, such as requiring CT for Symantec, distrusting new CNNIC certs, or name-constraining ANSSI and India CCA.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#63Earlier quoted context omitted.
Who cares if it's a pain? User security is vastly more important than saving companies from the mild inconvenience of changing certs.
You forget things like certificate pinning which can make sites inaccessible for long durations of time if the user doesn't visit said website during this transition period. I'm not super convinced about the user security argument either. Sure, they backdated SHA-1 certificates and that's nasty but those certificates still expire at a reasonable time in the near future and will soon enough not be accepted by browsers…
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#64While most of the doc focused on StartCom/WoSign, I thought this bit at the end was interesting: > no longer accept audits carried out by Ernst & Young (Hong Kong). To reject audits from E&Y.... It makes me wonder about the transparency and trust we put in the auditors as being a key part of CA validation process.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#65While most of the doc focused on StartCom/WoSign, I thought this bit at the end was interesting: > no longer accept audits carried out by Ernst & Young (Hong Kong). To reject audits from E&Y.... It makes me wonder about the transparency and trust we put in the auditors as being a key part of CA validation process.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#66> Taking into account all the issues listed above, Mozilla’s CA team has lost confidence in the ability of WoSign/StartCom to faithfully and competently discharge the functions of a CA. Therefore we propose that, starting on a date to be determined in the near future, Mozilla products will no longer trust newly-issued certificates issued by either of these two CA brands.
I recommend reading the whole thing if you have time. They used some shady tactics.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#67This is a very detailed investigation - the parts that appear to be new are the specific serial number patterns, the times/dates of manual issuance, and the case of the Tyro SHA-1 cert. It's a little unfortunate that Mozilla's option here is to rely on WoSign and StartCom continuing to be honest about notBefore, or really, on Google detecting further abuse of notBefore via Certificate Transparency. Mozilla should rea…
> Google detecting further abuse of notBefore via Certificate Transparency You don't need to rely on Google. All certs issued by WoSign since January 1st, 2015 should be on WoSign's own Certificate Transparency log from which you can download them. StartCom is logging all new certs too, but I don't know for sure if they pushed all older ones too. If you ever encounter a cert that isn't on the list, that's definitive…
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#68Re: WoSign and StartCom: Mozilla’s proposed conclusion
#69Earlier quoted context omitted.
What exactly don't you like about Let's Encrypt? Besides Let's Encrypt, your other option is paying for a cert from GoDaddy or something. My two cents: don't give business to Comodo, given their horrible track record of sleaziness ( https://en.wikipedia.org/wiki/Comodo_Group#Controversies ).
I don't like the EFF, but I guess I will have to use Let's Encrypt if there's no other option.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#70Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448
They're not "killing" anyone. They have reasonable doubt that the CA has misrepresented the truth and engaged in practices that violate the rules set forth by the CAB and those for inclusion in the Mozilla trust store. There will have to be consequences for else it means nothing. They're also very clear that they do not intend to invalidate any already issued certificates, only new ones after a specific, yet to be de…
That said, they deserve it.