Earlier quoted context omitted.
The max time also starts at 33 months w/ Chrome 59 so thankfully they're giving plenty of time to either resolve the situation or have people switch CAs.
Not really. By the end of the year with their schedule Chrome 64 will be out with 9 month validity. Then who knows after that. So it is at the most 18 months.
Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
141–150 of 329 posts
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#142Earlier quoted context omitted.
Can you name some specific examples?
Symantec took one of their widely trusted root certificates and declared that it was now "off the reservation", meaning they may choose to not comply with the BRs for its leaf certificates. I don't know if they have actively used it to issue SHA-1 certificates, but they certainly could.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#143This is huge, Symantec owns about 15% of the SSL certificate market[1], and as stated in the article, has issued 30% of in-use certificates. No certificate authority of this size has ever been raked over the coals like this. [1] https://w3techs.com/technologies/history_overview/ssl_certif...
Pretty much it will decide the question on whether or not the certificate system is even workable. My thesis is that either Symantec will not be able to respond (and so lose their ability to be a root certificate) in which case it will warn other root cert authorities to shape up or lose their business, or they will placate the Google and Chromium teams somehow and show that root cert authorities can be brought to be…
I think the likely result here is more widespread adoption of LE. The point is that CA's shouldn't be businesses.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#144Symantec being well... Symantec, I'd expecting them to lawyer up in order to delay, or outright block this. They're big enough to afford the higher end law firms likely needed too. :(
Then they'd also have to strong arm Mozilla, Apple and Microsoft since they're rather likely to act too and at least the latter two don't disclose such changes until they've made them.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#145Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#146Earlier quoted context omitted.
> No we cannot use LetsEncrypt for convenience reasons (we bake our certificate pub key in many places) Why does that matter? Pretty sure you don't have to change your public key to get or renew a Let's Encrypt cert.
we spawn our servers and scale them up and down. We terminate ssl internally to our applications which are on Docker. Letsencrypt is painful on docker. I dont mind paying 40$ per year for a wildcard ssl certificate.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#147This is huge, Symantec owns about 15% of the SSL certificate market[1], and as stated in the article, has issued 30% of in-use certificates. No certificate authority of this size has ever been raked over the coals like this. [1] https://w3techs.com/technologies/history_overview/ssl_certif...
Am I the only one worried about LetsEncrypt becoming a monopoly? This move from Google is, indirectly, a huge service for them.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#148TLDR: Google has lost trust in Symantec's ability to properly validate certificates they issue. Chrome has a Root Certificate Policy that expects a CA to perform in a manner commensurate with the trust being placed in them and the Google team appears to see evidence that they are not living up to the standard laid out. They propose a gradual distrust of existing certificates by reducing the 'maximum age' of the certi…
This is a good summary, but I'd clarify it by saying that Google isn't being subjective about Symantec's process failures. The CA industry self-regulates. Its regulatory organization is the CA/B Forum, and their principal regulation is the Baseline Requirements (the BRs). Google claims Symantec violated multiple BRs. If you want to dig a little deeper, here's the last version of the BRs: https://cabforum.org/wp-conte…
Normally browser makers publish openly evidence of mis-issued certificates, together with having the discussion with the vendor in the public.
It's sad that this announcement from Google seems to basically be saying "we had a closed door dispute with Symantec, and now don't trust them".
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#149TL;DR Google prefers to override what the standards say about validity of certicates instead of what would be the logical thing: stop trusting Symantec root Certs. A dangerous precedent.
Aside from that, to the best of my knowledge the CA/B forum doesn't set forth any rules that require the immediate and complete removal of trust of a CA that is found to be in violation of the guidelines. I also don't see how they could, the best they could do is put out some form of recommendation but it's up to the parties that actually include the CAs to decide how they get removed, which is normally stipulated in the rules for inclusion in a Root Certificate bundle.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#150This is huge, Symantec owns about 15% of the SSL certificate market[1], and as stated in the article, has issued 30% of in-use certificates. No certificate authority of this size has ever been raked over the coals like this. [1] https://w3techs.com/technologies/history_overview/ssl_certif...
How is this different from StartCom except for size? Is the "too big to fail" enough of an argument here? Edit: Oh wait. Verisign and Thawte. Okay, that's some massive excrement on a collision course with the ventilation device.