Live data from Hacker News

Comodo fails to check CAA records

mail-archive.com

11–20 of 71 posts

Re: Comodo fails to check CAA records

#11

Earlier quoted context omitted.

Standardization goes through the CA/B forum. There was a ballot voted to make CAA checking mandatory for CAs[1], and COMODO voted yes for it. Any CA that issues certificates publicly need to check CAA from the 8th of September onward. [1] https://cabforum.org/2017/03/08/ballot-187-make-caa-checking...

Ah, so they are three days late. That doesn't sound too serious.

Three days is quite a long time to be late, so I'd hope someone over there is getting a reprimand, but yeah, it's also not a disaster. They're response and time to remedy this will be more telling I think.

Re: Comodo fails to check CAA records

#12
post #4

maybe time to revoke Comodo's CA authority. Similar to what has happened before with Symantec (?).

Revocation for being three days late in implementing a new standard would be a massive overreaction. It would harm thousands of businesses in the process and would be extremely petty. Symantecs misdeeds are far worse than this.

Re: Comodo fails to check CAA records

#13

Worth noting that the rule they broke has only been in effect for three days ( https://cabforum.org/2017/03/08/ballot-187-make-caa-checking... ). This might cause the CAB to go a bit easier on them.

According to the mail, they have claimed to check CAA much earlier, so it's not just CAB guidelines they have broken, but their own word, which can be seen as worse.

Re: Comodo fails to check CAA records

#14

Earlier quoted context omitted.

Ah, so they are three days late. That doesn't sound too serious.

Three days is quite a long time to be late, so I'd hope someone over there is getting a reprimand, but yeah, it's also not a disaster. They're response and time to remedy this will be more telling I think.

Three days over a weekend, though. Context matters. Even if it's the most critical incident, you can't force employees to work outside of business hours.

Re: Comodo fails to check CAA records

#15

Earlier quoted context omitted.

Three days is quite a long time to be late, so I'd hope someone over there is getting a reprimand, but yeah, it's also not a disaster. They're response and time to remedy this will be more telling I think.

Three days over a weekend, though. Context matters. Even if it's the most critical incident, you can't force employees to work outside of business hours.

Except they claimed to support it a long time before this. It’s not that they were late, it’s that they lied.

Re: Comodo fails to check CAA records

#16
post #3

Curious to see how the CAB will handle this or if they're going to be "soft" as it's the first days of the CAA enforcement. Historically, they've been very accurate in enforcing their rules, which could mean a serious reprimand of Comodo. If anyone is interested in testing their own CAA records, we built an online CAA validator specifically for this; https://dnsspy.io/labs/caa-validator

To clarify, the CA/B Forum has no enforcement powers. This would only really be an issue if a root program takes issue with it or their auditor qualifies their audit.

Re: Comodo fails to check CAA records

#17

Earlier quoted context omitted.

Three days over a weekend, though. Context matters. Even if it's the most critical incident, you can't force employees to work outside of business hours.

Except they claimed to support it a long time before this. It’s not that they were late, it’s that they lied.

That makes no difference as to when the three days where. I never made any claims as to why it's late or them lying. I merely clarified that the three days were over a period where people don't usually work.

Re: Comodo fails to check CAA records

#18

Earlier quoted context omitted.

Three days is quite a long time to be late, so I'd hope someone over there is getting a reprimand, but yeah, it's also not a disaster. They're response and time to remedy this will be more telling I think.

Three days over a weekend, though. Context matters. Even if it's the most critical incident, you can't force employees to work outside of business hours.

The ballot was in March, so they have 6 month to prepare for it, not only 3 days to implement a surprising change.

Re: Comodo fails to check CAA records

#19

Earlier quoted context omitted.

Standardization goes through the CA/B forum. There was a ballot voted to make CAA checking mandatory for CAs[1], and COMODO voted yes for it. Any CA that issues certificates publicly need to check CAA from the 8th of September onward. [1] https://cabforum.org/2017/03/08/ballot-187-make-caa-checking...

Ah, so they are three days late. That doesn't sound too serious.

On a requirement they voted for half a year ago for a standard specified 5 years ago. It's sloppy and sloppy is not a property you want in a certificate authority.

Re: Comodo fails to check CAA records

#20

Earlier quoted context omitted.

Three days is quite a long time to be late, so I'd hope someone over there is getting a reprimand, but yeah, it's also not a disaster. They're response and time to remedy this will be more telling I think.

Three days over a weekend, though. Context matters. Even if it's the most critical incident, you can't force employees to work outside of business hours.

These 3 days don't matter when you have months of lead time.
Post reply on HN