maybe time to revoke Comodo's CA authority. Similar to what has happened before with Symantec (?).
Revocation for being three days late in implementing a new standard would be a massive overreaction. It would harm thousands of businesses in the process and would be extremely petty. Symantecs misdeeds are far worse than this.
Comodo fails to check CAA records
21–30 of 71 posts
Re: Comodo fails to check CAA records
#22Earlier quoted context omitted.
Except they claimed to support it a long time before this. It’s not that they were late, it’s that they lied.
That makes no difference as to when the three days where. I never made any claims as to why it's late or them lying. I merely clarified that the three days were over a period where people don't usually work.
Re: Comodo fails to check CAA records
#23Earlier quoted context omitted.
Standardization goes through the CA/B forum. There was a ballot voted to make CAA checking mandatory for CAs[1], and COMODO voted yes for it. Any CA that issues certificates publicly need to check CAA from the 8th of September onward. [1] https://cabforum.org/2017/03/08/ballot-187-make-caa-checking...
Ah, so they are three days late. That doesn't sound too serious.
Re: Comodo fails to check CAA records
#24Earlier quoted context omitted.
Except they claimed to support it a long time before this. It’s not that they were late, it’s that they lied.
That makes no difference as to when the three days where. I never made any claims as to why it's late or them lying. I merely clarified that the three days were over a period where people don't usually work.
Re: Comodo fails to check CAA records
#25Highlights include allowing fraudulent certs to be issued for Google, Yahoo, and Mozilla; working with a malware company; and trademark shenanigans with Let's Encrypt.
Re: Comodo fails to check CAA records
#26Worth noting that the rule they broke has only been in effect for three days ( https://cabforum.org/2017/03/08/ballot-187-make-caa-checking... ). This might cause the CAB to go a bit easier on them.
They also voted "yes" to the proposal and had 6 months to implement it.
And yet with all of Comodo's resources, they couldn't get this done? I can't take them seriously.
Re: Comodo fails to check CAA records
#27Earlier quoted context omitted.
That makes no difference as to when the three days where. I never made any claims as to why it's late or them lying. I merely clarified that the three days were over a period where people don't usually work.
It's not about them being late these 3 days. It's about them lying about having already implemented this months ago .
Re: Comodo fails to check CAA records
#28Wikipedia has a nice list of previous Comodo malfeasance: https://en.wikipedia.org/wiki/Comodo_Group#Controversies Highlights include allowing fraudulent certs to be issued for Google, Yahoo, and Mozilla; working with a malware company; and trademark shenanigans with Let's Encrypt.
Why is this a bad thing? A cert says "Yes, person x REALLY IS person x, and I can prove it mathematically." It doesn't say "Person x is trustworthy enough for me to vouch for them."
Re: Comodo fails to check CAA records
#29The general rule in Operations work is tolerance. You don't fire someone for making a mistake, you fire them for lying about the mistake, for refusing to avoid mistake-prone behaviors, and other problem of that sort.
Applying that same principle to CA operations, why on earth should Comodo be "fired" as a CA for this? They're actively working to solve it, they're responsive, and the agreements they operate under will compel a post-mortem into existence if only to meet the terms of their next CA audit.
If, after investigation, they are found to be willfully violating policy, knowingly lying about CAA support, fail to produce an acceptable post-mortem, and/or fail their next CA audit, then of course they should be at risk of direct sanctions - not just a verbal reprimand.
So if your initial response to this issue is "Comodo should be fired", remember that in Operations culture that specific response "X should be fired" is a harmful response to a zero-day report of an incident, and many Operations teams would fire anyone who called for a firing in response to a fresh incident, in order to protect others from that harmful posture.
Re: Comodo fails to check CAA records
#30Earlier quoted context omitted.
It's not about them being late these 3 days. It's about them lying about having already implemented this months ago .
How do you know they lied? What if they implemented it but simply did not flip the switch?