Chrome's Plan to Distrust Symantec Certificates
61–70 of 207 posts
Re: Chrome's Plan to Distrust Symantec Certificates
#62Earlier quoted context omitted.
> Another thing is, let's say I use some other CA for my certs, and I don't want LetsEncrypt issuing any. I can't really stop them, can I? You absolutely can. Let's Encrypt was one of the first CAs to support CAA (and, IIRC, they supported it when they first launched). CAA is a DNS record that lets you specify which CAs are permitted to issue certificates for your domain. > And finally, say I wanted to use LetsEncryp…
I wasn't aware of CAA, that's a nice development. > Do you want the ability to issue certificates under your own (constrained) intermediate certificate? Look at it this way: currently, if you can send network traffic from some IP space, you can create valid domain certs. This is the equivalent of using a hosts file with a list of IPs to authenticate an ssh connection. Yes, I think an intermediary key, and not simply…
There's an CAA extension in the works that will allow you to bind domains to ACME accounts (which are protected by your account key). Let's Encrypt has plans to support it. Is that what you're looking for?
Re: Chrome's Plan to Distrust Symantec Certificates
#63Is there a list somewhere of the actual Root CA certificates that will be removed as part of this? Is it just any Root CA certificate that has "Symantec, Thawte, VeriSign, Equifax, GeoTrust, and RapidSSL" in it's name?
Re: Chrome's Plan to Distrust Symantec Certificates
#64Amusing that security.googleblog.com itself is using a TLS certificate ultimately signed by GeoTrust Inc, which is owned by Symantec.
Re: Chrome's Plan to Distrust Symantec Certificates
#65What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…
> I'm a company that needs to show the company name next to the padlock Does anyone actually look at or care about that?
Re: Chrome's Plan to Distrust Symantec Certificates
#66What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…
> I'm a company that needs to show the company name next to the padlock Does anyone actually look at or care about that?
[1] https://www.troyhunt.com/journey-to-an-extended-validation-c...
Re: Chrome's Plan to Distrust Symantec Certificates
#67What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…
So yes, if you're using Gandi (and I still do myself for things LetsEncrypt cannot be used for, namely things where frequent rotation requires time-consuming manual intervention) you are safe from Symantec's distrust.
Re: Chrome's Plan to Distrust Symantec Certificates
#68What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…
> I'm a company that needs to show the company name next to the padlock Does anyone actually look at or care about that?
Users seem to notice but often times there's confusion as to why the address bar is, for lack of a better term, stuttering.
And god help you if your certificate uses a name you don't have any branding for.
Re: Chrome's Plan to Distrust Symantec Certificates
#69Surely the distrust doesn't apply to websites with the Norton Secured Seal, the most trusted mark on the internet: https://www.symantec.com/page.jsp?id=seal-transition
Re: Chrome's Plan to Distrust Symantec Certificates
#70If you are using the free SSL provided your Webhost "Let's Encrypt" certificate, you will be fine. That is not a Symantec cert.
When will google decide let's encrypt is not secure enough and start giving a warning around that.
When they start issuing illegitimate certificates.