Live data from Hacker News

Chrome's Plan to Distrust Symantec Certificates

security.googleblog.com

61–70 of 207 posts

Re: Chrome's Plan to Distrust Symantec Certificates

#62
post #46

Earlier quoted context omitted.

> Another thing is, let's say I use some other CA for my certs, and I don't want LetsEncrypt issuing any. I can't really stop them, can I? You absolutely can. Let's Encrypt was one of the first CAs to support CAA (and, IIRC, they supported it when they first launched). CAA is a DNS record that lets you specify which CAs are permitted to issue certificates for your domain. > And finally, say I wanted to use LetsEncryp…

I wasn't aware of CAA, that's a nice development. > Do you want the ability to issue certificates under your own (constrained) intermediate certificate? Look at it this way: currently, if you can send network traffic from some IP space, you can create valid domain certs. This is the equivalent of using a hosts file with a list of IPs to authenticate an ssh connection. Yes, I think an intermediary key, and not simply…

I'm not sure I understand your suggestion. How does the intermediary key improve the domain validation process?

There's an CAA extension in the works that will allow you to bind domains to ACME accounts (which are protected by your account key). Let's Encrypt has plans to support it. Is that what you're looking for?

Re: Chrome's Plan to Distrust Symantec Certificates

#63
post #60

Is there a list somewhere of the actual Root CA certificates that will be removed as part of this? Is it just any Root CA certificate that has "Symantec, Thawte, VeriSign, Equifax, GeoTrust, and RapidSSL" in it's name?

I think this is what you're looking for: https://chromium.googlesource.com/chromium/src/+/master/net/...

Re: Chrome's Plan to Distrust Symantec Certificates

#65

What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…

> I'm a company that needs to show the company name next to the padlock Does anyone actually look at or care about that?

Yes, everyone who cares about their security when using online banking.

Re: Chrome's Plan to Distrust Symantec Certificates

#66

What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…

> I'm a company that needs to show the company name next to the padlock Does anyone actually look at or care about that?

See here [1] for a pretty good write-up arguing EV isn't worth much. One issue is that it only has value if you would notice it is missing. Would you trust a paypal site that just had the green padlock, but not the name? Do you think your parents would?

[1] https://www.troyhunt.com/journey-to-an-extended-validation-c...

Re: Chrome's Plan to Distrust Symantec Certificates

#67

What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…

Generally a quick google answers the question as well, Gandi lists their partnership with Comodo on their EV certificate ("SSL business") page [1] as well as a coule places on their wiki.

So yes, if you're using Gandi (and I still do myself for things LetsEncrypt cannot be used for, namely things where frequent rotation requires time-consuming manual intervention) you are safe from Symantec's distrust.

[1] https://v4.gandi.net/ssl/business

Re: Chrome's Plan to Distrust Symantec Certificates

#68

What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…

> I'm a company that needs to show the company name next to the padlock Does anyone actually look at or care about that?

Marketing often cares about that a lot.

Users seem to notice but often times there's confusion as to why the address bar is, for lack of a better term, stuttering.

And god help you if your certificate uses a name you don't have any branding for.

Re: Chrome's Plan to Distrust Symantec Certificates

#70
post #4

If you are using the free SSL provided your Webhost "Let's Encrypt" certificate, you will be fine. That is not a Symantec cert.

When will google decide let's encrypt is not secure enough and start giving a warning around that.

>When will google decide let's encrypt is not secure enough and start giving a warning around that

When they start issuing illegitimate certificates.

Post reply on HN