Earlier quoted context omitted.
This is factually wrong. There wasn't plenty of warnings and google ignored their own roadmap. Google announced in October 2017 that they will block Symantec certificates in October 2018. Leaving a year to upgrade, fairly reasonable considering most certificates must be renewed early. However, Chrome blacklisted Symantec since April 2018, 6 months early. Taking a lot of people by surprise.
You mean this roadmap? https://security.googleblog.com/2017/09/chromes-plan-to-dist... That plan clearly states that all Symantec-issued certificates with a not-before date before June 1, 2016 would be distrusted in April. Is that not what happened?
Distrust of Symantec TLS Certificates
61–70 of 124 posts
Re: Distrust of Symantec TLS Certificates
#62FYI: Your site has been unreachable since April if you use Symantec certificates. Chrome announced the depreciation for October but they didn't stick to their own roadmap and blacklisted Symantec since April instead (Chrome 66 release). https://security.googleblog.com/2018/03/distrust-of-symantec...
https://security.googleblog.com/2017/09/chromes-plan-to-dist...
Re: Distrust of Symantec TLS Certificates
#63FYI: Your site has been unreachable since April if you use Symantec certificates. Chrome announced the depreciation for October but they didn't stick to their own roadmap and blacklisted Symantec since April instead (Chrome 66 release). https://security.googleblog.com/2018/03/distrust-of-symantec...
Not sure why this is downvoted. It is correct.
Re: Distrust of Symantec TLS Certificates
#64Earlier quoted context omitted.
You mean this roadmap? https://security.googleblog.com/2017/09/chromes-plan-to-dist... That plan clearly states that all Symantec-issued certificates with a not-before date before June 1, 2016 would be distrusted in April. Is that not what happened?
Yes, this roadmap. It was not followed. All certificates were blacklisted in April, irrelevant of their date.
Re: Distrust of Symantec TLS Certificates
#65There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…
Re: Distrust of Symantec TLS Certificates
#66Earlier quoted context omitted.
You mean this roadmap? https://security.googleblog.com/2017/09/chromes-plan-to-dist... That plan clearly states that all Symantec-issued certificates with a not-before date before June 1, 2016 would be distrusted in April. Is that not what happened?
Yes, this roadmap. It was not followed. All certificates were blacklisted in April, irrelevant of their date.
Personally I think it’s bad practice to have a cert last more than a year in the first place, due to a number of both operational concerns and security concerns, but that is neither here nor there.
Re: Distrust of Symantec TLS Certificates
#67Earlier quoted context omitted.
Yes, this roadmap. It was not followed. All certificates were blacklisted in April, irrelevant of their date.
Are you sure? Paypal.com's Symantec-issued certificate still works in Chrome, at least on my PC: https://www.paypal.com/
If it were actually allowed, I would upload some of the certificates and write a blog post to show you.
Paypal has an EV, I don't have EV. Maybe these were not blacklisted. The rest was.
Re: Distrust of Symantec TLS Certificates
#68Re: Distrust of Symantec TLS Certificates
#69There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…
Well, a specific example that's going to bite _plenty_ of medium to large sized corporations is that you have a pattern like this: Big Corp's Division Z need a cert for their new web site https://www.division-z.example/ and so Bob buys it with his corporate credit card, and gives as contact details bob@bigcorp.example. He buys, let's say, a Verisign SSL certificate. Six months later Bob leaves to work at some other c…
But my point was that this is not some reckless sudden move by the browsers or DigiCert. In my observation, they have been earnestly and diligently working in good faith so people don't get bit by the transition.
Re: Distrust of Symantec TLS Certificates
#70Wow, I didn't realise how many non-conformances there were with Symantec. It certainly looks like they had enough chances to get their houses in order and didn't! I wonder what the root problem was? They didn't care, they didn't think anyone would do anything or they are just a large sloppy corporate who can't run a group properly?
Did Symantec's shareholders get the board responsible for this... replaced? Did they at least get a big cut in their wages given that they're apparently no good at their jobs? Nope.
The Web PKI in my not at all humble opinion is doing a better job of handling this problem today than, for example, many actual bona fide regulators. When Symantec kept trying to offer up little bits and pieces (e.g. let's wind up this lucrative Korean partnership programme we've secretly been running for years that had no effective oversight...) they were told it wasn't enough.
In the end this distrust that you're seeing now was mandatory but it was not intended as a "death sentence" for the Symantec CA function pe se. Symantec were told to go find somebody whose leadership we could trust, and let the trustworthy outfit physically run the CA (with Symantec's brands) while Symantec got their shit together and tried again in a year or two. In the process of negotiating such a deal with DigiCert Symantec instead sold their entire CA business to them, which everybody seems to have (in some cases grudgingly) accepted is a good enough outcome.
DigiCert did a better than might be expected job of this from a technical point of view, and I hope that it works for them commercially as a result.
[Edited for clarity]