Earlier quoted context omitted.
Because it's wrong. The very post GP linked explicitly says that Symantec certs issued before June 1, 2016 would stop functioning in Chrome 66.
Chrome also blacklisted certs issued after June 1, 2016.
Distrust of Symantec TLS Certificates
81–90 of 124 posts
Re: Distrust of Symantec TLS Certificates
#82Re: Distrust of Symantec TLS Certificates
#83PayPal's site is affected by this
That's surprising, because Chrome has distrusted Symantec certs for a few months and it's odd that Paypal would not have fixed it by now.
PayPal is a diehard Symantec company and will not abandon anything Symantec related until it is absolutely forced to.
Re: Distrust of Symantec TLS Certificates
#84It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.
Re: Distrust of Symantec TLS Certificates
#85Re: Distrust of Symantec TLS Certificates
#86All I can say is Firefox and Mozilla need to go away.
Re: Distrust of Symantec TLS Certificates
#87Earlier quoted context omitted.
Do you have a source for that? Google's KB articles still reference Chrome 70 [1], and I can't find another reference to this anywhere else. Paypal.com is still operating with a Symantec signed cert - issued by "Symantec Class 3 EV SSL CA - G3". Works fine in Chrome 68. (and not in Firefox with the security.pki.distrust_ca_policy override set) [1] https://support.google.com/chrome/a/answer/7662561?hl=en
I worked at a large company whose sole supplier was Symantec. Everything has been blacklisted since April.
Re: Distrust of Symantec TLS Certificates
#88Here is a better model. You normally register your company with the local government corporate registration authority. The local government knows who this company is, who the corporate registrars are.
One should use a digital ID card to apply to register a company. The founders sign the registration of the company with their personal digital ID. The company is then registered. To apply for a domain name for a company should be digitally signed. The registration government authority should handle certificate of authentic not foreign CA registrars.
All corporations should use Government CAs all other types of certificates can then be issued by Lets Encrypt having proper DNS validation in place should help there too.
All else is broken security by design.
Re: Distrust of Symantec TLS Certificates
#89Earlier quoted context omitted.
Are you sure? Paypal.com's Symantec-issued certificate still works in Chrome, at least on my PC: https://www.paypal.com/
I couldn't be more sure. My company had hundreds of certificates issued from Symantec, who was our main supplier. Basically, all our websites broke the day Chrome was updated. It was hell. If it were actually allowed, I would upload some of the certificates and write a blog post to show you. Paypal has an EV, I don't have EV. Maybe these were not blacklisted. The rest was.
The SSL certificate used to load resources from https://www.paypalobjects.com will be distrusted in M70. Once distrusted, users will be prevented from loading these resources. See https://g.co/chrome/symantecpkicerts for more information.
Re: Distrust of Symantec TLS Certificates
#90Earlier quoted context omitted.
You mean this roadmap? https://security.googleblog.com/2017/09/chromes-plan-to-dist... That plan clearly states that all Symantec-issued certificates with a not-before date before June 1, 2016 would be distrusted in April. Is that not what happened?
Yes, this roadmap. It was not followed. All certificates were blacklisted in April, irrelevant of their date.
www.McDonalds.com is another site with a non-EV certificate that will be blocked by Chrome 70, albeit with the GeoTrust brand instead of Symantec directly. Surely McDonalds has a large enough IT division to have noticed and updated by now if Chrome had been blocking their site since April.