There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…
Distrust of Symantec TLS Certificates
111–120 of 124 posts
Re: Distrust of Symantec TLS Certificates
#112There's two problems this exposes. One, it takes a very long time to dis-trust a root cert. This means some people's connections could be exposed for a very long time. Two, the method for update shown here is to upgrade your browser. Not everyone can upgrade their browser. Corporations often lock down browser updates, and take a very long time to upgrade. Sure, it's fine for you to say "that's the corporation's fault…
Moving on past that, I think you've hit the nail on the head. CAs are about having a root for tree of trust. CAA and DANE are about ensuring that. I'm very curious how you imagine an improved, innovative solution to assuring trust!
I've seen proposals like Namecoin, which are innovative but fail the test of being improved.
Re: Distrust of Symantec TLS Certificates
#113There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…
Re: Distrust of Symantec TLS Certificates
#114I was getting frustrated because I could not visit Paypal (and Ebay) with Firefox nightly, because thy still use the old Symantec TLS certificates. I wonder whether there is _any_ major party that should be more concerned with their certificates than Paypal.
Re: Distrust of Symantec TLS Certificates
#115My favorite story is when Mark Shuttleworth sold Thawte to VeriSign and used the money to start Canonical. This shows one of the problems of the current debt-based economy.
> Canonical
> debt-based economy
What do any of those things have anything to do with Symantec certificates being distrusted?
Re: Distrust of Symantec TLS Certificates
#116My favorite story is when Mark Shuttleworth sold Thawte to VeriSign and used the money to start Canonical. This shows one of the problems of the current debt-based economy.
> Mark Shuttleworth > Canonical > debt-based economy What do any of those things have anything to do with Symantec certificates being distrusted?
Re: Distrust of Symantec TLS Certificates
#117Earlier quoted context omitted.
As I understand it, Chrome and Firefox are both operating under the same policies with about the same timetables. Full distrust doesn't come until Firefox 63 / Chrome 70 - neither of which are stable releases yet. The limited distrust (for older certs issued prior to June 2016) was activated in Firefox 60 and Chrome 66 much earlier this year.
That's factually incorrect. Google blacklisted ALL Symantec certificates since Chrome 66, in April. The roadmap announced the change for October but they did it 6 months earlier, ignoring their own roadmap. As the OP says, organizations using Symantec have already been hit very hard, by surprise.
"The SSL certificate used to load resources from https://(domain) will be distrusted in M70. Once distrusted, users will be prevented from loading these resources. See https://g.co/chrome/symantecpkicerts for more information."
Everything was being done in 2 waves. First wave was Chrome 66, second wave is Chrome 70. See Google's link above for the specifics.
Source: Chrome's own warnings and that I work for a business that deals heavily in SSL sales.
Re: Distrust of Symantec TLS Certificates
#118It's been obvious to me for quite a while that EV etc only really tells you "this person paid $$$ to get a cert" rather than anything about the site being trustworthy or being who it says it is. I wouldn't bat an eye if 10 years from now major browsers distrusted everything but letsencrypt. Once the letsencrypt project comes out with a comparable solution for code signing, there is really no more reason for paid cert…
Re: Distrust of Symantec TLS Certificates
#119I've got a question about this, as I've been hurled into the admin of our certs, and honestly I probably shouldn't be the one to do it, lol. But, we run root certs from DigiCert with the rest of the chain provided by RapidSSL. However, I have not received any depreciation warnings via email or any notification in the console output on these sites. Is there a utility available to "check" our sites, in the same way ven…
Re: Distrust of Symantec TLS Certificates
#120There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…
I understand the rationale behind all of this, but I would get pissed off if Google sent me an email that basically says "do what we tell you to do or we will take your website offline"
What's happening is "update your security on the thing that you have already got security on, or else at least two of the most popular browsers will mark it as insecure; also, you will lose points in our search engine".