Safari will no longer trust certs valid for more than 13 months
theregister.co.uk
Safari will no longer trust certs valid for more than 13 months
1–10 of 179 posts
Re: Safari will no longer trust certs valid for more than 13 months
#2Re: Safari will no longer trust certs valid for more than 13 months
#3No joint announcement with other industry 'leaders' like Google and Microsoft? What is their stance on this? Will they be making similar changes to Chrome/Edge? And Mozilla? And maybe I am wrong but compromised certs are game over very soon aren't they? Reducing their lifetime to 'just' a year is still plenty of time to do enough damage seemingly, so what exactly does this high-handed change bring to the table? Anoth…
As for the other browsers, Google originally proposed SC22 (https://cabforum.org/pipermail/servercert-wg/2019-August/000...) last year and all the browsers voted for it. CAs voted it down at the time but there were rumblings via various back channels that several major CAs actually wanted the ballot to pass but for political reasons could not publicly support it.
So while Apple is acting “unilaterally” here, there is universal support among browser makers and tepid support from CAs. You should expect Google and Mozilla to follow suit in the next 6-12 months.
Re: Safari will no longer trust certs valid for more than 13 months
#4No joint announcement with other industry 'leaders' like Google and Microsoft? What is their stance on this? Will they be making similar changes to Chrome/Edge? And Mozilla? And maybe I am wrong but compromised certs are game over very soon aren't they? Reducing their lifetime to 'just' a year is still plenty of time to do enough damage seemingly, so what exactly does this high-handed change bring to the table? Anoth…
The goal is to promote automation and continue lowering certificate lifetimes as operations get better. This ultimately will allow for lifetimes short enough to be useful. As for the other browsers, Google originally proposed SC22 ( https://cabforum.org/pipermail/servercert-wg/2019-August/000... ) last year and all the browsers voted for it. CAs voted it down at the time but there were rumblings via various back chan…
EDIT: to clarify - there are two bad things about Let's Encrypt:
1. It's automated
2. It's free
The fact that it's automated results in less human intervention along the way, which on one hand lowers costs, on the other hand makes it detecting scams harder (unless they deploy some really Machine Learning that detects frauds).
The fact that it's free means that there's no credit card number or other info that would help identify actual person that requested certificate issuance.
Together those things make things less secure, not more.
EDIT 2: Both types of Let's Encrypt challenges look like pushing down the responsibility to either web server owner or DNS service. Maybe that's a good thing, since at least there's one fewer party that can screw things up.
Re: Safari will no longer trust certs valid for more than 13 months
#5Re: Safari will no longer trust certs valid for more than 13 months
#6No joint announcement with other industry 'leaders' like Google and Microsoft? What is their stance on this? Will they be making similar changes to Chrome/Edge? And Mozilla? And maybe I am wrong but compromised certs are game over very soon aren't they? Reducing their lifetime to 'just' a year is still plenty of time to do enough damage seemingly, so what exactly does this high-handed change bring to the table? Anoth…
Re: Safari will no longer trust certs valid for more than 13 months
#7I understand the reasons behind wanting to shorten certificate validity periods, but CA or root certificates often have expiration periods far into the future. What’s the argument for this? Ease of use? Historical reasons?
Re: Safari will no longer trust certs valid for more than 13 months
#8Earlier quoted context omitted.
The goal is to promote automation and continue lowering certificate lifetimes as operations get better. This ultimately will allow for lifetimes short enough to be useful. As for the other browsers, Google originally proposed SC22 ( https://cabforum.org/pipermail/servercert-wg/2019-August/000... ) last year and all the browsers voted for it. CAs voted it down at the time but there were rumblings via various back chan…
How will that automation verify that certificate is issued to the legal owner of the web site and not a hacker? Are the challenges used by Let's Encrypt secure? For me, automating certificate issuance will lead to less and less verification, to the point where having a valid certificate will become meaningless. EDIT: to clarify - there are two bad things about Let's Encrypt: 1. It's automated 2. It's free The fact th…
Re: Safari will no longer trust certs valid for more than 13 months
#9Earlier quoted context omitted.
The goal is to promote automation and continue lowering certificate lifetimes as operations get better. This ultimately will allow for lifetimes short enough to be useful. As for the other browsers, Google originally proposed SC22 ( https://cabforum.org/pipermail/servercert-wg/2019-August/000... ) last year and all the browsers voted for it. CAs voted it down at the time but there were rumblings via various back chan…
How will that automation verify that certificate is issued to the legal owner of the web site and not a hacker? Are the challenges used by Let's Encrypt secure? For me, automating certificate issuance will lead to less and less verification, to the point where having a valid certificate will become meaningless. EDIT: to clarify - there are two bad things about Let's Encrypt: 1. It's automated 2. It's free The fact th…
Re: Safari will no longer trust certs valid for more than 13 months
#10Earlier quoted context omitted.
The goal is to promote automation and continue lowering certificate lifetimes as operations get better. This ultimately will allow for lifetimes short enough to be useful. As for the other browsers, Google originally proposed SC22 ( https://cabforum.org/pipermail/servercert-wg/2019-August/000... ) last year and all the browsers voted for it. CAs voted it down at the time but there were rumblings via various back chan…
How will that automation verify that certificate is issued to the legal owner of the web site and not a hacker? Are the challenges used by Let's Encrypt secure? For me, automating certificate issuance will lead to less and less verification, to the point where having a valid certificate will become meaningless. EDIT: to clarify - there are two bad things about Let's Encrypt: 1. It's automated 2. It's free The fact th…