Live data from Hacker News

Please remove StartCom Certification Authority root certificate

bugs.debian.org

1–10 of 48 posts

Re: Please remove StartCom Certification Authority root certificate

#5
Seems unlikely to happen based on what was said in the thread.

> Whatever you and I think of this pricing structure, people free to chose any provider of certificates that matches their pricing interest and that people are knowingly or should be knowlingly buying a product that has a certain price structure when they get the certificates in the first place.

> Revoking a certificate is generally primarily in the interest of the owner of said certificate so there is incentive to actually pay this fee.

> I do not believe it is Debian's place to pass judgement on which pricing scheme people should prefer, even if you and I personally rather pay up front and have no costs on revocation.

Re: Please remove StartCom Certification Authority root certificate

#6
post #3

Solution 3: cease trusting StartSSL certs issued before 2014-04-07? This is implied by the request itself but is it possible to implement?

This is actually not enough as you cannot be sure that certificates generated after that have never been used on a server with a vulnerable OpenSSL implementation.

Re: Please remove StartCom Certification Authority root certificate

#7
Either this request is naive, or I am.

As I understand it, not all StartCom certificates are necessarily vulnerable. I have a number of StartSSL certificates issued before 4/7 that, according to the HeartBleed checker here[1] are not vulnerable.

Is it wrong for me to assume that the tool is correct, or is it wrong to assume that all StartCom certificates are necessarily vulnerable?

[1] - http://filippo.io/Heartbleed/

Re: Please remove StartCom Certification Authority root certificate

#9
post #7

Either this request is naive, or I am. As I understand it, not all StartCom certificates are necessarily vulnerable. I have a number of StartSSL certificates issued before 4/7 that, according to the HeartBleed checker here[1] are not vulnerable. Is it wrong for me to assume that the tool is correct, or is it wrong to assume that all StartCom certificates are necessarily vulnerable? [1] - http://filippo.io/Heartbleed/

I don't think the certificates are vulnerable at all. Their private keys may have been stolen if people were using them with a vulnerable version of OpenSSL, but that has nothing to do with StartSSL certificates themselves.

Re: Please remove StartCom Certification Authority root certificate

#10
post #7

Either this request is naive, or I am. As I understand it, not all StartCom certificates are necessarily vulnerable. I have a number of StartSSL certificates issued before 4/7 that, according to the HeartBleed checker here[1] are not vulnerable. Is it wrong for me to assume that the tool is correct, or is it wrong to assume that all StartCom certificates are necessarily vulnerable? [1] - http://filippo.io/Heartbleed/

> is it wrong to assume that all StartCom certificates are necessarily vulnerable?

They aren't claiming all StartCom certificates are vulnerable, they are saying some StartCom certificates may be vulnerable because they impose a fee on revocation.

Post reply on HN