The real question is: why didn't they get booted out earlier?
Entrust Certificate Distrust
11–20 of 118 posts
Re: Entrust Certificate Distrust
#12Can someone ELI5 what the violations linked in the first line are? They seem pretty minor to me but I don't understand certs
Entrust missed/ignored the updates to how certificates were supposed to be formed and when caught declined to revoke the incorrectly issued ones (because it's probably a more or less manual process for many admins working in a pre-Let's Encrypt style of fashion) and they didn't want to inconvenience their customers and assumed that they themselves were the important party in the equation (CA's was that historically compared to site-admins).
The certificate industry has always been quite ad-hoc with CA's being entitled middlemen, we have Let's Encrypt and almost ubiquitous encryption now because browser makers and other internet actors saw security as more important than protecting the CA's business and now that LE is established Google,etc aren't the slightest interested in pampering CAs if they aren't interested in cleaning up the system.
Re: Entrust Certificate Distrust
#13it looks like Entrust is selling on the order of a few dozen certs a week to maybe upwards of 100-200.
EDIT: I've asked Google if Gmail will be discontinuing support for Entrusts VMC certificate (and thus BIMI logos), I would guess not since BIMI has some actual requirements, but assumptions are not the best way to make decisions about risk (like our BIMI logo not working later this fall).
Re: Entrust Certificate Distrust
#14Can someone ELI5 what the violations linked in the first line are? They seem pretty minor to me but I don't understand certs
Re: Entrust Certificate Distrust
#15I’m also an author on https://webpki.substack.com. I will be writing my thoughts on the distrust soon.
I can try to answer any questions folks may have. I can also help folks find ways they can also be involved!
Root programs can only do so much and need surveillance of the CAs from the community.
Re: Entrust Certificate Distrust
#16Re: Entrust Certificate Distrust
#17I wonder which root CA the intelligence agencies use to selectively MITM TLS traffic a la Crypto AG.
Re: Entrust Certificate Distrust
#18Re: Entrust Certificate Distrust
#19I wonder if Entrust can survive this. Even if Web-PKI doesn't account for the majority of their income (which it might, I genuinely don't know) this is a huge blow to their credibility. And for a CA, credibility is everything