Live data from Hacker News

Entrust Certificate Distrust

security.googleblog.com

11–20 of 118 posts

Re: Entrust Certificate Distrust

#11

The real question is: why didn't they get booted out earlier?

Probably worried that it would break something for a significant number of customers, so they took a cautious approach. That's the problem with any Internet-wide change: you don't always know who will be impacted negatively or how severely. No one wants to make a quick change only to find out some critical system is now broken.

Re: Entrust Certificate Distrust

#12
post #9

Can someone ELI5 what the violations linked in the first line are? They seem pretty minor to me but I don't understand certs

Since contents of certificates contents sadly often diff there was a ballot to streamline the contents to lessen the burden on implementations to interpret the differences.

Entrust missed/ignored the updates to how certificates were supposed to be formed and when caught declined to revoke the incorrectly issued ones (because it's probably a more or less manual process for many admins working in a pre-Let's Encrypt style of fashion) and they didn't want to inconvenience their customers and assumed that they themselves were the important party in the equation (CA's was that historically compared to site-admins).

The certificate industry has always been quite ad-hoc with CA's being entitled middlemen, we have Let's Encrypt and almost ubiquitous encryption now because browser makers and other internet actors saw security as more important than protecting the CA's business and now that LE is established Google,etc aren't the slightest interested in pampering CAs if they aren't interested in cleaning up the system.

Re: Entrust Certificate Distrust

#13
Entrust has BIMI certs which use a different root (CN = Entrust Verified Mark Root Certification Authority - VMCR1) and for which your choices of a BIMI certificate are: Entrust or Digicert. I doubt it makes as much money as their web certs (BIMI certs are not super common, and they are expensive to issue since there's an actual validation process that typically involves a public notary validating the ID of a corporate officer). If you believe https://bimiradar.com/glob

it looks like Entrust is selling on the order of a few dozen certs a week to maybe upwards of 100-200.

EDIT: I've asked Google if Gmail will be discontinuing support for Entrusts VMC certificate (and thus BIMI logos), I would guess not since BIMI has some actual requirements, but assumptions are not the best way to make decisions about risk (like our BIMI logo not working later this fall).

Re: Entrust Certificate Distrust

#14
post #9

Can someone ELI5 what the violations linked in the first line are? They seem pretty minor to me but I don't understand certs

They are very minor, but because the consequences of an mis-issued certificate can be so high, there’s an explicit policy that misissued certificates must be revoked and reissued promptly. The distrust was due to them refusing to comply with the policy and outright stating that they did not intend to comply in future incidents either.

Re: Entrust Certificate Distrust

#15
I’m one of the people who really went in depth with Entrust (Amir on Bugzilla).

I’m also an author on https://webpki.substack.com. I will be writing my thoughts on the distrust soon.

I can try to answer any questions folks may have. I can also help folks find ways they can also be involved!

Root programs can only do so much and need surveillance of the CAs from the community.

Re: Entrust Certificate Distrust

#19
post #5

I wonder if Entrust can survive this. Even if Web-PKI doesn't account for the majority of their income (which it might, I genuinely don't know) this is a huge blow to their credibility. And for a CA, credibility is everything

Entrust makes a ton of revenue from hardware-related products (for example, printing ID cards), so it is far from the end.
Post reply on HN