Why 6 day and not 8? - 8 is a lucky number and a power of 2 - 8 lets me refresh weekly and have a fixed day of the week to check whether there was some API 429 timeout - 6 is the value of every digit in the number of the beast - I just don't like 6!
> 8 lets me refresh weekly and have a fixed day of the week to check whether there was some API 429 timeout There’s your answer. 6 days means on a long enough enough timeframe the load will end up evenly distributed across a week. 8 days would result in things getting hammered on specific days of the week.
6-Day and IP Address Certificates Are Generally Available
211–220 of 290 posts
Re: 6-Day and IP Address Certificates Are Generally Available
#212Earlier quoted context omitted.
> No dependency on a registrar sounds nice. Actually the main benefit is no dependency on DNS (booth direct and root). IP is a simple primitive, i.e. "is it routable or not ?".
The popular HTTP validation method has the same drawback whether using DNS or IP certificates? Namely, if you can compromise routes to hijack traffic, you can also hijack the validation requests. Right?
1) How to secure routing information: some says RPKI, some argues that's not enough and are experimenting with something like SCION (https://docs.scion.org/en/latest/)
2) Principal-Agent problem: jabber.ru's hijack relied on (presumably) Hetzner being forced to do it by German law agents based on the powers provided under the German Telecommunications Act (TKG)
Re: 6-Day and IP Address Certificates Are Generally Available
#213Earlier quoted context omitted.
All major root store programs (Chrome, Apple, Microsoft, Mozilla) have this power. They set the requirements that CAs must follow to be included in their root store, and for most CAs their certs would be useless if they aren't included in all major ones. I don't think the root programs take these kind of decisions lightly and I don't see any selfish motives they could have. They need to find a balance between not ove…
The "client cert" requirements were specifically not a CABF rule because that would rule it out for everyone complying with those rules, which is much broader than just the CAs included in Chrome. Some CAs will continue to run PKIs which support client certs, for use outside of Chrome. In general, the "baseline requirements" are intended to be just that: A shared baseline that is met by everyone. All the major root p…
Right, that explains it. So the use would be for things other than websites or for websites that don't need to support Chrome (and also need clientAuth)?
I guess I find it hard to wrap my head around this because I don't have experience with any applications where this plus a publicly trusted certificate makes sense. But I suppose they must exist, otherwise there would've been an effort to vote it into the BRs.
If you or someone else here knows more about these use cases, then I'd like to hear about it to better understand this.
Re: 6-Day and IP Address Certificates Are Generally Available
#214Re: 6-Day and IP Address Certificates Are Generally Available
#215Earlier quoted context omitted.
1) For better or worse, code signing certificates are expected to come with some degree of organizational verification. No one would trust a domain-validated code signing cert, especially not one which was issued with no human involvement. 2) App stores review apps because they want to verify functionality and compliance with rules, not just as a box-checking exercise. A code signing cert provides no assurances in th…
They can just do id verification instead of domain, either in-house or outsource it. app store review isn't what I was talking about, I meant not having to verify your identity with the appstore, and use your own signing cert which can be used between platforms. Moreover, it would be less costly to develop signed windows apps. It costs several hundred dollars today.
That's pretty reasonable, considering it is built in to all the major code signing tools on Windows, they perform the identity verification, and the private keys are fully managed by Azure. Code signing certs are required to be on HSMs, so you're most likely going to be paying some cloud CA anyway.
Re: 6-Day and IP Address Certificates Are Generally Available
#216Re: 6-Day and IP Address Certificates Are Generally Available
#217Why 6 day and not 8? - 8 is a lucky number and a power of 2 - 8 lets me refresh weekly and have a fixed day of the week to check whether there was some API 429 timeout - 6 is the value of every digit in the number of the beast - I just don't like 6!
Re: 6-Day and IP Address Certificates Are Generally Available
#218Re: 6-Day and IP Address Certificates Are Generally Available
#219Earlier quoted context omitted.
About 99.99% of people and organisations are neither CAs nor Browsers. Hence they have no representation in the CAB Forum. Hardly 'by definition niche' IMHO.
The pitch here wasn't that only a few people get a vote, it was that the people making the decisions aren't aware of how "the wider world" works. And they are, clearly. The people making Chrome/Firefox and the people running the CAs every publicly-trusted site uses are aware of what their products do, and how they are used.
So great for E-Commerce, not so great for anyone else.
Re: 6-Day and IP Address Certificates Are Generally Available
#220Earlier quoted context omitted.
Because it allows to you to work for six days, and rest on the seventh. Like God did.
² By the seventh day God had finished the work He had been doing; so on the seventh day He rested from all His work. ³ Then the on-call tech, Lucifer, the Son of Dawn, was awoken at midnight because God did not renew the heavens' and the earths' HTTPS certificate. ⁴ Thusly Lucifer drafted his resignation in a great fury.