Live data from Hacker News

A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

follow.agwa.name

231–233 of 233 posts

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#231
post #52

Earlier quoted context omitted.

The problem here isn't really that one mis-issued certificate, but rather the general problematic behavior of that CA reported in TFA. If a CA can be convinced to issue a server certificate for google.com, would you feel very comfortable trusting their contract/deed/... signing certificates?

If the government says you need to use their CA, you may feel the feelings, but you will still use them

What would stop me from purging all this CA's certificates from my computet?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#232

Lol. "This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good." Yeah, this is after the certificate was issued, and my guess, used. Also, has anyone tried to look up CT logs lately? I tried. Can get maybe a single FQDN if you look, but trying to do wildcards or name-alikes, nothing worked. Most of th…

Wildcards work on crt.sh: https://crt.sh/?q=%25.ycombinator.com

Just wanting to add to my own comment...

crt.sh allows you to subscribe to an RSS feed for wildcard searches. We map those into a slack channel for infrastructure advisory alerts. You can also setup more aggressive alerts if something shows up unexpectedly.

It's an incredibly handy service.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#233

Earlier quoted context omitted.

Microsoft has nowhere near the power to change the PKI and/or DNS. And it's not an API problem, it's a problem of where companies go to get their legitimate certs. If there are a lot of companies getting their certs for international TLDs from country CAs, or country TLDs from international CAs, then you have to wait for huge systemic changes before enforcing any kind of TLD-CA relationship.

Microsoft has absolute power about the restrictions they support in their root store.

That's irrelevant. My whole point is that such restrictions go against the whole design of the PKI, at a systemic level. It's actively harmful to try to restrict trust in a CA to certificates for a certain TLD, because the two don't have any relationship whatsoever, by design.

It would be like restricting trust in a CA to certificates for sites whose name starts with a certain letter. It's exactly as meaningful from a Web PKI perspective.

Could Microsoft make it so that Windows only trusts this CA for certificates on domains whose name starts with a "b"? Sure. Would it help with anything? No. Would it be actively harmful to companies whose name starts with A that are using this CA? Yes. The same thing is true for domains whose name ends in .br.

Post reply on HN