Just curious about the root certificate distrust--are users capable of re-adding trust to distrusted certificates? Or is this hard coded into the browser? I'm assuming Mozilla stores certificates outside OS stores like Keychain and Windows?
Yes but why would you? If you have control of all your clients to push such a change, why not just set up a private CA instead of opening yourself up to the whims of a proven cheating CA?
Remediation Plan for WoSign and StartCom
31–40 of 54 posts
Re: Remediation Plan for WoSign and StartCom
#32What did I miss? Last I heard about this, the plan was to ban them from issuing new certificates for a year. Did something change?
They admitted they screwed up and the CEO stepped down.
Re: Remediation Plan for WoSign and StartCom
#33Earlier quoted context omitted.
Yes but why would you? If you have control of all your clients to push such a change, why not just set up a private CA instead of opening yourself up to the whims of a proven cheating CA?
Less difficult. Setting up a private CA means you have to be the CA, and vet and/or create a cert for every wosign/startcom site that people visit. One could trust them just enough depending on how heavily they depend on affected sites. I personally would rather whitelist sites as-needed, but can see why some admins would go the easier route.
Re: Remediation Plan for WoSign and StartCom
#34What did I miss? Last I heard about this, the plan was to ban them from issuing new certificates for a year. Did something change?
That remains the plan.
> ...
> 4) Remove the Affected Roots from NSS after the SSL certificates issued before October 1, 2016, have expired or have been replaced.
This sounds more serious than that. It says they can re-apply for inclusion of new roots next June though. So in practice it might really be just a one-year ban, if they will apply and pass the inclusion process.
Re: Remediation Plan for WoSign and StartCom
#35Earlier quoted context omitted.
Less difficult. Setting up a private CA means you have to be the CA, and vet and/or create a cert for every wosign/startcom site that people visit. One could trust them just enough depending on how heavily they depend on affected sites. I personally would rather whitelist sites as-needed, but can see why some admins would go the easier route.
Existing certs will continue to work until they expire. So "re-adding trust" to WoSign doesn't make sense. No sane site operator would renew their cert with WoSign since they will lose all Firefox and Apple clients.
Re: Remediation Plan for WoSign and StartCom
#36I am glad this is happening. I have lost all trust in StartCom when they blatantly ignored the issues surrounding Heartbleed, refusing to renew certificates, despite every other CA doing so. I hope their learn their lesson, and try to be more honest in the future!
Re: Remediation Plan for WoSign and StartCom
#37Re: Remediation Plan for WoSign and StartCom
#381. https://groups.google.com/forum/#!topic/mozilla.dev.security...
Re: Remediation Plan for WoSign and StartCom
#39Re: Remediation Plan for WoSign and StartCom
#40I dont like this route. The only value for the WoSign keys for a whole year would be issuing certificates with a doctored notBefore date, and they can't do that publically.