Remediation Plan for WoSign and StartCom
41–50 of 54 posts
Re: Remediation Plan for WoSign and StartCom
#42Earlier quoted context omitted.
That remains the plan.
> 1) Distrust certificates chaining up to Affected Roots with a notBefore date after October 21, 2016. > ... > 4) Remove the Affected Roots from NSS after the SSL certificates issued before October 1, 2016, have expired or have been replaced. This sounds more serious than that. It says they can re-apply for inclusion of new roots next June though. So in practice it might really be just a one-year ban, if they will ap…
Re: Remediation Plan for WoSign and StartCom
#43I am glad this is happening. I have lost all trust in StartCom when they blatantly ignored the issues surrounding Heartbleed, refusing to renew certificates, despite every other CA doing so. I hope their learn their lesson, and try to be more honest in the future!
Small nitpick: StartCom refused to revoke certificates at the time, not renew them.
Revocation cost $59 at the time. Was painful.
Re: Remediation Plan for WoSign and StartCom
#44I am glad this is happening. I have lost all trust in StartCom when they blatantly ignored the issues surrounding Heartbleed, refusing to renew certificates, despite every other CA doing so. I hope their learn their lesson, and try to be more honest in the future!
Small nitpick: StartCom refused to revoke certificates at the time, not renew them.
Bad move
Re: Remediation Plan for WoSign and StartCom
#45Earlier quoted context omitted.
Small nitpick: StartCom refused to revoke certificates at the time, not renew them.
They wouldn't let you renew them either unless you revoked first... Revocation cost $59 at the time. Was painful.
By the way, anyone knows a cheaper wildcard certificate provider?
Re: Remediation Plan for WoSign and StartCom
#46What does it take to build a Certificate Transparency log? Is this something that we could allow someone like the EFF/Let's Encrypt run?
[1]: https://github.com/google/certificate-transparency
[2]: https://www.chromium.org/Home/chromium-security/certificate-...
Re: Remediation Plan for WoSign and StartCom
#47Earlier quoted context omitted.
They wouldn't let you renew them either unless you revoked first... Revocation cost $59 at the time. Was painful.
Certificates are very expensive with most providers, $59 is a bargain depending on your needs. The sole reason I've been staying with StartSSL is I've SSL'd all my subdomains (it's awesome for Postgres, for example), and a wildcard certificate costs $300 to $500 at all other shops. By the way, anyone knows a cheaper wildcard certificate provider?
Re: Remediation Plan for WoSign and StartCom
#48Earlier quoted context omitted.
> 1) Distrust certificates chaining up to Affected Roots with a notBefore date after October 21, 2016. > ... > 4) Remove the Affected Roots from NSS after the SSL certificates issued before October 1, 2016, have expired or have been replaced. This sounds more serious than that. It says they can re-apply for inclusion of new roots next June though. So in practice it might really be just a one-year ban, if they will ap…
A 1 year ban is a long time for a company that sells certs. It might be the end of Wosign.
How much do you want to bet they're already working out how to supply new and renewing customers with certs provided by some other CA?
I notice the most recent StartSSL cert I got has a 3 year validity instead of their previous standard of 1 year - presumably in the hope that when my cert needs renewing they'll be able to provide that service. (I do have a handful of their certs which will expire during this 1 year ban. I'll certainly be needing to go elsewhere to renew them (finally time to learn how to auto-deploy LetEncrypt certs to Amazon ELB I guess, or maybe move all those domains to Route53 - I probably should have made time for that already...
Re: Remediation Plan for WoSign and StartCom
#49Earlier quoted context omitted.
They wouldn't let you renew them either unless you revoked first... Revocation cost $59 at the time. Was painful.
Certificates are very expensive with most providers, $59 is a bargain depending on your needs. The sole reason I've been staying with StartSSL is I've SSL'd all my subdomains (it's awesome for Postgres, for example), and a wildcard certificate costs $300 to $500 at all other shops. By the way, anyone knows a cheaper wildcard certificate provider?
Re: Remediation Plan for WoSign and StartCom
#50Earlier quoted context omitted.
That remains the plan.
> 1) Distrust certificates chaining up to Affected Roots with a notBefore date after October 21, 2016. > ... > 4) Remove the Affected Roots from NSS after the SSL certificates issued before October 1, 2016, have expired or have been replaced. This sounds more serious than that. It says they can re-apply for inclusion of new roots next June though. So in practice it might really be just a one-year ban, if they will ap…
I think you're slightly misunderstanding the plan (assuming I have interpreted your post correctly)
[ Edit: I just re-read your final couple of paragraphs and you're basically saying the same thing I wrote below ]
Effectively WoSign's (and StartCom's) current root certificates are now dead and useless for any new issuance.
Under Mozilla's proposed course of action, existing end user certs that were signed by those roots are valid, but there will never any more.
But, at some point in the future WoSign and/or StartCom can generate new root certs and apply to have them included in Mozilla's CA store.
That "point in the future" is June 2017 for WoSign and maybe earlier for StartCom if they can prove that their not controlled by WoSign (it seems unlikely that they can prove that). Their application process will need to demonstrate that they're resolve the issues that got them into this trouble