Live data from Hacker News

Remediation Plan for WoSign and StartCom

groups.google.com

41–50 of 54 posts

Re: Remediation Plan for WoSign and StartCom

#42
post #34
post #19

Earlier quoted context omitted.

That remains the plan.

> 1) Distrust certificates chaining up to Affected Roots with a notBefore date after October 21, 2016. > ... > 4) Remove the Affected Roots from NSS after the SSL certificates issued before October 1, 2016, have expired or have been replaced. This sounds more serious than that. It says they can re-apply for inclusion of new roots next June though. So in practice it might really be just a one-year ban, if they will ap…

A 1 year ban is a long time for a company that sells certs. It might be the end of Wosign.

Re: Remediation Plan for WoSign and StartCom

#43
post #36
post #23

I am glad this is happening. I have lost all trust in StartCom when they blatantly ignored the issues surrounding Heartbleed, refusing to renew certificates, despite every other CA doing so. I hope their learn their lesson, and try to be more honest in the future!

Small nitpick: StartCom refused to revoke certificates at the time, not renew them.

They wouldn't let you renew them either unless you revoked first...

Revocation cost $59 at the time. Was painful.

Re: Remediation Plan for WoSign and StartCom

#44
post #36
post #23

I am glad this is happening. I have lost all trust in StartCom when they blatantly ignored the issues surrounding Heartbleed, refusing to renew certificates, despite every other CA doing so. I hope their learn their lesson, and try to be more honest in the future!

Small nitpick: StartCom refused to revoke certificates at the time, not renew them.

StartCom refused to revoke certificates for free

Bad move

Re: Remediation Plan for WoSign and StartCom

#45
post #36

Earlier quoted context omitted.

Small nitpick: StartCom refused to revoke certificates at the time, not renew them.

They wouldn't let you renew them either unless you revoked first... Revocation cost $59 at the time. Was painful.

Certificates are very expensive with most providers, $59 is a bargain depending on your needs. The sole reason I've been staying with StartSSL is I've SSL'd all my subdomains (it's awesome for Postgres, for example), and a wildcard certificate costs $300 to $500 at all other shops.

By the way, anyone knows a cheaper wildcard certificate provider?

Re: Remediation Plan for WoSign and StartCom

#46

What does it take to build a Certificate Transparency log? Is this something that we could allow someone like the EFF/Let's Encrypt run?

Google open sourced their server implementation[1]. The problem that a number of CAs and other log operators have run into is that Google has rather strict requirements[2] for uptime and such (which makes sense!) if SCTs from that log server are to be accepted by Chrome, so you'd probably need a dedicated team capable of operating a HA cluster.

[1]: https://github.com/google/certificate-transparency

[2]: https://www.chromium.org/Home/chromium-security/certificate-...

Re: Remediation Plan for WoSign and StartCom

#47
post #45

Earlier quoted context omitted.

They wouldn't let you renew them either unless you revoked first... Revocation cost $59 at the time. Was painful.

Certificates are very expensive with most providers, $59 is a bargain depending on your needs. The sole reason I've been staying with StartSSL is I've SSL'd all my subdomains (it's awesome for Postgres, for example), and a wildcard certificate costs $300 to $500 at all other shops. By the way, anyone knows a cheaper wildcard certificate provider?

Give a look at https://cheapsslsecurity.com/

Re: Remediation Plan for WoSign and StartCom

#48
post #34

Earlier quoted context omitted.

> 1) Distrust certificates chaining up to Affected Roots with a notBefore date after October 21, 2016. > ... > 4) Remove the Affected Roots from NSS after the SSL certificates issued before October 1, 2016, have expired or have been replaced. This sounds more serious than that. It says they can re-apply for inclusion of new roots next June though. So in practice it might really be just a one-year ban, if they will ap…

A 1 year ban is a long time for a company that sells certs. It might be the end of Wosign.

Interestingly - this is a ban on their roots.

How much do you want to bet they're already working out how to supply new and renewing customers with certs provided by some other CA?

I notice the most recent StartSSL cert I got has a 3 year validity instead of their previous standard of 1 year - presumably in the hope that when my cert needs renewing they'll be able to provide that service. (I do have a handful of their certs which will expire during this 1 year ban. I'll certainly be needing to go elsewhere to renew them (finally time to learn how to auto-deploy LetEncrypt certs to Amazon ELB I guess, or maybe move all those domains to Route53 - I probably should have made time for that already...

Re: Remediation Plan for WoSign and StartCom

#49
post #45

Earlier quoted context omitted.

They wouldn't let you renew them either unless you revoked first... Revocation cost $59 at the time. Was painful.

Certificates are very expensive with most providers, $59 is a bargain depending on your needs. The sole reason I've been staying with StartSSL is I've SSL'd all my subdomains (it's awesome for Postgres, for example), and a wildcard certificate costs $300 to $500 at all other shops. By the way, anyone knows a cheaper wildcard certificate provider?

AWS offers free certificates, including free wildcard ones. I've only used them with other AWS services so I'm not sure how easy it would be to use one of them outside the AWS ecosystem.

Re: Remediation Plan for WoSign and StartCom

#50
post #34
post #19

Earlier quoted context omitted.

That remains the plan.

> 1) Distrust certificates chaining up to Affected Roots with a notBefore date after October 21, 2016. > ... > 4) Remove the Affected Roots from NSS after the SSL certificates issued before October 1, 2016, have expired or have been replaced. This sounds more serious than that. It says they can re-apply for inclusion of new roots next June though. So in practice it might really be just a one-year ban, if they will ap…

This sounds more serious than that

I think you're slightly misunderstanding the plan (assuming I have interpreted your post correctly)

[ Edit: I just re-read your final couple of paragraphs and you're basically saying the same thing I wrote below ]

Effectively WoSign's (and StartCom's) current root certificates are now dead and useless for any new issuance.

Under Mozilla's proposed course of action, existing end user certs that were signed by those roots are valid, but there will never any more.

But, at some point in the future WoSign and/or StartCom can generate new root certs and apply to have them included in Mozilla's CA store.

That "point in the future" is June 2017 for WoSign and maybe earlier for StartCom if they can prove that their not controlled by WoSign (it seems unlikely that they can prove that). Their application process will need to demonstrate that they're resolve the issues that got them into this trouble

Post reply on HN