Earlier quoted context omitted.
Do you have a source for that? Google's KB articles still reference Chrome 70 [1], and I can't find another reference to this anywhere else. Paypal.com is still operating with a Symantec signed cert - issued by "Symantec Class 3 EV SSL CA - G3". Works fine in Chrome 68. (and not in Firefox with the security.pki.distrust_ca_policy override set) [1] https://support.google.com/chrome/a/answer/7662561?hl=en
I worked at a large company whose sole supplier was Symantec. Everything has been blacklisted since April.
Distrust of Symantec TLS Certificates
71–80 of 124 posts
Re: Distrust of Symantec TLS Certificates
#72There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…
Well, a specific example that's going to bite _plenty_ of medium to large sized corporations is that you have a pattern like this: Big Corp's Division Z need a cert for their new web site https://www.division-z.example/ and so Bob buys it with his corporate credit card, and gives as contact details bob@bigcorp.example. He buys, let's say, a Verisign SSL certificate. Six months later Bob leaves to work at some other c…
Re: Distrust of Symantec TLS Certificates
#73Earlier quoted context omitted.
Sell more certificates, make more money. Anything which gets in the way of making more money (like security) should be reduced or eliminated, with the right touch you can get bonuses / promotions for meeting fiscal goals and leave your successor to deal with the aftermath. They might understand how certificates work but that doesn’t mean they know how to set up an organization with the right incentives to do it corre…
Interestingly, I looked up the symantec CEO. He was previously the ceo of Blue Coat. Blue Coat is a maker of man in the middle proxy appliances for businesses to spy on their employees. They controversially got root certificate authority. Which could of course be used to mitm SSL sites (which they promised and crossed their heart they would never do). https://www.theregister.co.uk/2016/05/27/blue_coat_ca_certs/
For users with Certificate Transparency checking (basically, Chrome) any dubious MITM certificates would have to be logged to show up as trusted public certificates. So there would not only be a smoking gun in the sense of the MITM cert being sent to all browsers that connected, it would be permanently preserved.
In addition Mozilla has an ongoing programme of trying to discover all the intermediate CAs that actually exist, partly because this occasions them to find various intermediates that probably _shouldn't_ exist and get them blacklisted. So this means if a intermediate exists and then you say you didn't realise it was being abused, you have the problem of explaining why you didn't report that it exists. If you say it's because you didn't know, it makes things worse - like if you say you didn't tell the IRS about the money because you got it when committing an armed robbery you weren't previously in the frame for - because that means your CA root was used to sign things you don't have a record of, and so obviously we can't trust your root any more...
Re: Distrust of Symantec TLS Certificates
#74Earlier quoted context omitted.
You mean this roadmap? https://security.googleblog.com/2017/09/chromes-plan-to-dist... That plan clearly states that all Symantec-issued certificates with a not-before date before June 1, 2016 would be distrusted in April. Is that not what happened?
Yes, this roadmap. It was not followed. All certificates were blacklisted in April, irrelevant of their date.
Re: Distrust of Symantec TLS Certificates
#75Earlier quoted context omitted.
Because it's wrong. The very post GP linked explicitly says that Symantec certs issued before June 1, 2016 would stop functioning in Chrome 66.
Chrome also blacklisted certs issued after June 1, 2016.
We had a bunch of RapidSSL certs in-use internally, and were rather pokey in replacing them since they were less-critical internal certs. Everything with the deprecation warnings were exactly as expected and announced.
I follow Mozilla's dev Security list and the CAB Forum mailing lists fairly regularly, can't find any discussions about Google deviating from their announced plan.
Re: Distrust of Symantec TLS Certificates
#76Re: Distrust of Symantec TLS Certificates
#77Earlier quoted context omitted.
Do you have a source for that? Google's KB articles still reference Chrome 70 [1], and I can't find another reference to this anywhere else. Paypal.com is still operating with a Symantec signed cert - issued by "Symantec Class 3 EV SSL CA - G3". Works fine in Chrome 68. (and not in Firefox with the security.pki.distrust_ca_policy override set) [1] https://support.google.com/chrome/a/answer/7662561?hl=en
I worked at a large company whose sole supplier was Symantec. Everything has been blacklisted since April.
Re: Distrust of Symantec TLS Certificates
#78There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…
Well, a specific example that's going to bite _plenty_ of medium to large sized corporations is that you have a pattern like this: Big Corp's Division Z need a cert for their new web site https://www.division-z.example/ and so Bob buys it with his corporate credit card, and gives as contact details bob@bigcorp.example. He buys, let's say, a Verisign SSL certificate. Six months later Bob leaves to work at some other c…
You don't have to get very big before these issues surface and cause tons of problems and toil.
Re: Distrust of Symantec TLS Certificates
#79Earlier quoted context omitted.
Chrome and Firefox have only distrusted Symantec certs in their pre-release versions. The Chrome 70 and Firefox 63 releases in mid-October are when the hammer will fall. https://security.googleblog.com/2018/03/distrust-of-symantec...
The hammer fell in April already. Google published a roadmap, the link you gave, but didn't respect it.
Re: Distrust of Symantec TLS Certificates
#80There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…
This is factually wrong. There wasn't plenty of warnings and google ignored their own roadmap. Google announced in October 2017 that they will block Symantec certificates in October 2018. Leaving a year to upgrade, fairly reasonable considering most certificates must be renewed early. However, Chrome blacklisted Symantec since April 2018, 6 months early. Taking a lot of people by surprise.
Nobody on the Internet appears to have noticed but you.
http://www.googblogs.com/distrust-of-the-symantec-pki-immedi... The timeline of alpha and beta releases may have confused you.