Fina Root CA signs certificates for 1.1.1.1
1–6 of 6 posts
Re: Fina Root CA signs certificates for 1.1.1.1
#2[deleted]
Re: Fina Root CA signs certificates for 1.1.1.1
#3This CA is trusted only by Microsoft. I and others have reported problematic CAs to Microsoft in the past (though this particular one wasn't on my radar) only for our concerns to be ignored. Mozilla, Chrome, and Apple have actual standards and don't trust CAs like this.
Re: Fina Root CA signs certificates for 1.1.1.1
#4Should Cloudflare have been monitoring CT logs to spot this earlier?
Re: Fina Root CA signs certificates for 1.1.1.1
#5Should Cloudflare have been monitoring CT logs to spot this earlier?
We definitely should have, and that is on us. We'll fix it. https://blog.cloudflare.com/unauthorized-issuance-of-certifi...
Re: Fina Root CA signs certificates for 1.1.1.1
#6This CA is trusted only by Microsoft. I and others have reported problematic CAs to Microsoft in the past (though this particular one wasn't on my radar) only for our concerns to be ignored. Mozilla, Chrome, and Apple have actual standards and don't trust CAs like this.
It's also trusted as an EU Trust Service Provider. https://eidas.ec.europa.eu/efda/trust-services/browse/eidas/...
That's basically QWACS.
Ah, of course you mentioned it in the other thread!