SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Game Over for WoSign and StartCom Certificate Authorities?
Date    Tuesday September 27 2016, @07:23AM
Author    martyb
Topic   
from the who-CAN-you-trust? dept.
https://soylentnews.org/article.pl?sid=16/09/27/0142212

zocalo writes:

Over the last several months Mozilla has been investigating a large number of breaches of what Mozilla deems to be acceptable CA protocols by the Chinese root CA WoSign and their perhaps better known subsidiary StartCom, whose acquistion by WoSign is one of the issues in question. Mozilla has now published their proposed solution (GoogleDocs link), and it's not looking good for WoSign and Startcom. Mozilla's position is that they have lost trust in WoSign and, by association StartCom, with a proposed action to give WoSign and StartCom a "timeout" by distrusting any certificates issued after a date to be determined in the near future for a period of one year, essentially preventing them issuing any certificates that will be trusted by Mozilla. Attempts to circumvent this by back-dating the valid-from date will result in an immediate and permanent revocation of trust, and there are some major actions required to re-establish that trust at the end of the time out as well.

This seems like a rather elegant, if somewhat draconian, solution to the issue of what to do when a CA steps out of line. Revoking trust for certificates issued after a given date does not invalidate existing certificates and thereby inconvenience their owners, but it does put a severe - and potentially business ending - penalty on the CA in question. Basically, WoSign and StartCom will have a year where they cannot issue any new certificates that Mozilla will trust, and will also have to inform any existing customers that have certificate renewals due within that period they cannot do so and they will need to go else where - hardly good PR!

What do the Soylentils think? Is Mozilla going too far here, or is their proposal justified and reasonable given WoSign's actions, making a good template for potential future breaches of trust by root CAs, particularly in the wake of other CA trust breaches by the likes of CNNIC, DigiNotar, and Symantec?

It appears this situation developed from this discussion at Google Groups.

[Editor's Note: SoylentNews used StartCom certificates in the past but we now use only certificates from Gandi and "Let's Encrypt."]


Original Submission

Links

  1. "zocalo" - https://soylentnews.org/~zocalo/
  2. "a large number" - https://wiki.mozilla.org/CA:WoSign_Issues
  3. "published their proposed solution" - https://docs.google.com/document/d/1C6BlmbeQfn4a9zydVi2UvjBGv6szuSB4sMYUcVrR8vQ/preview
  4. "CNNIC" - https://soylentnews.org/article.pl?sid=15/04/07/2111201
  5. "DigiNotar" - https://threatpost.com/final-report-diginotar-hack-shows-total-compromise-ca-servers-103112/77170/
  6. "Symantec?" - http://www.pcworld.com/article/3014712/security/google-to-revoke-trust-in-a-symantec-root-certificate.html
  7. "developed from this discussion at Google Groups" - https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/k9PBmyLCi8I[1-25]
  8. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=16069

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Game Over for WoSign and StartCom Certificate Authorities? on 2024-04-24 16:20:50