Skip to content

Comment on CA:WoSign Issuesparent

Comments

I know a couple reasons for a backdated cert. Here's one that is easy to explain: backdated clients + emergencies. At least one in a million client devices is backdated by more than three days. It is therefore prudent to wait until a week or more past NotBefore before deploying a cert.

If you need a new certificate in a terrible rush, you can backdate.

Now, that's not what happened here. I would chalk this up to a cultural shift between the Americans and Europeans making the rules at the CA/B forum and the WoSign folks who honestly never imagined they would be expected to comply with rules that couldn't be checked---that a rule would say "don't sign sha-1 after Jan 1" as opposed to "don't sign sha-1 with a NotBefore after Jan 1."

Hm, that's a fair reason. But really what's important here is the fixed CT cutoff date. If you have mandatory CT from October 1 onwards, it seems fine to promise that you'll actually do CT for all certs with a notBefore of September 24 or later, and on October 1, you will stop issuing certs with a notBefore earlier than September 24.

(Of course the complexity now re-introduces some room for "honest" mistakes.)

They never imagined they would be expected to comply with rules they explicitly agreed to?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.