I know a couple reasons for a backdated cert. Here's one that is easy to explain: backdated clients + emergencies. At least one in a million client devices is backdated by more than three days. It is therefore prudent to wait until a week or more past NotBefore before deploying a cert.
If you need a new certificate in a terrible rush, you can backdate.
Now, that's not what happened here. I would chalk this up to a cultural shift between the Americans and Europeans making the rules at the CA/B forum and the WoSign folks who honestly never imagined they would be expected to comply with rules that couldn't be checked---that a rule would say "don't sign sha-1 after Jan 1" as opposed to "don't sign sha-1 with a NotBefore after Jan 1."
Hm, that's a fair reason. But really what's important here is the fixed CT cutoff date. If you have mandatory CT from October 1 onwards, it seems fine to promise that you'll actually do CT for all certs with a notBefore of September 24 or later, and on October 1, you will stop issuing certs with a notBefore earlier than September 24.
(Of course the complexity now re-introduces some room for "honest" mistakes.)
Comments
I know a couple reasons for a backdated cert. Here's one that is easy to explain: backdated clients + emergencies. At least one in a million client devices is backdated by more than three days. It is therefore prudent to wait until a week or more past NotBefore before deploying a cert.
If you need a new certificate in a terrible rush, you can backdate.
Now, that's not what happened here. I would chalk this up to a cultural shift between the Americans and Europeans making the rules at the CA/B forum and the WoSign folks who honestly never imagined they would be expected to comply with rules that couldn't be checked---that a rule would say "don't sign sha-1 after Jan 1" as opposed to "don't sign sha-1 with a NotBefore after Jan 1."
Hm, that's a fair reason. But really what's important here is the fixed CT cutoff date. If you have mandatory CT from October 1 onwards, it seems fine to promise that you'll actually do CT for all certs with a notBefore of September 24 or later, and on October 1, you will stop issuing certs with a notBefore earlier than September 24.
(Of course the complexity now re-introduces some room for "honest" mistakes.)
They never imagined they would be expected to comply with rules they explicitly agreed to?