Skip to content

Comment on Entrust Certificate Distrust

Comments

I’m one of the people who really went in depth with Entrust (Amir on Bugzilla).

I’m also an author on https://webpki.substack.com. I will be writing my thoughts on the distrust soon.

I can try to answer any questions folks may have. I can also help folks find ways they can also be involved!

Root programs can only do so much and need surveillance of the CAs from the community.

I am a layperson so I appreciate the attention on the matter.

Regardless of how Entrust is operated, there appears to be significant complexity in CA program that the browsers operate. On the flip side, Let’s Encrypt is basically effortless for me to use, as an end user of an LE secured site and as a developer. Why misallocate all this toil on root CA compliance on the one hand, when LE could redirect that labor towards something valuable instead? What is so challenging about giving LE full leadership on this issue? Where does the proverbial political strength of Entrust and similar entities come from, in an ecosystem where there are functionally 5 cooperating, more or less transparent entities that decide the trust of certificates for 99% of end users? Why does anyone care about any of the CAs?

Let's Encrypt is just a player in the same ecosystem. Effectively they're no different from Entrust, GoDaddy, Google Trust Services, Digicert, Sectigo, etc etc.

Let's Encrypt started their operations with _automated_ certificate issuance only. They also do not do OV/EV certificates that are much, much harder to automate without providing any real benefits.

So, LE's mission is to issue certificates under the rules set by CAs and Browsers. (Yes, CAs do participate in setting up rules for CAs.

Where does the proverbial political strength of Entrust and similar entities come from

Generally supporting non-automated certificate issuance. Effectively, technical debt. A lot of older enterprises have done manual certificate issuance, and they don't feel the pressure/reason to switch.

LE has to comply with the root CA standards too. For a variety of reasons there haven't been as many problems with LE - partly because they don't get paid by folks getting certs and issuing certs is a cost to them so their incentives are different.

I don't get entrust here. It's not like they weren't told what to do.

Simplicity is a shortcut to correctness. Let's Encrypt is a simple thing to implement. Relatively speaking of course. It would be tempting (unbearably so for a for-profit issuer) to have manual issuance, this means at least duplicating the effort as every system can also be manual and must have the appropriate checks in place for that.

As an example of how wedded Let's Encrypt is to simplicity, part of routine application process is to show your certificates expire properly, often a CA would manually create a certificate which either was already expired (back dating it but arguably this is allowed for technical procedures) or had a very short lifetime and so would expire by the time the trust programme examines the demo cert. Let's Encrypt instead issued an ordinary 90 day certificate, using the same automatic process as their subscribers - and then just waited months for it to expire. Like a boss.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.