Skip to content

Comment on Entrust Certificate Distrust

Comments

All the google root security team's due diligence email are just a list of links to firefox's bugzilla who documented and followed up on all the issues.

https://groups.google.com/a/ccadb.org/g/public/c/29CRLOPM6OM...

In practice the Web PKI is overseen by the general public, via Mozilla's m.d.s.policy. It makes no sense for the proprietary vendors, including Google, to insist on doing something themselves badly when Mozilla is the obvious host for this work.

The older vendors are even less able to be properly open with their customers (let alone the general public) than Google. At Apple it's probably a firing offence to even confirm obvious decisions - it seemingly took months to get Apple's chosen representative to confirm that Apple's new 398 day rule was an issuance requirement, rather than just something where Apple wouldn't trust longer lived certs in Safari.

none of what you list are good excuses for anything. I fail to see the point. Is it that marketing trumps technical know how and it should be ok?

Representatives from the Chrome and Apple root programs participate in the Bugzilla discussions in an official capacity. But yes, there is significant help from the community in uncovering evidence and grilling CAs.

Mozilla's bugzilla is the de-facto site for coordinating issues in CA/B.

Any root program will refer to it for context on issues.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.