Package: ca-certificates Version: 20141019+deb8u2 Severity: important Tags: security
Hi, StartCom and WoSign certificates are now untrusted by the major browser vendors[0][1], making websites that use certs from these vendors inaccessible. However, as this is not reflected in ca-certificates, tools such as curl still intepret these as valid/secure. (This has a knock-on effect that health-check tools that use the output of such tools to determine whether a site is "up" — eg. updown.io — will misleadingly imply that the site is available to users when, in all practical senses, they are not.) I would suggest we remove the offending authorities from ca-certificates as soon as possible. [0] https://blog.mozilla.org/security/2016/10/24/distrusting-new-wosign-and-startcom-certificates/ [1] My installation "chrome-stable" rejects them as well. Regards, -- ,''`. : :' : Chris Lamb `. `'` [email protected] / chris-lamb.co.uk `-

