On 03/23/2017 04:02 AM, Chris Lamb wrote:
> StartCom and WoSign certificates are now untrusted by the major browser
> vendors[0][1], making websites that use certs from these vendors
> inaccessible.

I followed these events on dev-security-policy and libnss performs date
checks on certs signed by these roots, which ca-certificates has no
facility to perform.

> However, as this is not reflected in ca-certificates, tools such as curl
> still intepret these as valid/secure.

Blacklisting StartCom and WoSign roots will possibly invalidate some
user's pre- Oct 21, 2016 valid certificates, but I think that is
probably OK.

> (This has a knock-on effect that health-check tools that use the output
> of such tools to determine whether a site is "up" — eg. updown.io — will
> misleadingly imply that the site is available to users when, in all
> practical senses, they are not.)
> 
> I would suggest we remove the offending authorities from ca-certificates
> as soon as possible.
> 
> 
> [0] 
> https://blog.mozilla.org/security/2016/10/24/distrusting-new-wosign-and-startcom-certificates/
> [1] My installation "chrome-stable" rejects them as well.

Thanks for the report, Chris.

-- 
Kind regards,
Michael

Reply via email to