On 03/23/2017 04:02 AM, Chris Lamb wrote: > StartCom and WoSign certificates are now untrusted by the major browser > vendors[0][1], making websites that use certs from these vendors > inaccessible.
I followed these events on dev-security-policy and libnss performs date checks on certs signed by these roots, which ca-certificates has no facility to perform. > However, as this is not reflected in ca-certificates, tools such as curl > still intepret these as valid/secure. Blacklisting StartCom and WoSign roots will possibly invalidate some user's pre- Oct 21, 2016 valid certificates, but I think that is probably OK. > (This has a knock-on effect that health-check tools that use the output > of such tools to determine whether a site is "up" — eg. updown.io — will > misleadingly imply that the site is available to users when, in all > practical senses, they are not.) > > I would suggest we remove the offending authorities from ca-certificates > as soon as possible. > > > [0] > https://blog.mozilla.org/security/2016/10/24/distrusting-new-wosign-and-startcom-certificates/ > [1] My installation "chrome-stable" rejects them as well. Thanks for the report, Chris. -- Kind regards, Michael

