On Mon, 26 Sep 2016 10:31:02 +0200
Matthew Seaman <matt...@freebsd.org> wrote:
[...]
> > 
> >      https://censys.io/
> > 

[...]

> 
> Hmmm... their TLS certificate is issued by 'StartCom Class 1 DV Server
> CA'  This is a CA that prominently advertizes free SSL certificates,
> but otherwise looks like it charges just like any other CA.
> See: http://www.startssl.com/  No idea if this CA is any good but
> there's nothing to suggest any wrong doing just from their site.

Just an FYI regarding StartCom:  Mozilla is suspending their CA for
one year (and quite likely forever, it's unlikely they'll be able to
meet the requirements for reactivation).  Lots more info here in
Mozilla's investigation report:
https://docs.google.com/document/d/1C6BlmbeQfn4a9zydVi2UvjBGv6szuSB4sMYUcVrR8vQ/preview


-- 
PGP: 28CC 9078 8358 CE2D 6824  A5BC 2DB2 CD24 5BE7 8F06

_______________________________________________
freebsd-security@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org"

Reply via email to