[Uta] Re: webpki anchors and comodo-gate-style attacks

2025-03-07 Thread Rob Stradling
The CABForum TLS BRs don't suggest a name for this AFAICT. The nearest I can find is: "Application Software Supplier: A supplier of Internet browser software or other relying‐party application software that displays or uses Certificates and incorporates Root Certificates." Despite having non-

[Uta] Re: webpki anchors and comodo-gate-style attacks

2025-03-07 Thread Michael Richardson
Salz, Rich wrote: >> 1. How do I cite the CABFORUM WebPKI set of anchors. >> Does it have a clear name? (Because it's not identical on all platforms/browsers/libraries). > I am pretty sure that there isn't one. Instead, each trust store > operator (e.g., browser vendor) is suppos

[Uta] Re: webpki anchors and comodo-gate-style attacks

2025-03-07 Thread Michael Richardson
Rob Stradling wrote: >> 2. An attack where CA B (mistakenly) issues a certificate for corp.example, >> when it should have been CA A is called... ??? >> I know it as Comodo-Gate. > (Your question almost identified an answer 😉 ) Almost, but not quite. > CAA (RFC6844, obsole